Deauthentication Attacks

Force devices to disconnect from a Wi-Fi network

On this page

Deauthentication (deauth) attacks force devices to disconnect from a Wi-Fi network. This is useful for testing network resilience or capturing authentication handshakes when devices reconnect.

Note: Only perform deauth attacks on networks you own or have permission to test. See Legal and ethical rules.

How it works

Wi-Fi networks use management frames to coordinate connections. Two of these frames can terminate a connection:

  • Deauthentication frame: Ends the authentication relationship
  • Disassociation frame: Ends the association relationship

GhostESP sends both frame types. Since these frames are part of the original Wi-Fi standard (802.11), most devices have no way to verify if the message is legitimate.

How a deauth disconnects a client
ClientAPAttacker
authenticated and associatedFrame: Association Addr1 (AP): the BSSID Addr2 (client): station MAC
forged Deauth (from the AP)Deauthentication (subtype 0x0C) Reason 7 (class 3 frame from nonassociated STA) Addr1 (dest): client Addr2 (src): AP BSSID
forged Deauth (from the client)Deauthentication (subtype 0x0C) Reason 7 Also sends a Disassociation frame (subtype 0x0A) Addr1 (dest): AP BSSID Addr2 (src): client MAC
reconnection attemptBroadcast deauths (dest `FF:FF:FF:FF:FF:FF`) hit every client on the AP

GhostESP forges the frames in both directions, so the client and the AP each believe the other ended the connection.

Broadcast and targeted attacks

The attack sends frames in two ways:

  1. Broadcast (FF:FF:FF:FF:FF:FF): Hits all devices on the network without needing to know who’s connected
  2. Targeted: If you’ve scanned for stations (scansta), GhostESP automatically includes any discovered clients associated with the selected AP

Bidirectional frames

For targeted stations, GhostESP sends frames in both directions:

  • AP → Station: Appears to come from the access point, telling the device to disconnect
  • Station → AP: Appears to come from the device, telling the AP the device is leaving

This makes the attack more reliable since both sides think the connection ended.

Frequency band limitations

2.4 GHz only (most boards)

Most ESP32 boards (ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6) only support 2.4 GHz Wi-Fi. This means:

  • You can only deauth networks on channels 1-14
  • 5 GHz networks are invisible and unaffected
  • Many modern routers use both bands-devices on the 5 GHz band will stay connected

5 GHz support (ESP32-C5)

The ESP32-C5 supports both 2.4 GHz and 5 GHz bands, allowing you to:

  • Scan and attack networks on all Wi-Fi channels
  • Target devices on 5 GHz networks

If your target network uses 5 GHz, you need an ESP32-C5 based device.

Protected management frames (PMF)

PMF (also called MFP or 802.11w) is a security feature that cryptographically signs management frames. When enabled, devices can verify that deauth frames actually came from the real access point.

Networks immune to deauth

  • WPA3 networks: PMF is mandatory. Deauth attacks will not work.
  • WPA2/WPA3 mixed mode: Devices using WPA3 are protected; WPA2 devices may still be vulnerable.
  • WPA2 with PMF enabled: Some enterprise networks enable PMF on WPA2.

How to check

When you scan networks on an ESP32-C5 or ESP32-C6, GhostESP shows the security type and PMF status:

SSID: MyNetwork
Band: 2.4GHz
Security: WPA3
PMF: Required

If you see PMF: Required, deauth attacks will have no effect on that network.

Prerequisites

  • GhostESP device
  • Target network on a supported frequency band (2.4 GHz for most boards, or 5 GHz with ESP32-C5)
  • Country code set in device settings (see Troubleshooting if you get errors)

Launching a deauth attack

On-device UI

  1. Open Menu → Wi-Fi → Scanning and wait for the scan to complete.
  2. Select your target with Select AP.
  3. Open Menu → Wi-Fi → Attacks → Deauth Attack.
  4. The device will continuously send deauth frames to all clients on that network.
  5. To stop, run stopdeauth in the terminal.

CLI

  1. Scan for networks:
    scanap
    
  2. List results:
    list -a
    
  3. Select your target (replace 1 with the network number):
    select -a 1
    
  4. Start the attack:
    attack -d
    
  5. Stop the attack:
    stopdeauth
    

Targeting multiple networks

You can select multiple access points at once:

select -a 1,3,5
attack -d

GhostESP iterates the selected APs in selection order, tuning to each AP’s channel as it goes. Order your selection with this in mind if you want to reduce channel switching.

Troubleshooting

ESP_ERR_INVALID_ARG when deauthing

This error occurs when attempting to deauth a network on a channel not allowed by your current country code setting. The default country is US (index 0), which permits channels 1-11. (The 01 “World Safe” entry is only the fallback used when a settings slot is out of range, not the boot default.)

If your target network is on channel 12, 13, or 14, you must set the correct country code first.

Fix via on-device UI:

  1. Open Menu → Settings → Wi-Fi Country.
  2. Select your region.
  3. Restart the device.

Fix via CLI (all targets):

setcountry <CC>

Replace <CC> with one of the supported country codes (the setcountry command is documented in the CLI Reference):

CodeRegionCodeRegionCodeRegion
01World SafeATAustriaAUAustralia
BEBelgiumBGBulgariaBRBrazil
CACanadaCHSwitzerlandCNChina
CYCyprusCZCzechiaDEGermany
DKDenmarkEEEstoniaESSpain
FIFinlandFRFranceGBUnited Kingdom
GRGreeceHKHong KongHRCroatia
HUHungaryIEIrelandINIndia
ISIcelandITItalyJPJapan
KRSouth KoreaLILiechtensteinLTLithuania
LULuxembourgLVLatviaMTMalta
MXMexicoNLNetherlandsNONorway
NZNew ZealandPLPolandPTPortugal
RORomaniaSESwedenSISlovenia
SKSlovakiaTWTaiwanUSUnited States

Channel availability by region:

  • US, Canada (US, CA): Channels 1-11
  • Europe, Australia (GB, DE, AU, etc.): Channels 1-13
  • Japan (JP): Channels 1-14

Attack has no effect

  • Check the band: If the network is on 5 GHz and you’re using a 2.4 GHz-only board, the attack won’t work.
  • Check for PMF: WPA3 networks and some WPA2 networks with PMF enabled are immune.
  • Multiple APs: Some networks have multiple access points. You may need to target each one separately.
  • Distance: Get closer to the access point for a stronger signal.

Devices reconnect immediately

Devices reconnect immediately after being kicked. If they keep getting back on:

  • Make sure you’re only targeting one or two networks
  • Move closer to the access point
  • Check for other interference

The attack command selects from several management-frame attacks. See Other attack modes in Wi-Fi Basics for what each one does, and the CLI Reference for the exact flags.

All of these stop with stopdeauth, which halts every running Wi-Fi attack.