UDP traffic on port 443

Yann Shukor
Yann Shukor used Ask the Experts™
on
Hi

Has anyone got an explanation to explain why one can detect udp traffic on port 443 ?

thanks
yann
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Distinguished Expert 2018
Commented:
Possible answer is - Google's QUIC protocol
David FavorFractional CTO
Distinguished Expert 2018
Commented:
State your runtime environment.

Specifically, this is a signature of a Linux machine being hacked by exporting the recent zero day exploit, which triggered an update by every Distro.

If you're running a hackable Kernel, there's only one way out.

1) Move all your sites to a clean machine, where clean == recent Kernel, 4.10+ is best.

2) Reinstall machine from scratch. No updates. Complete obliteration install, using a recent Kernel, 4.10+ is best.

3) Then move all your sites back to newly installed machine.

Several new hosting clients came my way early last year because of this problem.

I never could quite figure out how to reverse all the exploits.

Likely an obliteration reinstall will be the least amount of time to fix this problem, if you're running Linux + you haven't specifically replumbed your Web infrastructure to use QUIC.

QUIC hasn't really made it into any mainstream server release yet, so the only way you'd likely be running QUIC, is if manually built various Web components using the GitHub reference code.

Author

Commented:
The site only has two PCs and two VoIP phones
Success in ‘20 With a Profitable Pricing Strategy

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Jane UpdegraffSr. Systems Administrator
Commented:
may i also point out that some darkweb browser plugins use UPD over port 443 .... i found a couple users last winter using a plugin called Ultrasurf (i think that's what it was called) and doing some very naughty things ... could not be detected by packet sniffing because the plugin did everything https (encapsulating everything in a plain paper wrapper basically) over UDP .. there are other things that use that combination but really the quickest way to find out is walk over the the endpoint where you see the traffic and look around a bit and what they're doing.

Commented:
Apparently there are a handful of reports with Youtube using UDP over this port as well.
David FavorFractional CTO
Distinguished Expert 2018

Commented:
I probably should have mentioned, on Linux machines, I setup iptables log + drop rules for UDP 443 packets, because I know they're hacks... in my runtime environment.

Then, if these packets every show up in /var/log/kern.log I know it's time to nuke the machine... do an obliteration reinstall from scratch.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial