EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingHard

A penetration tester is performing a wireless assessment on a corporate network. They discover an access point that is broadcasting a hidden SSID and is configured with WPA2-Personal. The tester attempts to capture a 4-way handshake, but no active clients are connected. To force a handshake capture, the tester uses a tool to send a deauthentication packet to a client that is associated with the target AP from a distance. Which specific 802.11 frame type is the tester leveraging for this action?

  1. ABeacon frame
  2. BDeauthentication frame
  3. CProbe request frame
  4. DAssociation request frame
Show answer & explanation

Correct answer: B. Deauthentication frame

A deauthentication frame is an 802.11 management frame used to disconnect a client from an access point. Attackers can spoof these frames to force clients to reauthenticate, thereby generating a 4-way handshake that can be captured for cracking WPA/WPA2-Personal keys.

Why the other options are wrong

  • A. Beacon frames are sent by APs to advertise their presence and network parameters; they do not disconnect clients.
  • C. Probe request frames are sent by clients to discover nearby APs; they do not disconnect clients.
  • D. Association request frames are sent by clients to request connection to an AP; they are part of the connection process, not disconnection.

802.11 Deauthentication Frame

An 802.11 deauthentication frame is a management frame used to terminate an existing connection between a wireless client and an access point.

  • It is an unauthenticated frame, making it vulnerable to spoofing.
  • Attackers use it to force clients to disconnect and reauthenticate.
  • This action generates a 4-way handshake, which can be captured for cracking.

Memory trick: Deauth frames unplug clients, making handshakes appear.

More Wireless Network Hacking questions