Files
OpenFUT-Bridge/docs/connection-gate-findings.md
T
funman300 49b3030e34 docs: connection-gate findings + roadmap (strategy pivot)
Stop fighting anadius's offline verdict. Document the clean-room findings
(the gate is an upstream in-process Ebisu connection-state check, not socket
traffic) and a milestone roadmap with two first-class outcomes: full playable
AI FUT (A) and a clean-room spec deliverable (B). Name M3 (first ProtoSSL
plaintext on the real Blaze connection) as the smallest end-to-end proof.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 18:00:27 -07:00

3.7 KiB

Connection-gate findings (clean-room)

Status: observed behaviour only — derived from running the client and reading the repack's own files. No EA source used. Unconfirmed values are marked TODO/CONFIRM rather than guessed.

Components (observed)

Component Role
FIFA23.exe Game. Statically links EA's Ebisu SDK (online) and DirtySDK/ProtoSSL (transport). Loads at fixed base 0x140000000 — no ASLR seen across launches.
_ProtoSSLSendPacket @ FIFA23.exe+0xEFA530 DirtySDK TLS record assembler — plaintext in, encrypts in place. Already located + hooked.
anadius64.dll anadius EA-app/Origin LSX server emulator (ASLR'd). Provides offline DRM / entitlements / persona so the game launches; deliberately keeps it offline.
FakeEAACLauncher Anti-cheat bypass only. Irrelevant to the online gate.

Observed online-startup flow

  1. Ebisu SDK opens LSX socket(s) to anadius; a challenge/response handshake completes — captured XML: <Challenge> / <ChallengeResponse> / <ChallengeAccepted>, sender="EALS", ContentId 16115019.
  2. River/PIN telemetry <session type=boot> is emitted.
  3. No further socket traffic. Clicking Ultimate Team → "connecting to the EA Servers…" → zero network attempts (no Blaze DNS, no connect, nothing on send/recv/WSASend/WSARecv) → falls back to offline.

Conclusion: the decision is upstream and in-process

  • The online/offline verdict is delivered through anadius's in-process detoured Ebisu calls, not socket messages. (No GetAuthCode/GoOnline/ entitlement query appears on any socket, sync or async.)
  • The game therefore never reaches DirtySDK/ProtoSSL for Blaze — it aborts before any ProtoSSLConnect(gosredirector…). The gate is an Ebisu-SDK connection-state / online-session check upstream of the transport.
  • ONLINE_ACCESS is a Blaze::Nucleus::EntitlementType (enum value 1). anadius's GoOnline LSX handler (anadius64.dll+0x2BB90) is a success stub; anadius64.dll+0xB6B1 is a large entitlement/profile builder that does reference ONLINE_ACCESS. Reverse-engineering that entitlement-status logic is the wrong fight (see strategy).

Strategy (decided)

Do not make anadius report "online." anadius exists to keep the game offline, and it can't be removed without breaking launch/DRM. Instead:

Let the game run its real online flow and answer that flow ourselves via the hook + brain. Target the Ebisu connection-state check the FUT-entry path polls; make the game pass it so it issues the real ProtoSSLConnect to the Blaze redirector → our redirect + ProtoSSL hook capture the real frames.

This deletes the "reverse-engineer anadius's entitlement logic" problem.

Next RE step (converges with the ProtoSSL hook)

  1. Locate and read-only hook ProtoSSLConnect (same DirtySDK module and technique that found _ProtoSSLSendPacket). Confirms the game never initiates the Blaze connection (pins the gate strictly upstream) and gives us the exact symbol that will flip from "never called" to "called" on success.
  2. Locate the Ebisu connection-state getter the FUT-entry / "connecting" UI polls. Candidate string anchors (observed): ONLINE_STATUS_EVENT, GoOnline result handling, the "connecting to the EA Servers" UI trigger.
  3. Determine the minimal intervention to make that getter report connected (out-hook it in our version.dll, winning over anadius's detour) so the game proceeds to ProtoSSLConnect.
    • TODO/CONFIRM: whether out-hooking the getter is sufficient, or secondary checks (auth-token presence) also gate the attempt.