UDP traffic on port 443


Has anyone got an explanation to explain why one can detect udp traffic on port 443 ?

Yann ShukorOwnerAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Possible answer is - Google's QUIC protocol

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
David FavorLinux/LXD/WordPress/Hosting SavantCommented:
State your runtime environment.

Specifically, this is a signature of a Linux machine being hacked by exporting the recent zero day exploit, which triggered an update by every Distro.

If you're running a hackable Kernel, there's only one way out.

1) Move all your sites to a clean machine, where clean == recent Kernel, 4.10+ is best.

2) Reinstall machine from scratch. No updates. Complete obliteration install, using a recent Kernel, 4.10+ is best.

3) Then move all your sites back to newly installed machine.

Several new hosting clients came my way early last year because of this problem.

I never could quite figure out how to reverse all the exploits.

Likely an obliteration reinstall will be the least amount of time to fix this problem, if you're running Linux + you haven't specifically replumbed your Web infrastructure to use QUIC.

QUIC hasn't really made it into any mainstream server release yet, so the only way you'd likely be running QUIC, is if manually built various Web components using the GitHub reference code.
Yann ShukorOwnerAuthor Commented:
The site only has two PCs and two VoIP phones
Get Blueprints for Increased Customer Retention

The IT Service Excellence Tool Kit has best practices to keep your clients happy and business booming. Inside, you’ll find everything you need to increase client satisfaction and retention, become more competitive, and increase your overall success.

Jane UpdegraffSr. Systems AdministratorCommented:
may i also point out that some darkweb browser plugins use UPD over port 443 .... i found a couple users last winter using a plugin called Ultrasurf (i think that's what it was called) and doing some very naughty things ... could not be detected by packet sniffing because the plugin did everything https (encapsulating everything in a plain paper wrapper basically) over UDP .. there are other things that use that combination but really the quickest way to find out is walk over the the endpoint where you see the traffic and look around a bit and what they're doing.
William MillerIT SpecialistCommented:
Apparently there are a handful of reports with Youtube using UDP over this port as well.
David FavorLinux/LXD/WordPress/Hosting SavantCommented:
I probably should have mentioned, on Linux machines, I setup iptables log + drop rules for UDP 443 packets, because I know they're hacks... in my runtime environment.

Then, if these packets every show up in /var/log/kern.log I know it's time to nuke the machine... do an obliteration reinstall from scratch.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.