Deauth Attacks
Wireless deauthentication attacks are a critical vector in network disruption and interception, leveraging the inherent vulnerabilities of wireless communication protocols. These attacks force clients to disconnect from an access point (AP), often triggering reassociation attempts that can be exploited for further attacks like EAP-Hammer. Understanding their mechanics and countermeasures is essential for both offensive analysis and defensive hardening.
Mechanics of Deauthentication Attacks¶
Deauthentication attacks exploit the IEEE 802.11 protocol's broadcast nature by flooding the airwaves with deauthentication frames. These frames target either all connected clients (broadcast) or specific devices (unicast), prompting them to terminate their association with the AP.
Attack Workflow:
1. Target Identification: The attacker identifies the AP's BSSID and connected clients using tools like airodump-ng.
2. Frame Injection: Using tools like aireplay-ng, the attacker sends deauthentication packets to force disconnection.
3. Reassociation Exploitation: Clients attempt to reconnect, potentially reassociating with the attacker's rogue AP or exposing credentials during the reauthentication process.
Impact:
- Network instability and denial of service (DoS).
- Vulnerability to MITM attacks during reassociation.
Example Command:
Mitigation Strategies¶
1. TKIP Rekeying¶
TKIP (Temporal Key Integrity Protocol) rekeying is a WPA/WPA2 mechanism that forces clients to reassociate with the AP after a deauthentication event. This delays the client's ability to reconnect, reducing the window for exploitation. However, some clients may not handle rekeying correctly, leaving gaps in protection.
Configuration Note: Ensure TKIP rekeying is enabled on the AP (typically default in WPA/WPA2).
2. Client-Side Protections¶
- WPA3 Adoption: WPA3 introduces stronger protections against deauthentication by requiring explicit reauthentication and mitigating replay attacks.
- Client Isolation: Configure clients to ignore deauthentication frames or use tools like
wpa_supplicantwithdeauth_protection=1to resist spoofed frames. - Network Monitoring: Deploy tools like
Wiresharkto detect deauthentication traffic:
3. Network Hardening¶
- MAC Address Filtering: Restrict access to known devices, though this can be bypassed by spoofing.
- Rate Limiting: Cap the number of deauthentication packets per second to deter automated attacks.
- 802.1X Enforcement: Ensure EAP methods (e.g., EAP-TLS) are used to secure reauthentication attempts.
Key takeaways¶
- Deauthentication attacks disrupt wireless connectivity and enable MITM scenarios during reassociation.
- TKIP rekeying and WPA3 provide partial mitigation, but client-side configurations are critical.
- Network monitoring and rate limiting are essential for detecting and mitigating deauthentication attempts.
- Always validate tools and configurations for authorized testing environments.