Gonc: Netcat with Zero-Config P2P NAT Traversal and End-to-End Encryption
Gonc – Netcat with P2P Nat Traversal

Gonc is a Golang-based netcat alternative that adds automated NAT traversal with zero configuration—just agree on a passphrase. It uses public STUN and MQTT servers for address exchange, establishes direct P2P connections (IPv6 TCP > IPv4 TCP > IPv4 UDP) with TLS 1.3 or DTLS encryption and mutual authentication. Beyond shell access and file transfer, it offers built-in SOCKS5/HTTP proxies, reverse shells with pseudo-terminal support, and flexible service configuration via -e. No relay servers; either it connects directly or fails.
No relay servers are used, and no fallback mechanisms are provided — either the connection fails, or it's a real P2P success.
- nicman23
there are public stun servers ???
- gonc_cc
A simple example:
On one machine:
`echo Hello | gonc -p2p <passphrase>`
On the other:
`gonc -p2p <passphrase>`
The second machine will print:
`Hello`
Both sides use the same command and passphrase. There is no separate server/client role.
If NAT traversal succeeds, a direct connection is established. There is no relay by default.