A generative IPv4/IPv6 network-stack fuzzer. ISIC emits piles of controlled-random valid and invalid packets — mangled headers, bad checksums, weird IP options, fragmentation — and watches the target stack for a crash, hang, or leak. It's the classic pre-Scapy generative fuzzer, still handy for soak-testing an IP stack, firewall, or IDS.
Note
This is a fork of ISIC, vendored from the maintained libnet-1.1+ fork
IPv4v6/isic. It carries two local changes
from upstream, both documented in PROVENANCE.md:
isic.hportability guard — the suite also builds on macOS/BSD.- Run forever by default — all ten
sictools now default to an unbounded run (until interrupted) instead of stopping after 2³² packets. Pass-p <n>(or-c <n>foresic) to bound a run, exactly as upstream did. Note the semantic shift: upstream-p 0/-c 0sent zero packets; here0means unbounded.
Upstream ISIC is © 1999–2007 Shu Xiao & Mike Frantzen, Modified BSD
(see License / LICENSE). Those terms are unchanged.
Warning
These tools generate raw traffic that can crash or hang the systems they hit. Only run ISIC against hosts and networks you own or are explicitly authorized to test. You are responsible for how you use it.
The suite builds ten binaries. Each opens raw sockets, so run them with sudo.
| Tool | Layer | Fuzzes |
|---|---|---|
isic |
IPv4 | IP headers, options, fragmentation |
tcpsic |
TCP / IPv4 | TCP headers, flags, options, checksums |
udpsic |
UDP / IPv4 | UDP headers and checksums |
icmpsic |
ICMP / IPv4 | ICMP messages |
multisic |
UDP / IPv4 | random multicast UDP packets |
esic |
Ethernet (L2) | raw Ethernet frames |
isic6 |
IPv6 | IPv6 headers, extension headers |
tcpsic6 |
TCP / IPv6 | TCP over IPv6 |
udpsic6 |
UDP / IPv6 | UDP over IPv6 |
icmpsic6 |
ICMPv6 | ICMPv6 messages |
Prebuilt packages are attached to each GitHub Release;
each declares a dependency on libnet, so your package manager pulls it in.
# Debian / Ubuntu
sudo apt install ./isic_<version>_amd64.deb
# Fedora / RHEL
sudo dnf install ./isic-<version>-1.x86_64.rpm
# Homebrew (macOS / Linux)
brew tap jonaslejon/isic
brew install isicOr build from source (below).
Needs a C compiler and libnet 1.1+ development headers.
# Ubuntu / Debian
sudo apt-get install -y build-essential libnet1-dev
# macOS
brew install libnet
./build.sh # builds all ten tools in placebuild.sh is a portable direct-compile wrapper (no autoconf). Verified on
Ubuntu 24.04 (gcc 13, libnet 1.1.6) and macOS arm64 (clang, brew libnet 1.3).
The sic tools open raw sockets — run them with sudo. A few examples:
# Fuzz a host's IPv4 stack with a random source, forever (Ctrl-C to stop)
sudo ./isic -s rand -d 10.0.0.1
# Fuzz TCP toward a firewall, stressing IP options
sudo ./tcpsic -s rand -d 10.0.0.1 -I 100
# Spew random raw Ethernet frames out an interface
sudo ./esic -i eth0
# Bound a run to a fixed packet count (the old upstream behavior)
sudo ./isic -s rand -d 10.0.0.1 -p 100000 # stop after 100k packets
sudo ./esic -i eth0 -c 100000 # esic uses -cRun any tool with -h for its full option list, or see the manual page:
man ./isic.1.
Every sic tool runs until you interrupt it, instead of upstream's finite 2³²
ceiling. The default count is 0, and 0 is the "unbounded" sentinel in each send
loop. Pass a positive count (-p <n>, or -c <n> for esic) to bound a run; a
bounded run keeps the seeded, -k-skippable, countable sequence unchanged. Full
rationale in PROVENANCE.md.
ISIC was created by Mike Frantzen and maintained upstream by Shu Xiao. This fork is maintained by Jonas Lejon.
| Contributor | Role / contribution |
|---|---|
| Jonas Lejon | This fork (macOS/BSD portability, run-forever default) |
| Shu Xiao | Upstream owner |
| Mike Frantzen | Original creator |
| Matt Hargett | Various patches |
| Dug Song | Various patches |
| Kelly Yancey | Various bug-fix patches |
| Marcelo Goes | GCC 4 patch |
| Todd Sherer | Testing on Red Hat 7.3 |
| Seth Bollinger | multisic prototype |
| Alex Behar | GCC 4 patch |
| Marc Tardif | GCC 4 patch |
| Sheng Li | Flood control + unit/regression tests |
The idea for ISIC came from Mike Frantzen's co-workers Kevin Kadow and Mike Scher.
Project history & accomplishments (upstream lore)
Mike Frantzen wrote ISIC v0.01 over a two-week period on a Red Hat 5.1 box. One
weekend he came back from work to find the disk full of SCSI errors; he recovered
what source he could from lost+found after fscking the drive on Mike Scher's
Linux box, but large (remarkably block-sized) chunks were missing or rearranged
across all the files. So over a weekend he rewrote isic, tcpsic, and udpsic;
icmpsic took a bit longer (he'd forgotten to add the IP header length to the
pointer to the IP options).
v0.02's Makefile wasn't compatible with future versions of Libnet — fixed in v0.03,
which also (finally) randomized the TCP flags [thanks Florian]. Mike added esic
(the Ethernet frame spewer) in v0.04. v0.05 was the last release for Libnet 1.0.x;
then Mike Schiffman rewrote Libnet and 1.1.x was no longer backward-compatible.
In late 2004, Shu Xiao — working as a security-testing engineer — sent patches that got ISIC compiling against the new Libnet, along with other fixes, and v0.06 was born as Mike handed the project to Shu. v0.07 (an overdue release) added the IPv6 tools and 32-bit-wide randomness for some fields. "It is supposed to singe more fur off your cat."
Vulnerabilities reported over the years using ISIC include:
- Checkpoint Firewall-1 4.0 — logging and IP-stack anomalies (not released).
- Gauntlet 5.0 / 5.5 Beta — lock-ups and frag DoS; the 5.0 lock-up (ICMP Parameter Problem packets carrying IP options in the encapsulated packet) was Bugtraq'd.
- Raptor 6.x — remote exploit (CERIAS, Bugtraq'd).
- NetBSD — panic on unaligned IP options (NHC20000504a.0, NHC Research).
- BeOS 5.0 — remote DoS via TCP fragmentation lock-up (AUX Technologies).
- MS ISA Server — event DoS (Defcom Labs advisory def-2001-16).
- v0.06 — various DoS bugs (crash/hang/freeze) found by vendors' internal tests.
ISIC is Copyright © 1999–2007 Shu Xiao (San Jose, CA, USA) and Mike Frantzen
(Chicago, IL, USA). All rights reserved. Released under the Modified BSD Source
License — redistribution in source and binary form is permitted provided the
copyright notice and disclaimer are retained. See LICENSE for the
full text. This fork does not change those terms.