[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftJFLamPtkepYRL0jaijWtZlDu2KM66ViHbKtm3l-etk":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":50,"createdAt":50,"_status":49},20,"How do you upload a file to a virtual machine using the vSphere Web Services API and pyvmomi?","You call the `InitiateFileTransferToGuest` method with parameters including the VM object, guest credentials, destination path, file attributes, file size, and an overwrite flag. The method returns a URI that you access via a PUT request with the file content in binary format to complete the upload. This is demonstrated in the open-source code [vSphereWebServicesAPI_Manage.py](\u002Fnews\u002Fvsphere-development-guide-2-vsphere-web-services-api).","\u003Cp>You call the `InitiateFileTransferToGuest` method with parameters including the VM object, guest credentials, destination path, file attributes, file size, and an overwrite flag. The method returns a URI that you access via a PUT request with the file content in binary format to complete the upload. This is demonstrated in the open-source code [vSphereWebServicesAPI_Manage.py](\u002Fnews\u002Fvsphere-development-guide-2-vsphere-web-services-api).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fvsphere-development-guide-2-vsphere-web-services-api\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-do-you-upload-a-file-to-a-virtual-machine-using-the-vsphere-web-services-api-1777485539802","InitiateFileTransferToGuest, file upload, pyvmomi, PUT request",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":20,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},7,"vSphere Development Guide 2 – vSphere Web Services API","vsphere-development-guide-2-vsphere-web-services-api","Learn vSphere Web Services API development with pyvmomi, analyze SharpSphere, and manage VMs via Python. Includes file upload\u002Fdownload code examples.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article 'vSphere Development Guide 1 – vSphere Automation API' introduced methods for interacting with vCenter Server and virtual machines through the vSphere Automation API. However, some operations in the vSphere Automation API are not supported by older versions of vCenter (&lt; vSphere 7.0U2), limiting its universality. This article will introduce a more universal implementation method – the vSphere Web Services API.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Development details of the vSphere Web Services API\u003C\u002Fli>\u003Cli>Analysis of the open-source tool SharpSphere\u003C\u002Fli>\u003Cli>Open-source code vSphereWebServicesAPI_Manage.py\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Development Details of the vSphere Web Services API\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference documents:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fcode.vmware.com\u002Fapis\u002F968\u003C\u002Fp>\u003Cp>https:\u002F\u002Fcode.vmware.com\u002Fdocs\u002F11721\u002Fvmware-vsphere-web-services-sdk-programming-guide\u003C\u002Fp>\u003Cp>References for Python implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fvmware\u002Fpyvmomi-community-samples\u003C\u002Fp>\u003Cp>To improve efficiency, we implement this based on the Python SDK pyvmomi\u003C\u002Fp>\u003Cp>Specific details are as follows:\u003C\u002Fp>\u003Ch4>(1) Login operation\u003C\u002Fh4>\u003Cp>Call SmartConnect, passing in the username and plaintext password\u003C\u002Fp>\u003Cp>Specific details can be viewed in the file \u002Flib\u002Fsite-packages\u002FpyVim\u002Fconnect.py after installing pyvmomi\u003C\u002Fp>\u003Ch4>(2) View virtual machine configuration\u003C\u002Fh4>\u003Cp>Query by creating a ContainerView managed object\u003C\u002Fp>\u003Cp>Compared to the vSphere Automation API, the obtained content is more comprehensive\u003C\u002Fp>\u003Cp>For example, vsphere-automation-sdk-python does not support obtaining the UUID corresponding to each virtual machine, but it can be obtained through pyvmomi\u003C\u002Fp>\u003Ch4>(3) Send files to a virtual machine\u003C\u002Fh4>\u003Cp>Use the method InitiateFileTransferToGuest, which requires passing in the following six parameters:\u003C\u002Fp>\u003Cul>\u003Cli>vm, specifying the virtual machine to operate on\u003C\u002Fli>\u003Cli>auth, credentials for logging into the virtual machine\u003C\u002Fli>\u003Cli>guestFilePath, the save path for the file sent to the virtual machine\u003C\u002Fli>\u003Cli>fileAttributes, the file attributes sent to the virtual machine\u003C\u002Fli>\u003Cli>fileSize, file size\u003C\u002Fli>\u003Cli>overwrite, specifies whether to overwrite\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Upon successful execution, returns the URI corresponding to the file\u003C\u002Fp>\u003Cp>Use the PUT method to access the URI, with the data field containing the file content to be sent, which must be transmitted in binary format\u003C\u002Fp>\u003Cp>The specific implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>def UploadFileToVM(api_host, username, password, vm_name, guest_username, guest_user_password, local_path, guest_path):\u003Cbr>    service_instance = SmartConnect(host=api_host, user=username, pwd=password, port=443, disableSslCertValidation=True)\u003Cbr>    if not service_instance:\u003Cbr>        raise SystemExit(\"[!] Unable to connect to host with supplied credentials.\")\u003Cbr>\u003Cbr>    creds = vim.vm.guest.NamePasswordAuthentication(username = guest_username, password = guest_user_password)\u003Cbr>\u003Cbr>    with open(local_path, 'rb') as file_obj:\u003Cbr>        data_to_send = file_obj.read()\u003Cbr>\u003Cbr>    try:\u003Cbr>\u003Cbr>        content = service_instance.RetrieveContent()\u003Cbr>        vm = get_obj(content, [vim.VirtualMachine], vm_name)\u003Cbr>        if not vm:\u003Cbr>            raise SystemExit(\"Unable to locate the virtual machine.\")\u003Cbr>\u003Cbr>        file_attribute = vim.vm.guest.FileManager.FileAttributes()    \u003Cbr>        profile_manager = content.guestOperationsManager.fileManager\u003Cbr>        res = profile_manager.InitiateFileTransferToGuest(vm, creds, guest_path, file_attribute, len(data_to_send), True)      \u003Cbr>        print(\"[+] transfer uri: \" + res)\u003Cbr>\u003Cbr>        headers = {\u003Cbr>            \"User-Agent\": \"Mozilla\u002F5.0 (X11; Linux x86_64; rv:52.0) Gecko\u002F20100101 Firefox\u002F52.0\",\u003Cbr>        } \u003Cbr>        r = requests.put(res, headers = headers, data = data_to_send, verify = False)\u003Cbr>        if r.status_code ==200:\u003Cbr>            print(\"[+] \" + r.text)\u003Cbr>        else:         \u003Cbr>            print(\"[!]\" + str(r.status_code))\u003Cbr>            print(r.text)\u003Cbr>            exit(0)\u003Cbr>\u003Cbr>    except vmodl.MethodFault as error:\u003Cbr>        print(\"[!] Caught vmodl fault : \" + error.msg)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Download files from virtual machine\u003C\u002Fh4>\u003Cp>Using the InitiateFileTransferFromGuest method, the following three parameters must be passed:\u003C\u002Fp>\u003Cul>\u003Cli>vm, specifies the virtual machine to operate on\u003C\u002Fli>\u003Cli>auth, credentials for logging into the virtual machine\u003C\u002Fli>\u003Cli>guestFilePath, the path of the virtual machine file to be downloaded\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Upon successful execution, returns the uri corresponding to the specified file\u003C\u002Fp>\u003Cp>When accessing the uri using the GET method, distinguish between text format and binary format when retrieving file content. Text format can be read using r.text, while binary format can be read using r.content\u003C\u002Fp>\u003Cp>The specific implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>def DownloadFileFromVM(api_host, username, password, vm_name, guest_username, guest_user_password, guest_path, type):\u003Cbr>    service_instance = SmartConnect(host=api_host, user=username, pwd=password, port=443, disableSslCertValidation=True)\u003Cbr>    if not service_instance:\u003Cbr>        raise SystemExit(\"[!] Unable to connect to host with supplied credentials.\")\u003Cbr>\u003Cbr>    creds = vim.vm.guest.NamePasswordAuthentication(username = guest_username, password = guest_user_password)\u003Cbr>\u003Cbr>    try:\u003Cbr>\u003Cbr>        content = service_instance.RetrieveContent()\u003Cbr>        vm = get_obj(content, [vim.VirtualMachine], vm_name)\u003Cbr>        if not vm:\u003Cbr>            raise SystemExit(\"Unable to locate the virtual machine.\")\u003Cbr>   \u003Cbr>        profile_manager = content.guestOperationsManager.fileManager\u003Cbr>        res = profile_manager.InitiateFileTransferFromGuest(vm, creds, guest_path)\u003Cbr>        print(\"[+] transfer uri: \" + res.url)\u003Cbr>        print(\"    size: \" + str(res.size))\u003Cbr>        headers = {\u003Cbr>            \"User-Agent\": \"Mozilla\u002F5.0 (X11; Linux x86_64; rv:52.0) Gecko\u002F20100101 Firefox\u002F52.0\",\u003Cbr>        }\u003Cbr>        r = requests.get(res.url, headers = headers, verify = False)\u003Cbr>        if r.status_code == 200:\u003Cbr>            if type == \"text\":\u003Cbr>                print(\"[+] result: \")\u003Cbr>                print(r.text)\u003Cbr>            else:\u003Cbr>                print(\"[+] save the result as temp.bin\")\u003Cbr>                with open(\"temp.bin\", \"wb\") as file_obj:\u003Cbr>                    file_obj.write(r.content)\u003Cbr>  \u003Cbr>        else:\u003Cbr>            print(\"[!]\" + str(r.status_code))\u003Cbr>            print(r.text)\u003Cbr>            exit(0)\u003Cbr>\u003Cbr>    except vmodl.MethodFault as error:\u003Cbr>        print(\"[!] Caught vmodl fault : \" + error.msg)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>Analysis of the Open-Source Tool SharpSphere 0x03\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FJamesCooteUK\u002FSharpSphere\u003C\u002Fp>\u003Cp>Developed in C#, compatible with Cobalt Strike\u003C\u002Fp>\u003Cp>Supports the following features:\u003C\u002Fp>\u003Cul>\u003Cli>Acts as a C2 server\u003C\u002Fli>\u003Cli>Code execution\u003C\u002Fli>\u003Cli>File upload\u003C\u002Fli>\u003Cli>File download\u003C\u002Fli>\u003Cli>View virtual machine configuration\u003C\u002Fli>\u003Cli>Dump memory\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The implementation process for dumping memory is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Obtain a virtual machine snapshot; if none exists, create a snapshot file (.vmem)\u003C\u002Fli>\u003Cli>Download the snapshot locally via file URI creation\u003C\u002Fli>\u003Cli>Parse the snapshot file using WinDbg and Mimikatz to extract credentials from the lsass process\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Currently, operations on Linux virtual machines are not supported.\u003C\u002Fp>\u003Cp>During actual use, if you encounter the following error:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Error: An error occurred while making the HTTP request to https:\u002F\u002F\u003Cip>\u002F. This could be due to the fact that the server certificate is not configured properly with HTTP.SYS in the HTTPS case. This could also be caused by a mismatch of the security binding between the client and the server.\u003C\u002Fip>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>You can try adding the following code to resolve it:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>System.Net.ServicePointManager.SecurityProtocol = System.Net.SecurityProtocolType.Tls12;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Open Source Code\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The complete open source code has been uploaded to GitHub, with the address as follows:\u003C\u002Fp>\u003Cp>An Open Source Project\u003C\u002Fp>\u003Cp>Code Applicable Version: No restrictions\u003C\u002Fp>\u003Cp>Supports the following features:\u003C\u002Fp>\u003Cul>\u003Cli>Read virtual machine configurations\u003C\u002Fli>\u003Cli>View virtual machine files\u003C\u002Fli>\u003Cli>Delete virtual machine files\u003C\u002Fli>\u003Cli>Upload files to the virtual machine\u003C\u002Fli>\u003Cli>Download files from the virtual machine\u003C\u002Fli>\u003Cli>Execute commands in the virtual machine\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The specific commands are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>ListVM\u003C\u002Fli>\u003Cli>GetVMConfig\u003C\u002Fli>\u003Cli>ListHost\u003C\u002Fli>\u003Cli>ListVMProcess\u003C\u002Fli>\u003Cli>CreateVMProcess\u003C\u002Fli>\u003Cli>KillVMProcess\u003C\u002Fli>\u003Cli>ListVMFolder\u003C\u002Fli>\u003Cli>DeleteVMFile\u003C\u002Fli>\u003Cli>DownloadFileFromVM\u003C\u002Fli>\u003Cli>UploadFileToVM\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For operations on virtual machines, both Windows and Linux systems are supported\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of interacting with vCenter Server and virtual machines through the vSphere Web Services API, including the open-source implementation code vSphereWebServicesAPI_Manage.py, and documents the development details.\u003C\u002Fp>\u003Cp>Regarding the vSphere Web Services API, it offers greater versatility; however, due to being developed based on the SDK, the resulting tools tend to have a larger file size.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",5,"published","2026-02-02T08:21:10.771Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"vSphere Web Services API Guide: Development & SharpSphere Analysis","vSphere Web Services API, pyvmomi, SharpSphere, VMware development, virtual machine management, Python SDK, file transfer, vSphere Automation API",false,[],{"docs":41,"hasNextPage":38},[42,43,44,4,45],23,22,21,19,{"title":30,"description":30,"image":30},"2026-07-24T02:07:30.894Z","2026-07-23T16:00:53.891Z","draft","2026-07-23T16:02:55.954Z"]