Linux curl命令详解

命令 curl

curl 是一个很强大的网络操作工具,可以支持上传和下载,默认数据以“标准输出”(stdout)形式输出。

语法

curl [option] [url]

常用参数

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
-A/--user-agent <string>              设置用户代理发送给服务器
-b/--cookie <name=string/file> cookie字符串或文件读取位置
-c/--cookie-jar <file> 操作结束后把cookie写入到这个文件中
-C/--continue-at <offset> 断点续转
-D/--dump-header <file> 把header信息写入到该文件中
-e/--referer 来源网址
-f/--fail 连接失败时不显示http错误
-o/--output 把输出写到该文件中
-O/--remote-name 把输出写到该文件中,保留远程文件的文件名
-r/--range <range> 检索来自HTTP/1.1或FTP服务器字节范围
-s/--silent 静音模式。不输出任何东西
-T/--upload-file <file> 上传文件
-u/--user <user[:password]> 设置服务器的用户和密码
-w/--write-out [format] 什么输出完成后
-x/--proxy <host[:port]> 在给定的端口上使用HTTP代理
-#/--progress-bar 进度条显示当前的传送状态

常见用法

  1. 查看网页源码
    1
    curl https://haoubox.cn
  2. 通过curl获取网络访问时间
    1
    curl -w %{time_namelookup}:%{time_connect}:%{time_starttransfer}:%{time_total}:%{speed_download}"\n" -o /dev/null "https://haoubox.cn"
  3. 测试网页返回值
    1
    curl -o /dev/null -s -w %{http_code} haoubox.cn
  4. 指定proxy服务器以及其端口
    很多时候上网需要用到代理服务器(比如是使用代理服务器上网或者因为使用curl别人网站而被别人屏蔽IP地址的时候),幸运的是curl通过使用内置option:-x来支持设置代理
    1
    curl -x 192.168.100.100:1080 https://haoubox.cn
  5. 带cookie访问
    1
    curl -c cookiec.txt  https://haoubox.cn
  6. 自动跳转
    1
    curl -L haoubox.cn
  7. 显示头信息
    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    curl -i https://haoubox.cn
    HTTP/1.1 200 OK
    Server: nginx/1.14.0 (Ubuntu)
    Date: Thu, 15 Apr 2021 08:12:28 GMT
    Content-Type: text/html
    Content-Length: 16132
    Last-Modified: Thu, 15 Apr 2021 07:34:47 GMT
    Connection: keep-alive
    ETag: "6077ec97-3f04"
    Accept-Ranges: bytes
  8. 显示通信过程
    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    curl -v www.baidu.com
    * Trying 110.242.68.4...
    * TCP_NODELAY set
    * Connected to www.baidu.com (110.242.68.4) port 80 (#0)
    > GET / HTTP/1.1
    > Host: www.baidu.com
    > User-Agent: curl/7.64.1
    > Accept: */*
    >
    < HTTP/1.1 200 OK
    < Accept-Ranges: bytes
    < Cache-Control: private, no-cache, no-store, proxy-revalidate, no-transform
    < Connection: keep-alive
    < Content-Length: 2381
    < Content-Type: text/html
    < Date: Thu, 15 Apr 2021 08:14:48 GMT
    < Etag: "588604c1-94d"
    < Last-Modified: Mon, 23 Jan 2017 13:27:29 GMT
    < Pragma: no-cache
    < Server: bfe/1.0.8.18
    < Set-Cookie: BDORZ=27315; max-age=86400; domain=.baidu.com; path=/
    <
    <!DOCTYPE html>....
    更详细的信息
    1
    curl --trace output.txt www.baidu.com
    1
    curl --trace-ascii output.txt www.baidu.com
  9. 保存http的response里面的header信息
    1
    curl -D cookied.txt www.baidu.com
  10. 保存cookie信息
    1
    curl -b cookiec.txt www.baidu.com
  11. 模仿浏览器
    1
    curl -A "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.0)" https://haoubox.cn
  12. 伪造referer(盗链)
    1
    curl -e "www.haoubox.cn" https://www.baidu.com
  13. 增加头信息
    1
    curl --header "Content-Type:application/json" https://haoubox.cn
  14. HTTP认证
    1
    curl --user name:password haoubox.cn
  15. 下载文件
  • 指定输出文件名
    1
    curl -o https://haoubox.cn/xxx.gif
  • 按照下载文件名自动下载保存
    1
    curl -O https://haoubox.cn/xxx.gif
  • 循环下载
    1
    curl -O http://haoubox.cn/xxx[1-5].JPG
  • 分块下载
    1
    2
    3
    4
    curl -r 0-100 -o xxx_part1.JPG http://haoubox.cn/xxx1.JPG
    curl -r 100-200 -o xxx_part2.JPG http://haoubox.cn/xxx1.JPG
    curl -r 200- -o xxx_part3.JPG http://haoubox.cn/xxx1.JPG
    cat xxx_part* > xxx.JPG
  • 显示下载进度条
    1
    curl -# -O http://haoubox.cn/xxx.JPG
  • ftp下载文件
    1
    2
    curl -O -u 用户名:密码 ftp://haoubox.cn/xxx.JPG
    curl -O ftp://用户名:密码@haoubox.cn/xxx.JPG
  • ftp上传文件
    1
    curl -T xxx.JPG -u 用户名:密码 ftp://haoubox.cn/file/

    完整参数

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    24
    25
    26
    27
    28
    29
    30
    31
    32
    33
    34
    35
    36
    37
    38
    39
    40
    41
    42
    43
    44
    45
    46
    47
    48
    49
    50
    51
    52
    53
    54
    55
    56
    57
    58
    59
    60
    61
    62
    63
    64
    65
    66
    67
    68
    69
    70
    71
    72
    73
    74
    75
    76
    77
    78
    79
    80
    81
    82
    83
    84
    85
    86
    87
    88
    89
    90
    91
    92
    93
    94
    95
    96
    97
    98
    99
    100
    101
    102
    103
    104
    105
    106
    107
    108
    109
    110
    111
    112
    113
    114
    115
    116
    117
    118
    119
    120
    121
    122
    123
    124
    125
    126
    127
    128
    129
    130
    131
    132
    133
    134
    135
    136
    137
    138
    139
    140
    141
    142
    143
    144
    145
    146
    147
    148
    149
    150
    151
    152
    153
    154
    155
    156
    157
    158
    159
    160
    161
    162
    163
    164
    165
    166
    167
    168
    169
    170
    171
    172
    173
    174
    175
    176
    177
    178
    179
    180
    181
    182
    183
    184
    185
    186
    187
    188
    189
    190
    191
    192
    193
    194
    195
    196
    197
    198
    199
    200
    201
    202
    203
    204
    205
    206
    207
    208
    209
    210
    211
    212
    213
    214
    215
    216
    217
    218
    219
    220
    221
    222
    Usage: curl [options...] <url>
    --abstract-unix-socket <path> Connect via abstract Unix domain socket
    --alt-svc <file name> Enable alt-svc with this cache file
    --anyauth Pick any authentication method
    -a, --append Append to target file when uploading
    --basic Use HTTP Basic Authentication
    --cacert <file> CA certificate to verify peer against
    --capath <dir> CA directory to verify peer against
    -E, --cert <certificate[:password]> Client certificate file and password
    --cert-status Verify the status of the server certificate
    --cert-type <type> Certificate file type (DER/PEM/ENG)
    --ciphers <list of ciphers> SSL ciphers to use
    --compressed Request compressed response
    --compressed-ssh Enable SSH compression
    -K, --config <file> Read config from a file
    --connect-timeout <seconds> Maximum time allowed for connection
    --connect-to <HOST1:PORT1:HOST2:PORT2> Connect to host
    -C, --continue-at <offset> Resumed transfer offset
    -b, --cookie <data|filename> Send cookies from string/file
    -c, --cookie-jar <filename> Write cookies to <filename> after operation
    --create-dirs Create necessary local directory hierarchy
    --crlf Convert LF to CRLF in upload
    --crlfile <file> Get a CRL list in PEM format from the given file
    -d, --data <data> HTTP POST data
    --data-ascii <data> HTTP POST ASCII data
    --data-binary <data> HTTP POST binary data
    --data-raw <data> HTTP POST data, '@' allowed
    --data-urlencode <data> HTTP POST data url encoded
    --delegation <LEVEL> GSS-API delegation permission
    --digest Use HTTP Digest Authentication
    -q, --disable Disable .curlrc
    --disable-eprt Inhibit using EPRT or LPRT
    --disable-epsv Inhibit using EPSV
    --disallow-username-in-url Disallow username in url
    --dns-interface <interface> Interface to use for DNS requests
    --dns-ipv4-addr <address> IPv4 address to use for DNS requests
    --dns-ipv6-addr <address> IPv6 address to use for DNS requests
    --dns-servers <addresses> DNS server addrs to use
    --doh-url <URL> Resolve host names over DOH
    -D, --dump-header <filename> Write the received headers to <filename>
    --egd-file <file> EGD socket path for random data
    --engine <name> Crypto engine to use
    --expect100-timeout <seconds> How long to wait for 100-continue
    -f, --fail Fail silently (no output at all) on HTTP errors
    --fail-early Fail on first transfer error, do not continue
    --false-start Enable TLS False Start
    -F, --form <name=content> Specify multipart MIME data
    --form-string <name=string> Specify multipart MIME data
    --ftp-account <data> Account data string
    --ftp-alternative-to-user <command> String to replace USER [name]
    --ftp-create-dirs Create the remote dirs if not present
    --ftp-method <method> Control CWD usage
    --ftp-pasv Use PASV/EPSV instead of PORT
    -P, --ftp-port <address> Use PORT instead of PASV
    --ftp-pret Send PRET before PASV
    --ftp-skip-pasv-ip Skip the IP address for PASV
    --ftp-ssl-ccc Send CCC after authenticating
    --ftp-ssl-ccc-mode <active/passive> Set CCC mode
    --ftp-ssl-control Require SSL/TLS for FTP login, clear for transfer
    -G, --get Put the post data in the URL and use GET
    -g, --globoff Disable URL sequences and ranges using {} and []
    --happy-eyeballs-timeout-ms <milliseconds> How long to wait in milliseconds for IPv6 before trying IPv4
    --haproxy-protocol Send HAProxy PROXY protocol v1 header
    -I, --head Show document info only
    -H, --header <header/@file> Pass custom header(s) to server
    -h, --help This help text
    --hostpubmd5 <md5> Acceptable MD5 hash of the host public key
    --http0.9 Allow HTTP 0.9 responses
    -0, --http1.0 Use HTTP 1.0
    --http1.1 Use HTTP 1.1
    --http2 Use HTTP 2
    --http2-prior-knowledge Use HTTP 2 without HTTP/1.1 Upgrade
    --ignore-content-length Ignore the size of the remote resource
    -i, --include Include protocol response headers in the output
    -k, --insecure Allow insecure server connections when using SSL
    --interface <name> Use network INTERFACE (or address)
    -4, --ipv4 Resolve names to IPv4 addresses
    -6, --ipv6 Resolve names to IPv6 addresses
    -j, --junk-session-cookies Ignore session cookies read from file
    --keepalive-time <seconds> Interval time for keepalive probes
    --key <key> Private key file name
    --key-type <type> Private key file type (DER/PEM/ENG)
    --krb <level> Enable Kerberos with security <level>
    --libcurl <file> Dump libcurl equivalent code of this command line
    --limit-rate <speed> Limit transfer speed to RATE
    -l, --list-only List only mode
    --local-port <num/range> Force use of RANGE for local port numbers
    -L, --location Follow redirects
    --location-trusted Like --location, and send auth to other hosts
    --login-options <options> Server login options
    --mail-auth <address> Originator address of the original email
    --mail-from <address> Mail from this address
    --mail-rcpt <address> Mail to this address
    -M, --manual Display the full manual
    --max-filesize <bytes> Maximum file size to download
    --max-redirs <num> Maximum number of redirects allowed
    -m, --max-time <seconds> Maximum time allowed for the transfer
    --metalink Process given URLs as metalink XML file
    --negotiate Use HTTP Negotiate (SPNEGO) authentication
    -n, --netrc Must read .netrc for user name and password
    --netrc-file <filename> Specify FILE for netrc
    --netrc-optional Use either .netrc or URL
    -:, --next Make next URL use its separate set of options
    --no-alpn Disable the ALPN TLS extension
    -N, --no-buffer Disable buffering of the output stream
    --no-keepalive Disable TCP keepalive on the connection
    --no-npn Disable the NPN TLS extension
    --no-sessionid Disable SSL session-ID reusing
    --noproxy <no-proxy-list> List of hosts which do not use proxy
    --ntlm Use HTTP NTLM authentication
    --ntlm-wb Use HTTP NTLM authentication with winbind
    --oauth2-bearer <token> OAuth 2 Bearer Token
    -o, --output <file> Write to file instead of stdout
    --pass <phrase> Pass phrase for the private key
    --path-as-is Do not squash .. sequences in URL path
    --pinnedpubkey <hashes> FILE/HASHES Public key to verify peer against
    --post301 Do not switch to GET after following a 301
    --post302 Do not switch to GET after following a 302
    --post303 Do not switch to GET after following a 303
    --preproxy [protocol://]host[:port] Use this proxy first
    -#, --progress-bar Display transfer progress as a bar
    --proto <protocols> Enable/disable PROTOCOLS
    --proto-default <protocol> Use PROTOCOL for any URL missing a scheme
    --proto-redir <protocols> Enable/disable PROTOCOLS on redirect
    -x, --proxy [protocol://]host[:port] Use this proxy
    --proxy-anyauth Pick any proxy authentication method
    --proxy-basic Use Basic authentication on the proxy
    --proxy-cacert <file> CA certificate to verify peer against for proxy
    --proxy-capath <dir> CA directory to verify peer against for proxy
    --proxy-cert <cert[:passwd]> Set client certificate for proxy
    --proxy-cert-type <type> Client certificate type for HTTPS proxy
    --proxy-ciphers <list> SSL ciphers to use for proxy
    --proxy-crlfile <file> Set a CRL list for proxy
    --proxy-digest Use Digest authentication on the proxy
    --proxy-header <header/@file> Pass custom header(s) to proxy
    --proxy-insecure Do HTTPS proxy connections without verifying the proxy
    --proxy-key <key> Private key for HTTPS proxy
    --proxy-key-type <type> Private key file type for proxy
    --proxy-negotiate Use HTTP Negotiate (SPNEGO) authentication on the proxy
    --proxy-ntlm Use NTLM authentication on the proxy
    --proxy-pass <phrase> Pass phrase for the private key for HTTPS proxy
    --proxy-pinnedpubkey <hashes> FILE/HASHES public key to verify proxy with
    --proxy-service-name <name> SPNEGO proxy service name
    --proxy-ssl-allow-beast Allow security flaw for interop for HTTPS proxy
    --proxy-tls13-ciphers <ciphersuite list> TLS 1.3 proxy cipher suites
    --proxy-tlsauthtype <type> TLS authentication type for HTTPS proxy
    --proxy-tlspassword <string> TLS password for HTTPS proxy
    --proxy-tlsuser <name> TLS username for HTTPS proxy
    --proxy-tlsv1 Use TLSv1 for HTTPS proxy
    -U, --proxy-user <user:password> Proxy user and password
    --proxy1.0 <host[:port]> Use HTTP/1.0 proxy on given port
    -p, --proxytunnel Operate through an HTTP proxy tunnel (using CONNECT)
    --pubkey <key> SSH Public key file name
    -Q, --quote Send command(s) to server before transfer
    --random-file <file> File for reading random data from
    -r, --range <range> Retrieve only the bytes within RANGE
    --raw Do HTTP "raw"; no transfer decoding
    -e, --referer <URL> Referrer URL
    -J, --remote-header-name Use the header-provided filename
    -O, --remote-name Write output to a file named as the remote file
    --remote-name-all Use the remote file name for all URLs
    -R, --remote-time Set the remote file's time on the local output
    -X, --request <command> Specify request command to use
    --request-target Specify the target for this request
    --resolve <host:port:address[,address]...> Resolve the host+port to this address
    --retry <num> Retry request if transient problems occur
    --retry-connrefused Retry on connection refused (use with --retry)
    --retry-delay <seconds> Wait time between retries
    --retry-max-time <seconds> Retry only within this period
    --sasl-ir Enable initial response in SASL authentication
    --service-name <name> SPNEGO service name
    -S, --show-error Show error even when -s is used
    -s, --silent Silent mode
    --socks4 <host[:port]> SOCKS4 proxy on given host + port
    --socks4a <host[:port]> SOCKS4a proxy on given host + port
    --socks5 <host[:port]> SOCKS5 proxy on given host + port
    --socks5-basic Enable username/password auth for SOCKS5 proxies
    --socks5-gssapi Enable GSS-API auth for SOCKS5 proxies
    --socks5-gssapi-nec Compatibility with NEC SOCKS5 server
    --socks5-gssapi-service <name> SOCKS5 proxy service name for GSS-API
    --socks5-hostname <host[:port]> SOCKS5 proxy, pass host name to proxy
    -Y, --speed-limit <speed> Stop transfers slower than this
    -y, --speed-time <seconds> Trigger 'speed-limit' abort after this time
    --ssl Try SSL/TLS
    --ssl-allow-beast Allow security flaw to improve interop
    --ssl-no-revoke Disable cert revocation checks (Schannel)
    --ssl-reqd Require SSL/TLS
    -2, --sslv2 Use SSLv2
    -3, --sslv3 Use SSLv3
    --stderr Where to redirect stderr
    --styled-output Enable styled output for HTTP headers
    --suppress-connect-headers Suppress proxy CONNECT response headers
    --tcp-fastopen Use TCP Fast Open
    --tcp-nodelay Use the TCP_NODELAY option
    -t, --telnet-option <opt=val> Set telnet option
    --tftp-blksize <value> Set TFTP BLKSIZE option
    --tftp-no-options Do not send any TFTP options
    -z, --time-cond <time> Transfer based on a time condition
    --tls-max <VERSION> Set maximum allowed TLS version
    --tls13-ciphers <list of TLS 1.3 ciphersuites> TLS 1.3 cipher suites to use
    --tlsauthtype <type> TLS authentication type
    --tlspassword TLS password
    --tlsuser <name> TLS user name
    -1, --tlsv1 Use TLSv1.0 or greater
    --tlsv1.0 Use TLSv1.0 or greater
    --tlsv1.1 Use TLSv1.1 or greater
    --tlsv1.2 Use TLSv1.2 or greater
    --tlsv1.3 Use TLSv1.3 or greater
    --tr-encoding Request compressed transfer encoding
    --trace <file> Write a debug trace to FILE
    --trace-ascii <file> Like --trace, but without hex output
    --trace-time Add time stamps to trace/verbose output
    --unix-socket <path> Connect through this Unix domain socket
    -T, --upload-file <file> Transfer local FILE to destination
    --url <url> URL to work with
    -B, --use-ascii Use ASCII/text transfer
    -u, --user <user:password> Server user and password
    -A, --user-agent <name> Send User-Agent <name> to server
    -v, --verbose Make the operation more talkative
    -V, --version Show version number and quit
    -w, --write-out <format> Use output FORMAT after completion
    --xattr Store metadata in extended file attributes

    参考

Author: suce
Link: https://haoubox.cn/2021/04/15/Linux-curl命令详解/
Copyright Notice: All articles in this blog are licensed under CC BY-NC-SA 4.0 unless stating additionally.