← All cheat sheets

FRAGROUTER

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

fragrouter is a network intrusion detection evasion toolkit that
implements most of the known IDS evasion attacks through IP
fragmentation. It acts as a one-way fragmenting router for
forwarding IP packets.

BASIC USAGE#

fragrouter -B1                   # Base-1: normal IP forwarding
fragrouter -F1                   # Frag-1: ordered 8-byte fragments
fragrouter -F2                   # Frag-2: ordered 24-byte fragments

ATTACK MODES#

# Base modes (no fragmentation):
fragrouter -B1                   # Normal IP forwarding (baseline)

# IP Fragmentation modes:
fragrouter -F1                   # Ordered 8-byte IP fragments
fragrouter -F2                   # Ordered 24-byte IP fragments
fragrouter -F3                   # Ordered 8-byte, one out of order
fragrouter -F4                   # Ordered 8-byte, one duplicate
fragrouter -F5                   # Out of order 8-byte fragments
fragrouter -F6                   # Ordered 8-byte, marked last frag first
fragrouter -F7                   # Ordered 16-byte, frag overlap (favor old)

# TCP Segment modes:
fragrouter -T1                   # TCP 1-byte segments, in order
fragrouter -T3                   # TCP 1-byte segments, out of order
fragrouter -T4                   # TCP 1-byte segments, one duplicate
fragrouter -T5                   # TCP 1-byte segments, one out of order
fragrouter -T7                   # TCP 1-byte segments, interleaved dup
fragrouter -T8                   # TCP 1-byte segments, one with bad RST

# TCBC (TCP Chaff) modes:
fragrouter -C2                   # TCP segments with null flag chaff
fragrouter -C3                   # TCP segments with bad ACK chaff

COMMAND LINE OPTIONS#

fragrouter -i <interface>        # Specify network interface
fragrouter -g <gateway>          # Specify gateway IP

EXAMPLES#

# Normal forwarding (baseline test)
fragrouter -B1

# Small IP fragments to evade IDS
fragrouter -F1

# Out of order fragments
fragrouter -F5

# TCP segment evasion
fragrouter -T1

# Specify interface and use fragment mode
fragrouter -i eth0 -F1

SETUP#

# 1. Enable IP forwarding
echo 1 > /proc/sys/net/ipv4/ip_forward

# 2. Configure routing so target traffic passes through
# 3. Run fragrouter with desired evasion mode
# 4. Generate traffic with scanner or exploit tool

NOTES#

- Requires root privileges
- Machine running fragrouter must be in the network path
- Acts as a router - requires IP forwarding enabled
- Use with ARP spoofing to redirect traffic
- Useful for testing IDS/IPS fragmentation handling
- Legacy tool - fragroute is the more modern alternative
- Original by Dug Song (1999)
- Some modes may not work with modern network stacks