Responder

INTERNALLLMNRNBT-NSNTLM

NOTES

Responder helps validate whether hosts rely on insecure local name-resolution behavior and whether authentication material can be coerced toward an untrusted listener.

I separate three claims: poisoning is possible, a challenge-response was captured, and relay or cracking creates additional impact. They require different evidence and should not be collapsed into one finding.

WORKFLOW

COMMANDS

sudo responder -I eth0 -A
sudo responder -I eth0 -w
sudo responder -I eth0 --lm

GOTCHAS

DOCS

Responder documentation ↗

← Back to Resources