INTRACE
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
InTrace is a traceroute-like tool that enumerates IP hops by exploiting existing TCP connections. Unlike traditional traceroute, it uses an established TCP session to bypass firewalls that block ICMP or UDP traceroute packets.
BASIC USAGE#
intrace -h <target> -p <port> # Trace route using TCP connection
OPTIONS#
intrace -h <target> # Target host intrace -p <port> # Target port (default: 80) intrace -s <size> # Packet payload size intrace -d # Debug mode
EXAMPLES#
# Trace route to web server intrace -h 192.168.1.1 -p 80 # Trace route via SSH connection intrace -h 192.168.1.1 -p 22 # Trace route via HTTPS intrace -h 192.168.1.1 -p 443 # Trace with custom payload size intrace -h 192.168.1.1 -p 80 -s 64 # Debug mode for troubleshooting intrace -h 192.168.1.1 -p 80 -d
HOW IT WORKS#
# 1. Establishes a TCP connection to target:port # 2. Sends packets with incrementing TTL values # 3. Uses the existing TCP session (SYN/ACK'd) # 4. Firewalls that allow the TCP session also pass these packets # 5. ICMP TTL Exceeded messages reveal intermediate hops # Advantages over traditional traceroute: # - Bypasses stateful firewalls (uses allowed TCP session) # - Works where ICMP/UDP traceroute is blocked # - Reveals true network path for allowed services
COMPARISON WITH TRACEROUTE#
# Traditional traceroute: # - Uses ICMP or UDP packets # - Easily blocked by firewalls # - May show different path than actual traffic # InTrace: # - Uses existing TCP connections # - Passes through stateful firewalls # - Shows actual path for established connections # - Requires an open port on target
NOTES#
- Requires root privileges - Target port must be open and accepting connections - More accurate than ICMP traceroute through firewalls - Works with any TCP service (HTTP, SSH, SMTP, etc.) - Useful when traditional traceroute is blocked - Shows network path for allowed traffic flows