Manual Page - ettercap(8)
i know, i know. it says tcpdump or ethereal. however (as i'm sure you already know) wireshark will import a tcpdump .lpc all day long.-w, --write <FILE>
WRITE packet to a pcap file
This is useful if you have to use "active" sniffing (arp poison) on a switched LAN but you want to analyze the packets with tcpdump or ethereal. You can use this option to dump the packets to a file and then load it into your favourite application.
good luck with that.