← All cheat sheets

INTRACE

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

InTrace is a traceroute-like tool that enumerates IP hops by
exploiting existing TCP connections. Unlike traditional traceroute,
it uses an established TCP session to bypass firewalls that block
ICMP or UDP traceroute packets.

BASIC USAGE#

intrace -h <target> -p <port>    # Trace route using TCP connection

OPTIONS#

intrace -h <target>              # Target host
intrace -p <port>                # Target port (default: 80)
intrace -s <size>                # Packet payload size
intrace -d                       # Debug mode

EXAMPLES#

# Trace route to web server
intrace -h 192.168.1.1 -p 80

# Trace route via SSH connection
intrace -h 192.168.1.1 -p 22

# Trace route via HTTPS
intrace -h 192.168.1.1 -p 443

# Trace with custom payload size
intrace -h 192.168.1.1 -p 80 -s 64

# Debug mode for troubleshooting
intrace -h 192.168.1.1 -p 80 -d

HOW IT WORKS#

# 1. Establishes a TCP connection to target:port
# 2. Sends packets with incrementing TTL values
# 3. Uses the existing TCP session (SYN/ACK'd)
# 4. Firewalls that allow the TCP session also pass these packets
# 5. ICMP TTL Exceeded messages reveal intermediate hops

# Advantages over traditional traceroute:
# - Bypasses stateful firewalls (uses allowed TCP session)
# - Works where ICMP/UDP traceroute is blocked
# - Reveals true network path for allowed services

COMPARISON WITH TRACEROUTE#

# Traditional traceroute:
# - Uses ICMP or UDP packets
# - Easily blocked by firewalls
# - May show different path than actual traffic

# InTrace:
# - Uses existing TCP connections
# - Passes through stateful firewalls
# - Shows actual path for established connections
# - Requires an open port on target

NOTES#

- Requires root privileges
- Target port must be open and accepting connections
- More accurate than ICMP traceroute through firewalls
- Works with any TCP service (HTTP, SSH, SMTP, etc.)
- Useful when traditional traceroute is blocked
- Shows network path for allowed traffic flows