skip to content

IPv4's Loose Source and Record Route option is still required of routers by RFC 1812, yet networks commonly discard source-routed packets; why, and what does the option let an attacker do?

level: seniorimportance: nice to knowfreq 12%

answer

  1. the sender picks the path
  2. destination field rewritten at each listed hop
  3. replies reverse the recorded route
  4. routing as a security boundary
  5. a discard switch, off by default

basics

~20 s

LSRR lets a sender list routers a datagram must visit, overriding normal routing, and the receiver reverses that list for replies. An attacker can bypass routing-based separation or spoof a trusted address and still receive replies, so many operators discard it.

solid answer

~50 s

The option (type 131) carries a pointer and a list of addresses. When the datagram reaches the address in its destination field, that node copies the next listed address into the destination field and records its own, so the datagram visits points the sender chose; Strict Source and Record Route (type 137) also demands each listed hop be directly connected. Two properties make it dangerous. It overrides routing, so separation built from routing tables can be crossed — RFC 1812's own discussion says so, and adds that filters away from the final leg can be bypassed. And endpoints reverse a received source route for replies: RFC 1122 passes it up for reversal and RFC 9293 makes a passive TCP use it for the connection, so a forger who lists itself as a hop receives the replies. RFC 1812 still requires support and says a discard setting MUST NOT be on by default; operators enable discarding anyway.

go deeper

for a junior

Recall that IPv4 headers can carry options after the 20 fixed bytes, and that source routing lets the sender choose routers the packet must visit.

for a middle

Explain the option format — copied flag, class, number, length — the 40-byte limit, and how loose source routing rewrites the destination field at each listed hop.

for a senior

Explain both attacks, routing-control bypass and reply reversal for spoofed sources, and justify discarding source-routed packets at the edge despite RFC 1812's default.

for a principal

Weigh diagnostic value against attack surface when a requirements RFC lags practice, and decide where in the network such options are dropped, logged or allowed.

## How IPv4 options are encoded An IPv4 header can carry options after its 20 fixed bytes, up to **40 bytes** in all (the 4-bit `IHL` stops at 15 words, 60 bytes). RFC 791 defines two shapes: - **Single-octet options:** End of Option List (type 0) and No Operation (type 1). - **Type-length-value options:** a type octet, a length octet that counts itself and the type, then data. The type octet has three parts: a **copied flag** (1 bit: copy into every fragment?), an **option class** (2 bits: 0 control, 2 debugging and measurement), and an **option number** (5 bits). | Option | Type | Copied | Purpose | |---|---|---|---| | End of Option List | 0 | no | marks the end of options | | No Operation | 1 | no | alignment padding between options | | Security | 130 | yes | handling labels; RFC 1812 calls the RFC 791 form obsolete | | Loose Source and Record Route | 131 | yes | sender-chosen waypoints, any path between them | | Strict Source and Record Route | 137 | yes | sender-chosen hops, each directly connected | | Record Route | 7 | no | each router appends its address | | Stream ID | 136 | yes | obsolete; RFC 1812 says ignore it | | Internet Timestamp | 68 | no | routers add timestamps | RFC 791 says every IP module must **implement** options; only carrying them is optional. ## What source routing does on the wire The option holds a **pointer** and a list of 4-byte addresses. Processing (RFC 791): 1. The datagram is routed normally toward the address in the header's `Destination Address`. 2. When it **reaches** that address and the pointer is not past the end of the list, the node **replaces the destination field with the next listed address**. 3. It writes **its own outgoing address** into the slot it just consumed — the record-route half — and advances the pointer by 4. 4. The header keeps the same length the whole way. 5. When the pointer passes the end, the list is spent and routing proceeds on the destination field alone. With **loose** routing, any number of routers may sit between listed hops. With **strict** routing, each listed hop must be reached directly over a connected network, or the datagram cannot be delivered. ## Why the option is dangerous - **It overrides routing.** RFC 1812 section 5.3.13.4's discussion warns that source routing "may be used to bypass administrative and security controls", especially where routing tables, rather than filters, separate networks. - **It can slip past filters.** The same section adds that packet filtering "can be defeated by source routing" when applied anywhere except the final leg of the source-routed path. - **It turns blind spoofing into a conversation.** RFC 1122 requires a host to pass a completed source route up so it can be reversed for replies; RFC 9293 requires a passive TCP that receives one to **save the return route and use it** for the whole connection. An attacker forges a trusted source such as 192.0.2.10, lists its own address 203.0.113.5 as a hop, and the target sends its replies back through the attacker. - **Record Route and Timestamp disclose topology**, revealing internal router addresses and timing. ## What the RFCs say versus what networks do | Rule | Source | |---|---| | Routers MUST support source route options in forwarded packets | RFC 1812, 5.3.13.4 | | Routers MAY offer a setting that discards all source-routed packets | RFC 1812, 5.3.13.4 | | That setting MUST NOT be enabled by default | RFC 1812, 5.3.13.4 | | Routers MUST ignore options they do not recognise | RFC 1812, 4.2.2.6 | | Hosts MUST support originating and terminating source routes | RFC 1122, 3.2.1.8 | RFC 1812 dates from 1995. Operators commonly enable discarding at their edges, and many host stacks expose a setting to refuse source-routed datagrams; both are operational choices layered on top of a requirements document that still asks for support. Separately, many router implementations process option-bearing packets on a slower path than plain ones, which makes floods of them a load concern — an implementation trait, not a protocol rule. ## The IPv6 parallel, in one line IPv6 faced the same problem with its Type 0 Routing Header, and RFC 5095 deprecated it after it was shown to enable traffic amplification. ## What to say in an interview 1. Define the option precisely: a list of waypoints, a pointer, and the destination field rewritten at each listed hop. 2. Name both dangers: routing-based controls bypassed, and spoofed sources that still get replies through reversal. 3. Give the twist: the router requirements still mandate support with discarding off by default, and operators override that.

  • Why can the IPv4 Record Route option capture only a short path?
    Options share at most 40 bytes, because IHL tops out at 15 words, 60 bytes, of which 20 are fixed. Record Route spends 3 bytes on type, length and pointer, leaving 37, enough for nine 4-byte addresses. Once the list is full, RFC 791 says routers forward the datagram without recording, so longer paths come back truncated.
  • Does discarding source-routed IPv4 packets at a network's edge close the attack completely?
    It closes the inbound path: forged source-routed datagrams no longer reach internal hosts, which matters because RFC 1812 notes that ordinary packet filters can be bypassed by source routing unless they sit on the path's final leg. The reply half is a host behaviour, so host stacks that refuse or ignore received source routes close it from the other side.

saying these in an interview costs you the question

  • Loose source routing only records the path; it cannot change where a datagram goes.
  • RFC 1812 forbids routers from forwarding source-routed packets.
  • A forged source address can never receive replies, so spoofing is always blind.
  • IPv4 options are rare because RFC 791 made implementing them optional.
  • IPv4 options can grow the header to any size the Total Length allows.