문서의 이전 판입니다!
curl
CLI
curl [options...] <url>
curl [options…] <url>–abstract-unix-socket path: Connect via abstract Unix domain socket–alt-svc name: Enable alt-svc with this cache file(name)–anyauth: Pick any authentication method–append,-a: Append to target file when uploading–basic: Use HTTP Basic Authentication–cacert file: CA certificate to verify peer against–capath dir: CA directory to verify peer against–cert certificate[:password],-E certificate[:password]:Client certificate file and password–cert-status: Verify the status of the server certificate–cert-type type: Certificate file type(DER/PEM/ENG)–ciphers ciphers:SSL ciphers(list) to use–compressed: Request compressed response–compressed-ssh: Enable SSH compression–config file,-K file: Read config from a file–connect-timeout seconds: Maximum time allowed for connection–connect-to HOST1:PORT1:HOST2:PORT2: Connect to host–continue-at offset,-C offset: Resumed transfer offset–cookie data/filename,-b data/filename: Send cookies from string/file–cookie-jar filename,-c filename: Write cookies tofilenameafter operation–create-dirs: Create necessary local directory hierarchy–crlf: Convert LF to CRLF in upload–crlfile file: Get a CRL list in PEM format from the given file–data data,-d data: HTTP POST data–data-ascii data: HTTP POST ASCII data–data-binary data: HTTP POST binary data–data-raw data: HTTP POST data, '@' allowed–data-urlencode data: HTTP POST data url encoded–delegation LEVEL: GSS-API delegation permission–digest: Use HTTP Digest Authentication–disable,-q: Disable .curlrc–disable-eprt: Inhibit using EPRT or LPRT–disable-epsv: Inhibit using EPSV–disallow-username-in-url: Disallow username in url–dns-interface interface: Interface to use for DNS requests–dns-ipv6-addr address: IPv6 address to use for DNS requests–dns-ipv4-addr address: IPv4 address to use for DNS requests–dns-servers address: DNS server addrs to use–doh-url URL: Resolve host names over DOH–dump-header filename,-D filename: Write the received headers tofilename–egd-file file: EGD socket path for random data–engine name: Crypto engine to use–etag-save file: Get an ETag from response header and save it to a FILE–etag-compare file: Get an ETag from a file and send a conditional request–expect100-timeout seconds: How long to wait for 100-continue–fail,-f: Fail silently (no output at all) on HTTP errors–fail-early: Fail on first transfer error, do not continue–false-start: Enable TLS False Start–form name=content,-F name=content: Specify multipart MIME data–form-string name=string: Specify multipart MIME data–ftp-account data: Account data string–ftp-alternative-to-user command: String to replace USER [name]–ftp-create-dirsCreate the remote dirs if not present–ftp-method method: Control CWD usage–ftp-pasv: Use PASV/EPSV instead of PORT–ftp-port address,-P address: Use PORT instead of PASV–ftp-pret: Send PRET before PASV–ftp-skip-pasv-ip: Skip the IP address for PASV–ftp-ssl-ccc: Send CCC after authenticating–ftp-ssl-ccc-mode active|passive: Set CCC mode–ftp-ssl-control: Require SSL/TLS for FTP login, clear for transfer–get,-G: Put the post data in the URL and use GET–globoff,-g: Disable URL sequences and ranges using {} and []–happy-eyeballs-timeout-ms milliseconds: How long to wait in milliseconds for IPv6 before trying IPv4–haproxy-protocol: Send HAProxy PROXY protocol v1 header–head,-I: Show document info only–header header/@file,-H header/@file: Pass custom header(s) to server–help,-h: This help text–hostpubmd5 md5: Acceptable MD5 hash of the host public key–http0.9: Allow HTTP 0.9 responses–http1.0,-0: Use HTTP 1.0–http1.1: Use HTTP 1.1–http2: Use HTTP 2–http2-prior-knowledge: Use HTTP 2 without HTTP/1.1 Upgrade–http3: Use HTTP v3–ignore-content-length: Ignore the size of the remote resource–include,-i: Include protocol response headers in the output–insecure,-k: Allow insecure server connections when using SSL–interface name: Use network INTERFACE (or address)–ipv4,-4: Resolve names to IPv4 addresses–ipv6,-6: Resolve names to IPv6 addresses–junk-session-cookies,-j: Ignore session cookies read from file–keepalive-time seconds: Interval time for keepalive probes–key key: Private key file name–key-type type: Private key file type (DER/PEM/ENG)–krb level: Enable Kerberos with securitylevel–libcurl file: Dump libcurl equivalent code of this command line–limit-rate speed: Limit transfer speed to RATE–list-only,-l: List only mode–local-port num/range: Force use of RANGE for local port numbers-L,–location: Follow redirects–location-trusted: Like–location, and send auth to other hosts–login-options options: Server login options–mail-auth address: Originator address of the original email–mail-from address: Mail from this address–mail-rcpt address: Mail to this address-M,–manual: Display the full manual–max-filesizebytes: Maximum file size to download–max-redirs num: Maximum number of redirects allowed–max-time seconds,-m seconds: Maximum time allowed for the transfer–metalink: Process given URLs as metalink XML file–negotiate: Use HTTP Negotiate (SPNEGO) authentication–netrc,-n: Must read .netrc for user name and password–netrc-file filname: Specify FILE for netrc–netrc-optional: Use either .netrc or URL–next,-:: Make next URL use its separate set of options–no-alpn: Disable the ALPN TLS extension–no-buffer,-N: Disable buffering of the output stream–no-keepalive: Disable TCP keepalive on the connection–no-npn: Disable the NPN TLS extension–no-progress-meter: Do not show the progress meter–no-sessionid: Disable SSL session-ID reusing–noproxy no-proxy-list: List of hosts which do not use proxy–ntlm: Use HTTP NTLM authentication–ntlm-wb: Use HTTP NTLM authentication with winbind–oauth2-bearer<token> OAuth 2 Bearer Token–output file,-o file: Write to file instead of stdout–parallel,-Z: Perform transfers in parallel–parallel-immediate: Do not wait for multiplexing (with –parallel)–parallel-max: Maximum concurrency for parallel transfers–pass phrase: Pass phrase for the private key–path-as-is: Do not squash .. sequences in URL path–pinnedpubkey hashed: FILE/HASHES Public key to verify peer against–post301: Do not switch to GET after following a 301–post302: Do not switch to GET after following a 302–post303: Do not switch to GET after following a 303–preproxy [protocol://]host[:port]: Use this proxy first–progress-bar,-#: Display transfer progress as a bar–proto protocols: Enable/disable PROTOCOLS–proto-default protocol: Use PROTOCOL for any URL missing a scheme–proto-redir protocols: Enable/disable PROTOCOLS on redirect–proxy [protocol://]host[:port],-x [protocol://]host[:port]: Use this proxy–proxy-anyauth: Pick any proxy authentication method–proxy-basic: Use Basic authentication on the proxy–proxy-cacert file: CA certificate to verify peer against for proxy–proxy-capath dir: CA directory to verify peer against for proxy–proxy-cert cert[:passwd]: Set client certificate for proxy–proxy-cert-type type: Client certificate type for HTTPS proxy–proxy-ciphers list: SSL ciphers to use for proxy–proxy-crlfile file: Set a CRL list for proxy–proxy-digest: Use Digest authentication on the proxy–proxy-header header/@file: Pass custom header(s) to proxy–proxy-insecure: Do HTTPS proxy connections without verifying the proxy–proxy-key key: Private key for HTTPS proxy–proxy-key-type type: Private key file type for proxy–proxy-negotiate: Use HTTP Negotiate (SPNEGO) authentication on the proxy–proxy-ntlm: Use NTLM authentication on the proxy–proxy-pass phrase: Pass phrase for the private key for HTTPS proxy–proxy-pinnedpubkey hashes: FILE/HASHES public key to verify proxy with–proxy-service-name name: SPNEGO proxy service name–proxy-ssl-allow-beast: Allow security flaw for interop for HTTPS proxy–proxy-tls13-ciphers list: TLS 1.3 ciphersuites for proxy (OpenSSL)–proxy-tlsauthtype type: TLS authentication type for HTTPS proxy–proxy-tlspassword string: TLS password for HTTPS proxy–proxy-tlsuser name: TLS username for HTTPS proxy–proxy-tlsv1: Use TLSv1 for HTTPS proxy–proxy-user user:password,-U user:password: Proxy user and password–proxy1.0 host[:port]: Use HTTP/1.0 proxy on given port–proxytunnel,-p: Operate through an HTTP proxy tunnel (using CONNECT)–pubkey key: SSH Public key file name–quote,-Q: Send command(s) to server before transfer–random-file file: File for reading random data from–range range,-r range: Retrieve only the bytes within RANGE–raw: Do HTTP "raw"; no transfer decoding–referer URL,-e URL: Referrer URL–remote-header-name,-J: Use the header-provided filename–remote-name,-O: Write output to a file named as the remote file–remote-name-all: Use the remote file name for all URLs–remote-time,-R: Set the remote file's time on the local output–request command,-Xcommand: Specify request command to use–request-target: Specify the target for this request–resolve host:port:address[,address]…: Resolve the host+port to this address–retry num: Retry request if transient problems occur–retry-connrefused: Retry on connection refused (use with –retry)–retry-delay seconds: Wait time between retries–retry-max-time seconds: Retry only within this period–sasl-authzid identity: Use this identity to act as during SASL PLAIN authentication–sasl-ir: Enable initial response in SASL authentication–service-name name: SPNEGO service name–show-error,-S: Show error even when -s is used–silent,-s: Silent mode–socks4 host[:port]: SOCKS4 proxy on given host + port–socks4a host[:port]: SOCKS4a proxy on given host + port–socks5 host[:port]: SOCKS5 proxy on given host + port–socks5-basic: Enable username/password auth for SOCKS5 proxies–socks5-gssapi: Enable GSS-API auth for SOCKS5 proxies–socks5-gssapi-nec: Compatibility with NEC SOCKS5 server–socks5-gssapi-service name: SOCKS5 proxy service name for GSS-API–socks5-hostname host[:port]: SOCKS5 proxy, pass host name to proxy–speed-limit speed,-Y speed: Stop transfers slower than this–speed-time seconds,-y seconds: Trigger 'speed-limit' abort after this time–ssl: Try SSL/TLS–ssl-allow-beast: Allow security flaw to improve interop–ssl-no-revoke: Disable cert revocation checks (Schannel)–ssl-reqd: Require SSL/TLS–sslv2,-2: Use SSLv2–sslv3,-3: Use SSLv3–stderr: Where to redirect stderr–styled-output: Enable styled output for HTTP headers–suppress-connect-headers: Suppress proxy CONNECT response headers–tcp-fastopen: Use TCP Fast Open–tcp-nodelay: Use the TCP_NODELAY option–telnet-option opt=val,-t opt=val: Set telnet option–tftp-blksize value: Set TFTP BLKSIZE option–tftp-no-options: Do not send any TFTP options–time-cond time,-z time: Transfer based on a time condition–tls-max VERSION: Set maximum allowed TLS version–tls13-ciphers list: TLS 1.3 ciphersuites (OpenSSL)–tlsauthtype type: TLS authentication type–tlspassword: TLS password–tlsuser name: TLS user name–tlsv1,-1: Use TLSv1.0 or greater–tlsv1.0: Use TLSv1.0 or greater–tlsv1.1: Use TLSv1.1 or greater–tlsv1.2: Use TLSv1.2 or greater–tlsv1.3: Use TLSv1.3 or greater–tr-encoding: Request compressed transfer encoding–trace file: Write a debug trace to FILE–trace-ascii file: Like–trace, but without hex output–trace-time: Add time stamps to trace/verbose output–unix-socket path: Connect through this Unix domain socket–upload-file file,-T file: Transfer local FILE to destination–url url: URL to work with–use-ascii,-B: Use ASCII/text transfer–user user:password,-u user:password: Server user and password–user-agent name,-A name: Send User-Agentnameto server–verbose,-v: Make the operation more talkative–version,-V: Show version number and quit–write-out format,-w format: Use output FORMAT after completion–xattr: Store metadata in extended file attributes
Help
Example
# POST curl -X POST -d '{"name": "aaa", "gender": "m"}' -H "Accept: application/json" -H "Content-Type: application/json" http://localhost/rest/ # 웹 취약점 체크 curl -v -X TRACE host:port # WebDAV 파일 업로드 curl -u user:password -T filenme http://localhost/url