Responder
Responder
This is a tool made by Trustwave that does NBNS (NetBIOS Name Server) and LLMNR (Local-Link Multicast Name Resolution) Spoofing.
For the initial start of the test, we typically run the following command:
responder -F -I eth0
Responder should be a tool that you run at the very beginning of the test and is best to focus your efforts on this tool when employees are most frequently using their workstations. So as they roll into the office and begin logging in and after lunch are great times. You may let this run for a while and be sure to monitor how fast hashes are coming in. Once you have a few hashes, copy and paste them offline for password cracking.
Once a few hashes are captured, they will show up in /usr/share/responder/logs, you will see various .txt files that contain individual hashes. Compile these hashes into a single text file and remove duplicate hashes
Last updated