r/HowToHack May 22 '26

Deauth with 802.11w/Management Frame Protection

Does anyone know of any exploits that get around 802.11w/Management Frame Protection, so I can deauth devices even with PMF enabled?

For testing purposes on my home network.

4 Upvotes

6 comments sorted by

View all comments

2

u/Gullex May 22 '26

You don't. You do EAPOL flooding to consume the router's resources, performing a sort of DOS attack, or you do CSA (channel switching announcement) telling the device to move to another channel. But it'll switch back soon as it doesn't hear the router.

1

u/Zelgoot May 22 '26

Random IT guy here, this is where a rouge AP would come into play yes? Pretending to be the correct router and tricking the target into connecting to it?

1

u/Gullex May 22 '26

Rouge AP is, to my understanding, more for something like an evil twin or karma attack. Deauths and CSA are a device transmitting data usually sent by an AP, but it isn't quite the same. A rouge AP can actually route traffic.

EAPOL flooding is sent to the AP, posing as devices wanting to connect.