A Wi-Fi deauthentication attack exploits unencrypted management frames to forcibly disconnect a client from an access point, enabling denial-of-service or adversary-in-the-middle attacks. It is a foundational wireless attack technique and a common precursor to the evil twin attack.
Wi-Fi Deauthentication Attack
When two devices are connected wirelessly, everything is done through the air. So here we've got a client machine talking to an access point, and all of the communication can be seen by everyone else. This could be encrypted, but not all of the data that's being passed back and forth is encrypted. This means as an attacker we can listen in on this conversation and see a lot of valuable information. For instance, we can see what the MAC address is of these two devices, this access point and this client over here.
One thing during Wi-Fi communication is that a client can ask to be deauthenticated. This essentially just means that they're done communicating. So if a machine says, hey, I'm done communicating, then there's no longer need for communication back and forth.
The thing is that this is easily spoofed. As an attacker, we can listen in on the conversation here, see what the MAC address is of this machine, and then emulate that and send it to the access point. And then this access point is going to deauthenticate, or stop communication with, this client machine. Therefore, this is a way that we can carry out a denial of service attack.
This is often a precursor to an evil twin attack, where we can start emulating this access point. Now, sending this deauthentication will disconnect the client from that access point. That client will then try to set up that communication again and will reauthenticate. And if you act as a rogue access point that this machine is making a connection to, now you can carry out an adversary attack — or, since this is wireless, it's called an evil twin attack.
So here's our attack card on our Wi-Fi deauthentication attack. Essentially, it's a way that we can carry out a denial of service attack, or the precursor to doing something like an adversary in the middle attack, where we can send a deauthentication to the access point disconnecting the communication between a client and that access point. Now that client is going to try to reestablish that connection, and we can block that, or we can use ourselves as being an evil twin mimicking this access point and then getting in between, carrying out an adversary in the middle attack.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →