SpiderLabs / Responder

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

DontRespondTo setting no longer seems to work

cclements opened this issue · comments

In the latest build, Responder correctly lists the ip not to respond to when starting up, then responds and captures hashes anyway.

https://gist.github.com/cclements/afb260d4ad47a67745ac7be000e1f2a0

Thanks for your report. What's running on port 80?

Had an instance of darkhttpd running on the box I had forgotten about. Issue persists after killing it however.

Ok. Responder should never respond to its own IP address by default. The dontrespondto option is used for out of scope IP address or to avoid NAC detection.

This project has been forked the author. Issues/Feature requests/Pulls will only be supported by lgandx at this address: https://github.com/lgandx/Responder
If you have any suggestion, bugs, pulls, please use the new address.