Fragroute Provided Scripts Allows to Blindside Snort
17 Apr. 2002
Summary
Fragroute intercepts, modifies, and rewrites egress traffic destined for a specified host, implementing most of the attacks described in the Secure Networks "Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection" paper of January 1998.
It features a simple rule set language to delay, duplicate, drop, fragment, overlap, print, reorder, segment, source-route, or otherwise monkey with all outbound packets destined for a target host, with minimal support for randomized or probabilistic behavior.
The tool can be used to blindside Snort into not detecting the latest wu-ftpd exploits when fragroute is executed with the "tcp_seg 1 new" option turned on. The following is a list of fragroute scripts that can be used to blind Snort into not detecting attacks.
Credit:
The information has been provided by 0xcafebabe.