lsrscan FAQ:

1 - General information about Source Routing
  1.1 - How does source routing work?
  1.2 - Why was source routing created?
  1.3 - What are the security implications of source routing?
  1.4 - What do systems do with source routed packets?
2 - Problems with lsrscan
  2.1 - configure is giving me libpcap errors! What's wrong?
  2.2 - What's the difference between a TO and THROUGH scan?
  2.3 - Why does lsrscan only do loose source routing?

***   Section 1: General information about Source Routing   ***

   1.1 - How does source routing work?

Source routing allows end points to specify within a packet which IP
addresses that packet must be routed through. There are two flavors
of source routing, loose and strict. In strict source routing, each
hop must explicitly be specified, with no intervening hops. In loose
source routing, the intervening hops between the hops contained in
the source route are specified by the intervening hardware.

The way this actually works at the packet level is that the source IP
address remains untouched throughout the packet lifetime. The destination
IP address will be set to the next hop in the source route. Thus, backbone
routers can route the packets as they normally would, without having to
dig down into the IP options field. When the packet reaches that hop,
it is the responsibility of the end computer to rewrite the packet,
replacing the destination IP address with the next hop in the source
route, and reissuing the packet.

When a source routed packet reaches its final destination, the target
OS will often respond with a source routed packet that reverses the
source route it receiveed the packet from.

   1.2 - Why was source routing created?

Source routing was created as a method of debugging routing problems
by being able to specify endpoints that the packets must travel along.
It is still used today by some large ISPs to verify that peers are
routing packets appropriately, and not simply dumping traffic onto
each others links at the earliest opportunity. 

   1.3 - What are the security implications of source routing?

There are two primary security implications of source routing. (That I've
thought of. Anyone with others, please let me know). The first is that
it is trivial to spoof IP addresses against machines that reverse source
routes. Simply pose your IP as one of the middle hops in the source
route, and spoof the source IP. The target machine will route all replies
back to you, and you can have complete conversations without the spoofed
IP ever receiving a packet.

The second is that source routing allows non-public IP addresses to
be reached, if the gateway forwards source routed packets. Use
the gateway as an intermediate hop, and even if the public internet
doesn't know how to get to 10.0.0.x, the gateway does.

   1.4 - What do systems do with source routed packets?

Systems I have tested so far:
  OpenBSD 3.0 : Default sets the kernel variable net.inet.ip.sourceroute to 0
  Solaris <= 7: Will respond to and reverse LSR packets.
  Solaris >= 8: Will respond to LSR packets, but will not reverse route.
  Windows     : Will respond to and reverse LSR packets.
(98, 2000, and XP tested)

***   Section 2: Problems with lsrscan   ***

   2.1 - configure is giving me libpcap errors! What's wrong?

This question pops up most often when people are told by configure
to install a newer version of libpcap, they do, but the error stays.
The issue is most often that your OS has a copy of libpcap in /usr/lib,
and the new version of libpcap is installed in /usr/local/lib.
Without the LIBRARY_PATH environment variable set to put /usr/local/lib
before /usr/lib, the wrong libpcap is getting linked against. Set
your LIBRARY_PATH, or use the --with-pcap=PATH option in configure
to fix.

   2.2 - What's the difference between a TO and THROUGH scan?

A THROUGH scan simply checks to see if a system will forward a
source routed packet if it is listed as one of the hops. You could
also check this functionality with a traceroute -g. A TO scan
checks to ensure that a host will reverse the source route when
replying to a source routed packet.

   2.3 - Why does lsrscan do only loose source routing?

Personal choice. Strict source routing is too difficult to use, IMO,
and it doesn't really let you do anything you can't do with loose
source routing. It's really easy to add, but I don't think it would be
worth the confusion it could cause in the man page. 
