Blade Software makes an IDS/IPS testing tool.

However, the most important thing you can do for testing an IPS is full content. Just throwing a packet at the IPS with the exploit in it is pointless. You have to be able to throw full session conversations at it. Use fragroute. Break the attack up across several packets. This is really the only way to truly test an IPS.

Oh, and do this billions of times.