Cadaver: The WebDAV Command-Line Client Every Pentester Should Know

cadaver: WebDAV command-line client

I use cadaver almost every time I find a WebDAV endpoint during a penetration test. Where DavTest tells me whether a server has a WebDAV file upload weakness, cadaver is the tool I switch to when I actually want to interact with that share by hand — browsing directories, uploading a web shell, moving files around, or just poking at permissions manually to confirm what an automated scanner reported.

What Is Cadaver?

Cadaver is a command-line WebDAV client for Unix-like systems. It behaves a lot like an FTP client — you connect to a URL, get an interactive shell-like prompt, and run commands like ls, cd, put, get, delete, mkcol, move, and copy. Under the hood, every one of those commands maps directly to a WebDAV HTTP method (PROPFIND, PUT, GET, DELETE, MKCOL, MOVE, COPY), so it’s essentially a friendly wrapper around raw WebDAV protocol calls.

How It Works Internally

Cadaver is built on top of the neon HTTP/WebDAV library, which handles the low-level protocol details — TLS negotiation, HTTP method construction, and XML parsing of PROPFIND responses (WebDAV uses XML-based multistatus responses to describe file/folder metadata).

When you run ls inside a cadaver session, it isn’t doing a directory listing the way FTP does — it’s sending a PROPFIND request with a Depth: 1 header, parsing the returned XML for <D:response> entries, and rendering them as a familiar file listing. This matters to understand because it explains some quirks: if a server’s WebDAV implementation returns malformed XML or doesn’t support PROPFIND fully, ls inside cadaver may behave oddly even though put/get still work fine.

Installation

On Debian/Kali-based systems:

sudo apt update
sudo apt install cadaver

Verify:

cadaver --version

Basic Syntax

cadaver <URL>

Example:

cadaver http://192.168.56.101/webdav/

If authentication is required, cadaver will prompt interactively, or you can pass credentials in the URL for quick testing (not recommended for anything beyond a lab):

cadaver http://user:pass@192.168.56.101/webdav/

Interactive Session Commands

Once connected, you get a dav:/webdav/> prompt. The commands I use most:

CommandPurpose
lsList files/directories
cd <dir>Change directory
put <local_file>Upload a file
get <remote_file>Download a file
delete <file>Delete a file
mkcol <name>Create a new directory
move <src> <dst>Move/rename a file (useful for extension-bypass tricks)
copy <src> <dst>Copy a file
propnames <file>List WebDAV properties of a file
quitExit the session

Full Example Walkthrough

$ cadaver http://192.168.56.101/webdav/
dav:/webdav/> ls
Listing collection `/webdav/': succeeded.
Coll:   uploads                                0  Jul 12 09:14
        readme.txt                            42  Jul 10 15:02

dav:/webdav/> cd uploads
dav:/webdav/uploads/> put shell.php
Uploading shell.php to `/webdav/uploads/shell.php':
Progress: [=============================>] 100.0% of 612 bytes succeeded.

dav:/webdav/uploads/> ls
Listing collection `/webdav/uploads/': succeeded.
        shell.php                             612  Jul 30 10:41

At that point, in an authorized lab, I’d browse to http://192.168.56.101/webdav/uploads/shell.php to confirm execution.

Bypassing Extension Filters with put + move

Some servers block .php uploads directly but don’t validate the filename after a MOVE operation. A common technique:

dav:/webdav/uploads/> put shell.txt
dav:/webdav/uploads/> move shell.txt shell.php

This uploads as an allowed extension, then renames server-side — bypassing filters that only inspect the incoming PUT request’s filename.

Real-World Use Case (Authorized Lab Only)

In a lab VM running an Apache server with mod_dav_fs enabled and weak write permissions, my usual chain is:

  1. davtest to confirm PHP execution is allowed.
  2. cadaver to manually upload a proper PHP web shell (e.g., a simple system()-based one-liner used strictly for demonstrating impact in the report).
  3. Browser or curl to trigger the shell and capture proof of code execution.
  4. cadaver‘s delete command to clean up test artifacts before closing out the engagement.

Workflow Integration

  • Nmap/whatweb → detect WebDAV is enabled.
  • DavTest → automated check of which extensions execute.
  • cadaver → manual, precise interaction: uploading payloads, testing MOVE/COPY bypasses, verifying permissions on individual files.
  • Burp Suite → intercept cadaver’s raw HTTP traffic when you need to tweak headers (like Destination on a MOVE request) beyond what cadaver’s CLI exposes.

Troubleshooting & Common Mistakes

  • Could not open file for writing — usually a permissions issue on the server, or the server rejecting that specific extension.
  • ls hangs or returns malformed data — some non-standard WebDAV servers respond poorly to PROPFIND; try put/get directly by full path instead of relying on directory listing.
  • SSL certificate errors — cadaver validates certs by default; for a lab environment with self-signed certs, you’ll be prompted to accept — don’t blanket-disable cert checks outside of a lab.
  • Forgetting authenticated sessions expire — long interactive sessions against servers with short session timeouts may need reconnecting.

Best Practices

  • Never leave uploaded test files or shells on a target after the engagement — use delete to clean up.
  • Use randomized, non-obvious filenames for uploaded test payloads so they don’t get accidentally indexed or found by others during the test window.
  • Always pair cadaver’s manual poking with a proxy (Burp/ZAP) running in the background so you have a full request/response log for your report.

FAQ

Is cadaver still maintained? It’s a mature, stable tool — development has slowed since WebDAV usage declined, but it remains fully functional and is still packaged in Kali and Debian repos.

Can cadaver do recursive uploads of a whole directory? Not natively in a single command — you script it by looping put commands, often via cadaver’s non-interactive batch mode using -f with a command file.

Does cadaver support HTTPS? Yes, just use an https:// URL; it will prompt about certificate trust if the cert isn’t in the system trust store.

Summary

Cadaver is the manual, hands-on counterpart to DavTest’s automated scanning. It gives me full interactive control over a WebDAV share — uploading, downloading, renaming, and probing permissions exactly the way a legitimate WebDAV client would, which makes it invaluable both for confirming automated findings and for actually demonstrating exploitation in a report.

References

  • Kali Linux Tools: https://www.kali.org/tools/cadaver/
  • Cadaver homepage (via Debian package tracker): https://tracker.debian.org/pkg/cadaver
  • neon HTTP/WebDAV library: https://notroj.github.io/neon/
Total
1
Shares

Leave a Reply

Previous Post
ffuf: Fuzzing web applications for vulnerabilities

ffuf: Fast Web Fuzzing for Directories, Parameters, and Vulnerabilities

Next Post
davtest: Tests WebDAV servers for vulnerabilities

davtest: Tests WebDAV servers for vulnerabilities

Related Posts