-
Notifications
You must be signed in to change notification settings - Fork 222
Responder
7h30th3r0n3 edited this page May 11, 2025
·
1 revision
A simple responder like, that answers NBNS/LLMNR and SMB discovery requests, captures NTLMv2 hashes, and logs them.
| Feature | Description |
|---|---|
| LLLMNR/NBNS Spoofing | Automatically replies to all NBNS and LLMNR name lookups with its IP address. |
| SMBv1 & SMBv2 | Supports both SMBv1 and SMBv2 to encourage client authentication. |
| NTLMv2 Challenge | Sends a challenge that forces clients to reveal their NTLMv2 hash. |
| Hash Logging | Counts captures, displays last user/domain, saves ntlm_hashes.txt to SD card. |
| Visual Dashboard | Radar-style animation for requests and a stats panel on the Cardputer screen. |
- Listens for NBNS & LLMNR queries and responds instantly.
- Waits for SMB connection attempts (v1 or v2).
- Sends an NTLMv2 challenge when authentication is attempted.
- Captures the NTLMv2 hash from the client response.
- Updates on-screen dashboard and logs details to SD card.
- Connect to Wi-Fi and start Responder.
- From another computer, trigger a name lookup with
\\evilin a folder path. - Observe the radar printout on the Cardputer that feedback answered LLMNR/NBNS.
- If cached credentials exist, the NTLMv2 hash is sent automatically and/or a pop-up asks for credentials.
- When an NTLMv2 hash is received, the display switches from Big radar to info screen and shows:
- Total NTLM captures
- Last detected username & domain
- Client device name or IP
- Mini radar feedback
- Use hashcat to crack the password
-
ntlm_hashes.txton the SD card (Hashcat format, one line per capture with device hostname). - Serial log detailing events and errors.
Disclaimer:
For authorized security testing only. Use on networks you own or have permission to assess. Unauthorized use is prohibited.
- Installation
- Slave
- ESP32 RIG Tutorial
- Scan WiFi
- Select WiFi
- Clone & Details
- Captive Portal Management
- Admin WebUI
- Check Credential
- Probes Attack
- Sniffing Probes
- Karma Attack
- Automated Karma Attack
- Karma Spear
- Bluetooth Serial Control
- Wardriving
- Wardriving Master
- Beacon Spam
- Deauther
- Auto Deauther
- Evil Twin
- Handshake Master
- WiFi Raw Sniffing
- Sniff Raw Client
- WiFi Channel Visualizer
- Client Sniff And Deauth
- Handshakes/Deauth sniffing
- Wall Of Flipper
- Send Tesla Code with RFunit
- SSH Shell
- Scan Network and Port
- Full Network Scan
- Web Crawler
- PwnGridSpam
- Skimmer Detector
- Mouse Jiggler
- BadUSB
- Bluetooth Keyboard
- Reverse TCP Tunnel
- DHCP Starvation Attack
- Rogue DHCP Server
- Switch DNS
- Network Hijacking
- Printer Attack
- Web Siphoning Cookie
- Honeypot
- LLM Chat Stream
- EvilChatMesh
- Responder
- WPAD Abuse
- Crack NTLMv2
- FileManager
- UART Shell
- SIP toolkit
- CCTV toolkit
- SSDP poisoning
- SkyJack
- Wifi Dead Drop
- BLENameFlood
- Wall Of Airtag
- FindMyEvil
- UPnP Mapping
- UPnP NAT
- LDAPDump
- IMSI Catcher
- Open Wifi Checker
- CIW ZeroClick
- Settings
- Installation
- Slave
- ESP32 RIG Tutorial
- Scan WiFi
- Select WiFi
- Clone & Details
- Captive Portal Management
- Admin WebUI
- Check Credential
- Probes Attack
- Sniffing Probes
- Karma Attack
- Automated Karma Attack
- Karma Spear
- Bluetooth Serial Control
- Wardriving
- Wardriving Master
- Beacon Spam
- Deauther
- Auto Deauther
- Evil Twin
- Handshake Master
- WiFi Raw Sniffing
- Sniff Raw Client
- WiFi Channel Visualizer
- Client Sniff And Deauth
- Handshakes/Deauth sniffing
- Wall Of Flipper
- Send Tesla Code with RFunit
- SSH Shell
- Scan Network and Port
- Full Network Scan
- Web Crawler
- PwnGridSpam
- Skimmer Detector
- Mouse Jiggler
- BadUSB
- Bluetooth Keyboard
- Reverse TCP Tunnel
- DHCP Starvation Attack
- Rogue DHCP Server
- Switch DNS
- Network Hijacking
- Printer Attack
- Web Siphoning Cookie
- Honeypot
- LLM Chat Stream
- EvilChatMesh
- Responder
- WPAD Abuse
- Crack NTLMv2
- FileManager
- UART Shell
- SIP toolkit
- CCTV toolkit
- SSDP poisoning
- SkyJack
- Wifi Dead Drop
- BLENameFlood
- Wall Of Airtag
- FindMyEvil
- UPnP Mapping
- UPnP NAT
- LDAPDump
- IMSI Catcher
- Open Wifi Checker
- CIW ZeroClick
- TagTinker ESL
- Settings