I use cadaver almost every time I find a WebDAV endpoint during a penetration test. Where DavTest tells me whether a server has a WebDAV file upload weakness, cadaver is the tool I switch to when I actually want to interact with that share by hand — browsing directories, uploading a web shell, moving files around, or just poking at permissions manually to confirm what an automated scanner reported.
What Is Cadaver?
Cadaver is a command-line WebDAV client for Unix-like systems. It behaves a lot like an FTP client — you connect to a URL, get an interactive shell-like prompt, and run commands like ls, cd, put, get, delete, mkcol, move, and copy. Under the hood, every one of those commands maps directly to a WebDAV HTTP method (PROPFIND, PUT, GET, DELETE, MKCOL, MOVE, COPY), so it’s essentially a friendly wrapper around raw WebDAV protocol calls.
How It Works Internally
Cadaver is built on top of the neon HTTP/WebDAV library, which handles the low-level protocol details — TLS negotiation, HTTP method construction, and XML parsing of PROPFIND responses (WebDAV uses XML-based multistatus responses to describe file/folder metadata).
When you run ls inside a cadaver session, it isn’t doing a directory listing the way FTP does — it’s sending a PROPFIND request with a Depth: 1 header, parsing the returned XML for <D:response> entries, and rendering them as a familiar file listing. This matters to understand because it explains some quirks: if a server’s WebDAV implementation returns malformed XML or doesn’t support PROPFIND fully, ls inside cadaver may behave oddly even though put/get still work fine.
Installation
On Debian/Kali-based systems:
sudo apt update
sudo apt install cadaver
Verify:
cadaver --version
Basic Syntax
cadaver <URL>
Example:
cadaver http://192.168.56.101/webdav/
If authentication is required, cadaver will prompt interactively, or you can pass credentials in the URL for quick testing (not recommended for anything beyond a lab):
cadaver http://user:pass@192.168.56.101/webdav/
Interactive Session Commands
Once connected, you get a dav:/webdav/> prompt. The commands I use most:
| Command | Purpose |
|---|---|
ls | List files/directories |
cd <dir> | Change directory |
put <local_file> | Upload a file |
get <remote_file> | Download a file |
delete <file> | Delete a file |
mkcol <name> | Create a new directory |
move <src> <dst> | Move/rename a file (useful for extension-bypass tricks) |
copy <src> <dst> | Copy a file |
propnames <file> | List WebDAV properties of a file |
quit | Exit the session |
Full Example Walkthrough
$ cadaver http://192.168.56.101/webdav/
dav:/webdav/> ls
Listing collection `/webdav/': succeeded.
Coll: uploads 0 Jul 12 09:14
readme.txt 42 Jul 10 15:02
dav:/webdav/> cd uploads
dav:/webdav/uploads/> put shell.php
Uploading shell.php to `/webdav/uploads/shell.php':
Progress: [=============================>] 100.0% of 612 bytes succeeded.
dav:/webdav/uploads/> ls
Listing collection `/webdav/uploads/': succeeded.
shell.php 612 Jul 30 10:41
At that point, in an authorized lab, I’d browse to http://192.168.56.101/webdav/uploads/shell.php to confirm execution.
Bypassing Extension Filters with put + move
Some servers block .php uploads directly but don’t validate the filename after a MOVE operation. A common technique:
dav:/webdav/uploads/> put shell.txt
dav:/webdav/uploads/> move shell.txt shell.php
This uploads as an allowed extension, then renames server-side — bypassing filters that only inspect the incoming PUT request’s filename.
Real-World Use Case (Authorized Lab Only)
In a lab VM running an Apache server with mod_dav_fs enabled and weak write permissions, my usual chain is:
davtestto confirm PHP execution is allowed.cadaverto manually upload a proper PHP web shell (e.g., a simplesystem()-based one-liner used strictly for demonstrating impact in the report).- Browser or
curlto trigger the shell and capture proof of code execution. cadaver‘sdeletecommand to clean up test artifacts before closing out the engagement.
Workflow Integration
- Nmap/whatweb → detect WebDAV is enabled.
- DavTest → automated check of which extensions execute.
- cadaver → manual, precise interaction: uploading payloads, testing MOVE/COPY bypasses, verifying permissions on individual files.
- Burp Suite → intercept cadaver’s raw HTTP traffic when you need to tweak headers (like
Destinationon a MOVE request) beyond what cadaver’s CLI exposes.
Troubleshooting & Common Mistakes
Could not open file for writing— usually a permissions issue on the server, or the server rejecting that specific extension.lshangs or returns malformed data — some non-standard WebDAV servers respond poorly toPROPFIND; tryput/getdirectly by full path instead of relying on directory listing.- SSL certificate errors — cadaver validates certs by default; for a lab environment with self-signed certs, you’ll be prompted to accept — don’t blanket-disable cert checks outside of a lab.
- Forgetting authenticated sessions expire — long interactive sessions against servers with short session timeouts may need reconnecting.
Best Practices
- Never leave uploaded test files or shells on a target after the engagement — use
deleteto clean up. - Use randomized, non-obvious filenames for uploaded test payloads so they don’t get accidentally indexed or found by others during the test window.
- Always pair cadaver’s manual poking with a proxy (Burp/ZAP) running in the background so you have a full request/response log for your report.
FAQ
Is cadaver still maintained? It’s a mature, stable tool — development has slowed since WebDAV usage declined, but it remains fully functional and is still packaged in Kali and Debian repos.
Can cadaver do recursive uploads of a whole directory? Not natively in a single command — you script it by looping put commands, often via cadaver’s non-interactive batch mode using -f with a command file.
Does cadaver support HTTPS? Yes, just use an https:// URL; it will prompt about certificate trust if the cert isn’t in the system trust store.
Summary
Cadaver is the manual, hands-on counterpart to DavTest’s automated scanning. It gives me full interactive control over a WebDAV share — uploading, downloading, renaming, and probing permissions exactly the way a legitimate WebDAV client would, which makes it invaluable both for confirming automated findings and for actually demonstrating exploitation in a report.
References
- Kali Linux Tools: https://www.kali.org/tools/cadaver/
- Cadaver homepage (via Debian package tracker): https://tracker.debian.org/pkg/cadaver
- neon HTTP/WebDAV library: https://notroj.github.io/neon/