Ettercap works by putting the network interface into promiscuous mode and by ARP poisoning the target machines. Thereby it can act as a 'man in the middle' and unleash various attacks on the victims. Ettercap has plugin support so that the features can be extended by adding new plugins.
Ettercap supports active and passive dissection of many protocols (including ciphered ones) and provides many features for network and host analysis. Ettercap offers four modes of operation:
In addition, the software also offers the following features:
Ettercap also has the ability to actively or passively find other poisoners on the LAN.
"The men behind ettercapNG". Linux.com. 2004-11-09. Retrieved 2021-08-20. https://www.linux.com/news/men-behind-ettercapng/ ↩
Jeffries, Adrianne (2013-09-13). "Meet Hacking Team, the company that helps the police hack you". The Verge. Retrieved 2021-08-20. https://www.theverge.com/2013/9/13/4723610/meet-hacking-team-the-company-that-helps-police-hack-into-computers ↩