FRAGROUTE
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
fragroute intercepts, modifies, and rewrites egress traffic destined for a specified host. It implements most attacks from IDS evasion literature, fragmenting and transforming IP packets to test network security devices.
BASIC USAGE#
fragroute <target_ip> # Run with default rules fragroute -f rules.conf <target> # Use custom ruleset file
COMMAND LINE OPTIONS#
fragroute <target> # Intercept traffic to target fragroute -f <file> <target> # Load rules from file fragroute -d <target> # Debug mode
RULE SYNTAX#
# Rules are processed in order, one per line # Comments start with # # Rules modify packets before sending
FRAGMENTATION RULES#
ip_frag <size> # Fragment IP packets to <size> bytes ip_frag 8 # Fragment into 8-byte chunks ip_frag 24 # Fragment into 24-byte chunks
TCP SEGMENTATION#
tcp_seg <size> # Segment TCP data to <size> bytes tcp_seg 1 # Segment into 1-byte chunks tcp_seg 8 # Segment into 8-byte chunks
DELAY RULES#
delay first <ms> # Delay first fragment/segment delay last <ms> # Delay last fragment/segment delay random <ms> # Random delay up to <ms>
REORDER RULES#
order random # Randomize packet order order reverse # Reverse packet order
DUPLICATION RULES#
dup first <prob> # Duplicate first fragment dup last <prob> # Duplicate last fragment dup random <prob> # Random duplication (probability 1-100)
DROP RULES#
drop first # Drop first fragment drop last # Drop last fragment drop random <prob> # Random drop (probability 1-100)
IP OPTIONS#
ip_chaff dup # Insert duplicate chaff packets ip_chaff opt # Insert chaff with bad IP options ip_chaff <ttl> # Insert chaff with short TTL ip_ttl <value> # Set IP TTL value
TCP OPTIONS#
tcp_chaff cksum # Insert chaff with bad checksums tcp_chaff null # Insert null chaff segments tcp_chaff paws # Insert chaff with old timestamps tcp_chaff rexmit # Insert chaff as retransmissions tcp_opt mss <value> # Set TCP MSS option
PRINT / INSPECT#
print # Print packets to stdout
EXAMPLE RULESETS#
# IDS evasion - fragment and reorder ip_frag 8 order random print # TCP segmentation with chaff tcp_seg 1 tcp_chaff cksum order random print # Fragment with delays ip_frag 16 delay random 100 order random print # Full evasion test ip_frag 8 ip_chaff dup tcp_chaff cksum order random delay random 50 print
NOTES#
- Requires root privileges - Only modifies outbound traffic to the specified target - Commonly used for IDS/IPS evasion testing - Works at the IP and TCP layer - Pair with nmap or other scanners to test detection - Use in controlled lab environments only - Part of the dsniff suite by Dug Song