| |/ \ | | ___ | | | _|| || |/ | \ | || \ | || \
| | || || |||| \ | | -.-. | || || | || | || \
||_/ || ||_|||||| _/|/_||__/|__||____/
作者: @w_m_
一个简单的工具,用于检测 NBT-NS 和 LLMNR 欺骗(并稍微捣乱一下它们)

渗透测试人员、红队成员甚至真正的攻击者都喜欢使用 Responder 之类的工具来欺骗 LLMNR 和/或 NBT-NS 响应。有一些很棒的其他工具可以帮助检测,例如 respounder。但我想自己搞清楚,同时添加一种向使用这些欺骗工具的人推送“蜜罐”令牌(虚假 AD 凭据)的方法。
git clone https://github.com/joda32/got-responded.git
cd got-responded
python3 -m venv responded-env
source responded-env/bin/activate
pip install -r requirements.txt
这将启动默认模式,将同时检查 LLMNR 和 NBT-NS 欺骗,但不会发送虚假 SMB 凭据
python got-responded.py