How to Use Fake QUIC Initial Packets for DPI Bypass in zapret-discord-youtube

Run any general*.bat script to automatically inject pre-generated QUIC Initial packets via winws.exe, confusing DPI engines and allowing YouTube and Discord traffic to bypass stateful inspection.

The zapret-discord-youtube repository provides Windows-based Deep Packet Inspection (DPI) circumvention tools powered by WinDivert. To evade blocking on services that inspect QUIC handshakes, the toolset employs fake QUIC Initial packets that desynchronize inspection engines by disrupting their state tracking mechanisms.

How Fake QUIC Initial Packets Bypass DPI

DPI engines typically implement stateful tracking of QUIC connections, expecting a sequential handshake: Initial → Handshake → 0‑RTT. The bypass technique exploits this assumption by injecting standalone QUIC Initial packets that mimic legitimate connection starts but never progress to the next state.

When winws.exe transmits these synthetic packets (stored as raw binary blobs), the DPI system allocates resources to track a handshake that never completes. The original application traffic interleaves with these decoys, causing the inspection engine to drop or ignore the genuine connection while waiting for follow-up packets that never arrive. This desynchronization allows encrypted traffic to pass through uninspected.

The Injection Mechanism

In general.bat, the launcher constructs a WinDivert filter that attaches to UDP port 443. The critical parameter --dpi-desync-fake-quic instructs winws.exe to read the raw packet data from bin/quic_initial_www_google_com.bin (for Google/YouTube) or bin/quic_initial_dbankcloud_ru.bin (for Discord) and periodically inject these bytes into matching outbound flows.

"%BIN%winws.exe" ^
  --wf-udp=443 ^
  --filter-udp=443 ^
  --dpi-desync=fake ^
  --dpi-desync-repeats=6 ^
  --dpi-desync-fake-quic="%BIN%quic_initial_www_google_com.bin"

The binary files contain actual QUIC Initial packets captured from legitimate connections, ensuring the decoys bear authentic headers and random values that DPI heuristics expect.

Configuration Parameters

The following winws.exe options control the fake QUIC behavior:

  • --dpi-desync-fake-quic: Path to the raw binary file containing the QUIC Initial packet to inject. Typical values include bin/quic_initial_www_google_com.bin for Google services and bin/quic_initial_dbankcloud_ru.bin for Discord.
  • --filter-udp: Specifies the UDP ports where the rule applies, typically 443 for HTTPS-over-QUIC.
  • --dpi-desync-repeats: Controls injection frequency per connection. Values range from 6 (standard) to 11 (aggressive strategies).
  • --dpi-desync: Enables the desynchronization mode; must be set to fake for QUIC injection to function.

Running the Default Strategy

Using the Standard Batch Scripts

Execute the default Google/YouTube strategy by running the batch file with administrator privileges:

general.bat

This script automatically resolves the BIN path and launches winws.exe with the QUIC desync parameters preconfigured.

Manual Execution with winws.exe

For debugging or custom configurations, invoke winws.exe directly from an elevated command prompt:

set BIN=C:\path\to\zapret\bin\

"%BIN%winws.exe" ^
  --wf-udp=443 ^
  --filter-udp=443 ^
  --dpi-desync=fake ^
  --dpi-desync-repeats=6 ^
  --dpi-desync-fake-quic="%BIN%quic_initial_www_google_com.bin"

This command attaches to all UDP port 443 traffic and injects the fake Google QUIC Initial packet six times per detected flow.

Customizing Fake QUIC Payloads

Replacing the Packet Binary

To test a different QUIC Initial payload captured from another domain, replace the binary file while preserving the filename expected by the script:

copy my_custom_quic.bin "%~dp0bin\quic_initial_www_google_com.bin"
general.bat

Alternatively, modify the --dpi-desync-fake-quic path in general.bat to point to your custom binary without renaming it.

Using Aggressive Strategies

The repository includes variants like general (FAKE TLS AUTO).bat that employ identical QUIC injection with higher repeat counts:

"general (FAKE TLS AUTO).bat"

This variant uses --dpi-desync-repeats=11, suitable for networks with particularly persistent DPI inspection engines.

Disabling QUIC Desync for Testing

To observe connection behavior without QUIC injection, remove the --dpi-desync-fake-quic parameter from the launch command:

"%BIN%winws.exe" ^
  --filter-udp=443 ^
  --dpi-desync=fake ^
  --dpi-desync-repeats=6

Running this configuration demonstrates how the connection performs when only TCP-level desynchronization is active.

Summary

  • Fake QUIC Initial packets disrupt DPI state machines by initiating handshakes that never complete.
  • The winws.exe binary in Flowseal/zapret-discord-youtube reads raw packet data from bin/quic_initial_www_google_com.bin and injects it via WinDivert filters.
  • Launch any general*.bat script to automatically enable this bypass with preconfigured parameters.
  • Customize injection frequency using --dpi-desync-repeats or substitute payload binaries for domain-specific evasion.
  • This technique operates at the UDP layer before TLS decryption, making it effective even when underlying transport protocols vary.

Frequently Asked Questions

What is the difference between the Google and Discord QUIC binaries?

The quic_initial_www_google_com.bin file contains packet signatures specific to Google services (YouTube, Search), while quic_initial_dbankcloud_ru.bin targets Discord infrastructure. The content differs in Connection ID lengths, token fields, and supported version numbers that match each service's QUIC implementation, ensuring DPI classifiers recognize the decoys as legitimate traffic for their respective targets.

Can I capture my own QUIC Initial packets for custom domains?

Yes. Use packet capture tools like Wireshark or tcpdump to record the first UDP datagram of a successful QUIC connection to your target domain. Extract the raw bytes of the Initial packet and save them to a .bin file, then reference this file via --dpi-desync-fake-quic. Ensure the captured packet includes a valid Connection ID and complies with the QUIC protocol version expected by the remote server.

Why does the fake packet need to repeat multiple times?

DPI engines often employ probabilistic or sampled inspection. Sending the fake packet only once might miss inspection windows or be dismissed as noise. The --dpi-desync-repeats parameter ensures the decoy appears consistently throughout the connection initiation phase, maximizing the probability that the inspection engine latches onto the bogus state and ignores the genuine traffic flow.

Is this technique effective against all DPI implementations?

No. Stateless DPI systems that examine packet contents without tracking connection progress are not affected by QUIC state confusion. Additionally, some advanced engines validate cryptographic handshakes or employ active probing to verify endpoint reachability. The fake QUIC technique specifically targets stateful middleboxes that enforce protocol compliance through handshake progression monitoring.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →