← All cheat sheets

FRAGROUTE

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

fragroute intercepts, modifies, and rewrites egress traffic destined
for a specified host. It implements most attacks from IDS evasion
literature, fragmenting and transforming IP packets to test network
security devices.

BASIC USAGE#

fragroute <target_ip>            # Run with default rules
fragroute -f rules.conf <target> # Use custom ruleset file

COMMAND LINE OPTIONS#

fragroute <target>               # Intercept traffic to target
fragroute -f <file> <target>     # Load rules from file
fragroute -d <target>            # Debug mode

RULE SYNTAX#

# Rules are processed in order, one per line
# Comments start with #
# Rules modify packets before sending

FRAGMENTATION RULES#

ip_frag <size>                   # Fragment IP packets to <size> bytes
ip_frag 8                        # Fragment into 8-byte chunks
ip_frag 24                       # Fragment into 24-byte chunks

TCP SEGMENTATION#

tcp_seg <size>                   # Segment TCP data to <size> bytes
tcp_seg 1                        # Segment into 1-byte chunks
tcp_seg 8                        # Segment into 8-byte chunks

DELAY RULES#

delay first <ms>                 # Delay first fragment/segment
delay last <ms>                  # Delay last fragment/segment
delay random <ms>                # Random delay up to <ms>

REORDER RULES#

order random                     # Randomize packet order
order reverse                    # Reverse packet order

DUPLICATION RULES#

dup first <prob>                 # Duplicate first fragment
dup last <prob>                  # Duplicate last fragment
dup random <prob>                # Random duplication (probability 1-100)

DROP RULES#

drop first                       # Drop first fragment
drop last                        # Drop last fragment
drop random <prob>               # Random drop (probability 1-100)

IP OPTIONS#

ip_chaff dup                     # Insert duplicate chaff packets
ip_chaff opt                     # Insert chaff with bad IP options
ip_chaff <ttl>                   # Insert chaff with short TTL
ip_ttl <value>                   # Set IP TTL value

TCP OPTIONS#

tcp_chaff cksum                  # Insert chaff with bad checksums
tcp_chaff null                   # Insert null chaff segments
tcp_chaff paws                   # Insert chaff with old timestamps
tcp_chaff rexmit                 # Insert chaff as retransmissions
tcp_opt mss <value>              # Set TCP MSS option
print                            # Print packets to stdout

EXAMPLE RULESETS#

# IDS evasion - fragment and reorder
ip_frag 8
order random
print

# TCP segmentation with chaff
tcp_seg 1
tcp_chaff cksum
order random
print

# Fragment with delays
ip_frag 16
delay random 100
order random
print

# Full evasion test
ip_frag 8
ip_chaff dup
tcp_chaff cksum
order random
delay random 50
print

NOTES#

- Requires root privileges
- Only modifies outbound traffic to the specified target
- Commonly used for IDS/IPS evasion testing
- Works at the IP and TCP layer
- Pair with nmap or other scanners to test detection
- Use in controlled lab environments only
- Part of the dsniff suite by Dug Song