{"id":194,"date":"2014-05-11T13:45:13","date_gmt":"2014-05-11T05:45:13","guid":{"rendered":"http:\/\/matnet.my\/blog\/?p=194"},"modified":"2014-05-28T10:37:03","modified_gmt":"2014-05-28T02:37:03","slug":"the-behaviour-of-legit-de-auth-frame-and-malicious-de-auth-frame","status":"publish","type":"post","link":"https:\/\/matnet.my\/blog\/2014\/05\/the-behaviour-of-legit-de-auth-frame-and-malicious-de-auth-frame\/","title":{"rendered":"The behaviour of legit De-Auth frame and Malicious De-Auth frame"},"content":{"rendered":"<p>I have done several testbed to looks details on the De-Auth frames.<\/p>\n<p>This is the legit de-auth packet sent from client to AP.<\/p>\n<p><a href=\"https:\/\/matnet.my\/blog\/wp-content\/uploads\/2014\/05\/legit.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-195\" src=\"https:\/\/matnet.my\/blog\/wp-content\/uploads\/2014\/05\/legit.png\" alt=\"legit\" width=\"681\" height=\"193\" srcset=\"https:\/\/matnet.my\/blog\/wp-content\/uploads\/2014\/05\/legit.png 681w, https:\/\/matnet.my\/blog\/wp-content\/uploads\/2014\/05\/legit-300x85.png 300w\" sizes=\"auto, (max-width: 681px) 100vw, 681px\" \/><\/a><\/p>\n<p>Here is De-Auth packet sending by aireplay-ng with command :<\/p>\n<pre class=\"code\"><strong><span style=\"color: #ff0000;\">aireplay-ng -0 1 -a 10:FE:ED:F6:C1:A0 -c 00:1F:3C:E4:AF:7F mon0<\/span><\/strong>\r\n\r\nWhere : \r\n\r\n-0 - Means deauthentication<\/pre>\n<pre class=\"code\">1  - Number of deauth<\/pre>\n<pre class=\"code\">-a 00:14:6C:7E:40:80 - MAC address of deauth packet<\/pre>\n<pre class=\"code\">-c 00:0F:B5:34:30:30 - MAC address of station\r\n\r\nmon0 - the interface name<\/pre>\n<p><a href=\"https:\/\/matnet.my\/blog\/wp-content\/uploads\/2014\/05\/deauth-attack.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-196\" src=\"https:\/\/matnet.my\/blog\/wp-content\/uploads\/2014\/05\/deauth-attack.png\" alt=\"deauth-attack\" width=\"674\" height=\"218\" srcset=\"https:\/\/matnet.my\/blog\/wp-content\/uploads\/2014\/05\/deauth-attack.png 674w, https:\/\/matnet.my\/blog\/wp-content\/uploads\/2014\/05\/deauth-attack-300x97.png 300w\" sizes=\"auto, (max-width: 674px) 100vw, 674px\" \/><\/a><\/p>\n<p>So what we have here ?<\/p>\n<p>1. The legitimate de-auth packet just send only 1 packet to de-auth<\/p>\n<p>2. The legitimate de-auth packet length is 39 bit where malicious de-auth sending 44 bit length<\/p>\n<p>3. De-auth attacks using aireplay-ng with 1 deauth will send 128 packet which is 64 packet to the AP and 64 to the Client as depicted above.<\/p>\n<p>4. On the reason code for the legit deauth is Code 3 that is sending STA is leaving, but from the malicious deauth packet send Code 7 &#8211; Class 3 received from non associated station.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I have done several testbed to looks details on the De-Auth frames. This is the legit de-auth packet sent from &hellip; <a href=\"https:\/\/matnet.my\/blog\/2014\/05\/the-behaviour-of-legit-de-auth-frame-and-malicious-de-auth-frame\/\" class=\"more-link\">More <span class=\"screen-reader-text\">The behaviour of legit De-Auth frame and Malicious De-Auth frame<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-194","post","type-post","status-publish","format-standard","hentry","category-cs778","standard"],"_links":{"self":[{"href":"https:\/\/matnet.my\/blog\/wp-json\/wp\/v2\/posts\/194","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/matnet.my\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/matnet.my\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/matnet.my\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/matnet.my\/blog\/wp-json\/wp\/v2\/comments?post=194"}],"version-history":[{"count":4,"href":"https:\/\/matnet.my\/blog\/wp-json\/wp\/v2\/posts\/194\/revisions"}],"predecessor-version":[{"id":205,"href":"https:\/\/matnet.my\/blog\/wp-json\/wp\/v2\/posts\/194\/revisions\/205"}],"wp:attachment":[{"href":"https:\/\/matnet.my\/blog\/wp-json\/wp\/v2\/media?parent=194"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/matnet.my\/blog\/wp-json\/wp\/v2\/categories?post=194"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/matnet.my\/blog\/wp-json\/wp\/v2\/tags?post=194"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}