EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingHard
A penetration tester is performing a wireless assessment on a corporate network. They discover an access point that is broadcasting a hidden SSID and is configured with WPA2-Personal. The tester attempts to capture a 4-way handshake, but no active clients are connected. To force a handshake capture, the tester uses a tool to send a deauthentication packet to a client that is associated with the target AP from a distance. Which specific 802.11 frame type is the tester leveraging for this action?
- ABeacon frame
- BDeauthentication frame
- CProbe request frame
- DAssociation request frame
Show answer & explanationAnswer & explanation
Correct answer: B. Deauthentication frame
A deauthentication frame is an 802.11 management frame used to disconnect a client from an access point. Attackers can spoof these frames to force clients to reauthenticate, thereby generating a 4-way handshake that can be captured for cracking WPA/WPA2-Personal keys.
Why the other options are wrong
- A. Beacon frames are sent by APs to advertise their presence and network parameters; they do not disconnect clients.
- C. Probe request frames are sent by clients to discover nearby APs; they do not disconnect clients.
- D. Association request frames are sent by clients to request connection to an AP; they are part of the connection process, not disconnection.
802.11 Deauthentication Frame
An 802.11 deauthentication frame is a management frame used to terminate an existing connection between a wireless client and an access point.
- It is an unauthenticated frame, making it vulnerable to spoofing.
- Attackers use it to force clients to disconnect and reauthenticate.
- This action generates a 4-way handshake, which can be captured for cracking.
Memory trick: Deauth frames unplug clients, making handshakes appear.