FRAGROUTER
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
fragrouter is a network intrusion detection evasion toolkit that implements most of the known IDS evasion attacks through IP fragmentation. It acts as a one-way fragmenting router for forwarding IP packets.
BASIC USAGE#
fragrouter -B1 # Base-1: normal IP forwarding fragrouter -F1 # Frag-1: ordered 8-byte fragments fragrouter -F2 # Frag-2: ordered 24-byte fragments
ATTACK MODES#
# Base modes (no fragmentation): fragrouter -B1 # Normal IP forwarding (baseline) # IP Fragmentation modes: fragrouter -F1 # Ordered 8-byte IP fragments fragrouter -F2 # Ordered 24-byte IP fragments fragrouter -F3 # Ordered 8-byte, one out of order fragrouter -F4 # Ordered 8-byte, one duplicate fragrouter -F5 # Out of order 8-byte fragments fragrouter -F6 # Ordered 8-byte, marked last frag first fragrouter -F7 # Ordered 16-byte, frag overlap (favor old) # TCP Segment modes: fragrouter -T1 # TCP 1-byte segments, in order fragrouter -T3 # TCP 1-byte segments, out of order fragrouter -T4 # TCP 1-byte segments, one duplicate fragrouter -T5 # TCP 1-byte segments, one out of order fragrouter -T7 # TCP 1-byte segments, interleaved dup fragrouter -T8 # TCP 1-byte segments, one with bad RST # TCBC (TCP Chaff) modes: fragrouter -C2 # TCP segments with null flag chaff fragrouter -C3 # TCP segments with bad ACK chaff
COMMAND LINE OPTIONS#
fragrouter -i <interface> # Specify network interface fragrouter -g <gateway> # Specify gateway IP
EXAMPLES#
# Normal forwarding (baseline test) fragrouter -B1 # Small IP fragments to evade IDS fragrouter -F1 # Out of order fragments fragrouter -F5 # TCP segment evasion fragrouter -T1 # Specify interface and use fragment mode fragrouter -i eth0 -F1
SETUP#
# 1. Enable IP forwarding echo 1 > /proc/sys/net/ipv4/ip_forward # 2. Configure routing so target traffic passes through # 3. Run fragrouter with desired evasion mode # 4. Generate traffic with scanner or exploit tool
NOTES#
- Requires root privileges - Machine running fragrouter must be in the network path - Acts as a router - requires IP forwarding enabled - Use with ARP spoofing to redirect traffic - Useful for testing IDS/IPS fragmentation handling - Legacy tool - fragroute is the more modern alternative - Original by Dug Song (1999) - Some modes may not work with modern network stacks