How to Use Fake QUIC Initial Packets for DPI Bypass in zapret-discord-youtube
Run any general*.bat script to automatically inject pre-generated QUIC Initial packets via winws.exe, confusing DPI engines and allowing YouTube and Discord traffic to bypass stateful inspection.
The zapret-discord-youtube repository provides Windows-based Deep Packet Inspection (DPI) circumvention tools powered by WinDivert. To evade blocking on services that inspect QUIC handshakes, the toolset employs fake QUIC Initial packets that desynchronize inspection engines by disrupting their state tracking mechanisms.
How Fake QUIC Initial Packets Bypass DPI
DPI engines typically implement stateful tracking of QUIC connections, expecting a sequential handshake: Initial → Handshake → 0‑RTT. The bypass technique exploits this assumption by injecting standalone QUIC Initial packets that mimic legitimate connection starts but never progress to the next state.
When winws.exe transmits these synthetic packets (stored as raw binary blobs), the DPI system allocates resources to track a handshake that never completes. The original application traffic interleaves with these decoys, causing the inspection engine to drop or ignore the genuine connection while waiting for follow-up packets that never arrive. This desynchronization allows encrypted traffic to pass through uninspected.
The Injection Mechanism
In general.bat, the launcher constructs a WinDivert filter that attaches to UDP port 443. The critical parameter --dpi-desync-fake-quic instructs winws.exe to read the raw packet data from bin/quic_initial_www_google_com.bin (for Google/YouTube) or bin/quic_initial_dbankcloud_ru.bin (for Discord) and periodically inject these bytes into matching outbound flows.
"%BIN%winws.exe" ^
--wf-udp=443 ^
--filter-udp=443 ^
--dpi-desync=fake ^
--dpi-desync-repeats=6 ^
--dpi-desync-fake-quic="%BIN%quic_initial_www_google_com.bin"
The binary files contain actual QUIC Initial packets captured from legitimate connections, ensuring the decoys bear authentic headers and random values that DPI heuristics expect.
Configuration Parameters
The following winws.exe options control the fake QUIC behavior:
--dpi-desync-fake-quic: Path to the raw binary file containing the QUIC Initial packet to inject. Typical values includebin/quic_initial_www_google_com.binfor Google services andbin/quic_initial_dbankcloud_ru.binfor Discord.--filter-udp: Specifies the UDP ports where the rule applies, typically443for HTTPS-over-QUIC.--dpi-desync-repeats: Controls injection frequency per connection. Values range from6(standard) to11(aggressive strategies).--dpi-desync: Enables the desynchronization mode; must be set tofakefor QUIC injection to function.
Running the Default Strategy
Using the Standard Batch Scripts
Execute the default Google/YouTube strategy by running the batch file with administrator privileges:
general.bat
This script automatically resolves the BIN path and launches winws.exe with the QUIC desync parameters preconfigured.
Manual Execution with winws.exe
For debugging or custom configurations, invoke winws.exe directly from an elevated command prompt:
set BIN=C:\path\to\zapret\bin\
"%BIN%winws.exe" ^
--wf-udp=443 ^
--filter-udp=443 ^
--dpi-desync=fake ^
--dpi-desync-repeats=6 ^
--dpi-desync-fake-quic="%BIN%quic_initial_www_google_com.bin"
This command attaches to all UDP port 443 traffic and injects the fake Google QUIC Initial packet six times per detected flow.
Customizing Fake QUIC Payloads
Replacing the Packet Binary
To test a different QUIC Initial payload captured from another domain, replace the binary file while preserving the filename expected by the script:
copy my_custom_quic.bin "%~dp0bin\quic_initial_www_google_com.bin"
general.bat
Alternatively, modify the --dpi-desync-fake-quic path in general.bat to point to your custom binary without renaming it.
Using Aggressive Strategies
The repository includes variants like general (FAKE TLS AUTO).bat that employ identical QUIC injection with higher repeat counts:
"general (FAKE TLS AUTO).bat"
This variant uses --dpi-desync-repeats=11, suitable for networks with particularly persistent DPI inspection engines.
Disabling QUIC Desync for Testing
To observe connection behavior without QUIC injection, remove the --dpi-desync-fake-quic parameter from the launch command:
"%BIN%winws.exe" ^
--filter-udp=443 ^
--dpi-desync=fake ^
--dpi-desync-repeats=6
Running this configuration demonstrates how the connection performs when only TCP-level desynchronization is active.
Summary
- Fake QUIC Initial packets disrupt DPI state machines by initiating handshakes that never complete.
- The
winws.exebinary in Flowseal/zapret-discord-youtube reads raw packet data frombin/quic_initial_www_google_com.binand injects it via WinDivert filters. - Launch any
general*.batscript to automatically enable this bypass with preconfigured parameters. - Customize injection frequency using
--dpi-desync-repeatsor substitute payload binaries for domain-specific evasion. - This technique operates at the UDP layer before TLS decryption, making it effective even when underlying transport protocols vary.
Frequently Asked Questions
What is the difference between the Google and Discord QUIC binaries?
The quic_initial_www_google_com.bin file contains packet signatures specific to Google services (YouTube, Search), while quic_initial_dbankcloud_ru.bin targets Discord infrastructure. The content differs in Connection ID lengths, token fields, and supported version numbers that match each service's QUIC implementation, ensuring DPI classifiers recognize the decoys as legitimate traffic for their respective targets.
Can I capture my own QUIC Initial packets for custom domains?
Yes. Use packet capture tools like Wireshark or tcpdump to record the first UDP datagram of a successful QUIC connection to your target domain. Extract the raw bytes of the Initial packet and save them to a .bin file, then reference this file via --dpi-desync-fake-quic. Ensure the captured packet includes a valid Connection ID and complies with the QUIC protocol version expected by the remote server.
Why does the fake packet need to repeat multiple times?
DPI engines often employ probabilistic or sampled inspection. Sending the fake packet only once might miss inspection windows or be dismissed as noise. The --dpi-desync-repeats parameter ensures the decoy appears consistently throughout the connection initiation phase, maximizing the probability that the inspection engine latches onto the bogus state and ignores the genuine traffic flow.
Is this technique effective against all DPI implementations?
No. Stateless DPI systems that examine packet contents without tracking connection progress are not affected by QUIC state confusion. Additionally, some advanced engines validate cryptographic handshakes or employ active probing to verify endpoint reachability. The fake QUIC technique specifically targets stateful middleboxes that enforce protocol compliance through handshake progression monitoring.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →