Toorcon 9 – Caffe Latte Attack
Although I didn’t attend, I tried to keep track of all the keynotes, and blog submissions of last weekends Toorcon 9 (October 19-21). Here you will find a brief synopsis of what took place, or at least what I came to find of interest. As more information
becomes available I will continue to post.
[Cafe Latte Attack]
A shame if your still using WEP…
Vivek Ramachandran’s Cafe Latte attack was one of the last talks. It’s fairly simple and deals with cracking WEP keys from unassociated laptops. First your WEP honeypot tells the client that it has successfully associated. The next thing the client does is broadcast a WEP encrypted ARP packet. By flipping the bits in the ARP packet you can replay the WEP packet and it will appear to the client to be coming from an IP MAC combo of another host on the network. All of the replies will have unique IVs and once you get ~60K you can crack it using PTW. The bit flipping is the same technique used in the fragmentation attack, but Cafe Latte requires generation of far fewer packets. – Hackaday
You can read about the Cafe Latte attack on AirTight Networks.
Download of the Presentation – PowerPoint Presentation Link
View the presentaion via Google Video Link