lsrtunnel requires libpcap version 0.4 or greater ( http://tcpdump.org ) and 
libdnet version 1.2 or greater ( http://libdnet.sourceforge.net ) to work.

lsrtunnel assists in spoofing connections to a remote host using
loose source routed frames. To do this, lsrtunnel makes use of an
unused IP address, where it can receive packets without a real IP
stack getting in the way.

There are four fundamental IPs that come into the spoofing story
of lsrtunnel. They are, in no particular order:

Your IP. This is the IP of the default interface of the box you're
running lsrtunnel on.

The remote IP. This is the IP of the box you are going to be spoofing
packets to. This IP must reverse source routed frames, or lsrtunnel
won't work.

The spoofed IP. This is the poor sucker you will be posing as, 
who the remote box thinks it is communicating with. If all goes
well, this IP will never recieve a packet.

The silent IP. This is an IP on the same subnet as your IP, that
has no IP stack getting in the way and mucking things up. 

When lsrtunnel starts, it will fork off a child that will update
the kernel ARP table, so that the local host believes that the
silent IP has a hardware address, and won't sit around and ARP for it
all day. The child will also listen for ARP requests for the
silent IP, and reply with your default interface's MAC addr. Basically
the child is in charge of ensuring packets intended for the silent
IP make it to your interface to be sniffed and dealt with appropriately.

Meanwhile, the parent will repackage any packet that comes to it
from the ip of the machine destined to the silent IP address as
a packet from the spoofed machine, destined to the remote
machine, which happens to be source routed using the silent IP
as an intermediate hop.

Packets that come to the silent IP from the remote IP will be
repackaged as packets from the silent IP destined to your IP.
In this way, you should be able to point any TCP based client
at the silent IP from your machine, and connect to the remote
machine, showing up in the logs as (and gaining any priveleges
of) the spoofed sucker.

Known issues: ssh sessions will fail to connect, giving a 
bad packet length error. Curiously, single commands can be run
over ssh, but logging in remotely is broken. Telnet, rsh, rlogin,
etc. all work flawlessly, so it's not just a tty thing. Something
about ttys over ssh particularly, perhaps? Anyone who knows the
protocol please let me know!

--Todd
