49b3030e34
Stop fighting anadius's offline verdict. Document the clean-room findings (the gate is an upstream in-process Ebisu connection-state check, not socket traffic) and a milestone roadmap with two first-class outcomes: full playable AI FUT (A) and a clean-room spec deliverable (B). Name M3 (first ProtoSSL plaintext on the real Blaze connection) as the smallest end-to-end proof. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
66 lines
3.7 KiB
Markdown
66 lines
3.7 KiB
Markdown
# Connection-gate findings (clean-room)
|
|
|
|
**Status:** observed behaviour only — derived from running the client and reading
|
|
the repack's own files. No EA source used. Unconfirmed values are marked
|
|
`TODO/CONFIRM` rather than guessed.
|
|
|
|
## Components (observed)
|
|
|
|
| Component | Role |
|
|
|---|---|
|
|
| `FIFA23.exe` | Game. Statically links EA's **Ebisu SDK** (online) and **DirtySDK/ProtoSSL** (transport). Loads at fixed base `0x140000000` — no ASLR seen across launches. |
|
|
| `_ProtoSSLSendPacket` @ `FIFA23.exe+0xEFA530` | DirtySDK TLS record assembler — plaintext in, encrypts in place. Already located + hooked. |
|
|
| `anadius64.dll` | anadius EA-app/Origin **LSX server** emulator (ASLR'd). Provides offline DRM / entitlements / persona so the game *launches*; deliberately keeps it **offline**. |
|
|
| `FakeEAACLauncher` | Anti-cheat bypass only. Irrelevant to the online gate. |
|
|
|
|
## Observed online-startup flow
|
|
|
|
1. Ebisu SDK opens LSX socket(s) to anadius; a **challenge/response handshake**
|
|
completes — captured XML: `<Challenge>` / `<ChallengeResponse>` /
|
|
`<ChallengeAccepted>`, `sender="EALS"`, `ContentId 16115019`.
|
|
2. River/PIN telemetry `<session type=boot>` is emitted.
|
|
3. **No further socket traffic.** Clicking Ultimate Team → "connecting to the EA
|
|
Servers…" → **zero** network attempts (no Blaze DNS, no `connect`, nothing on
|
|
`send`/`recv`/`WSASend`/`WSARecv`) → falls back to offline.
|
|
|
|
## Conclusion: the decision is upstream and in-process
|
|
|
|
- The online/offline verdict is delivered through anadius's **in-process
|
|
detoured Ebisu calls**, not socket messages. (No `GetAuthCode`/`GoOnline`/
|
|
entitlement query appears on any socket, sync or async.)
|
|
- The game therefore **never reaches DirtySDK/ProtoSSL for Blaze** — it aborts
|
|
before any `ProtoSSLConnect(gosredirector…)`. The gate is an **Ebisu-SDK
|
|
connection-state / online-session check upstream of the transport.**
|
|
- `ONLINE_ACCESS` is a `Blaze::Nucleus::EntitlementType` (enum value `1`).
|
|
anadius's `GoOnline` LSX handler (`anadius64.dll+0x2BB90`) is a success stub;
|
|
`anadius64.dll+0xB6B1` is a large entitlement/profile builder that *does*
|
|
reference `ONLINE_ACCESS`. Reverse-engineering that entitlement-status logic
|
|
is the **wrong fight** (see strategy).
|
|
|
|
## Strategy (decided)
|
|
|
|
Do **not** make anadius report "online." anadius exists to keep the game
|
|
offline, and it can't be removed without breaking launch/DRM. Instead:
|
|
|
|
> Let the game run its **real** online flow and answer that flow ourselves via
|
|
> the hook + brain. Target the Ebisu connection-state check the FUT-entry path
|
|
> polls; make the game *pass* it so it issues the real `ProtoSSLConnect` to the
|
|
> Blaze redirector → our redirect + ProtoSSL hook capture the real frames.
|
|
|
|
This deletes the "reverse-engineer anadius's entitlement logic" problem.
|
|
|
|
## Next RE step (converges with the ProtoSSL hook)
|
|
|
|
1. Locate and **read-only hook `ProtoSSLConnect`** (same DirtySDK module and
|
|
technique that found `_ProtoSSLSendPacket`). Confirms the game never
|
|
initiates the Blaze connection (pins the gate strictly upstream) and gives us
|
|
the exact symbol that will flip from "never called" to "called" on success.
|
|
2. Locate the Ebisu **connection-state getter** the FUT-entry / "connecting" UI
|
|
polls. Candidate string anchors (observed): `ONLINE_STATUS_EVENT`,
|
|
`GoOnline` result handling, the "connecting to the EA Servers" UI trigger.
|
|
3. Determine the minimal intervention to make that getter report **connected**
|
|
(out-hook it in our `version.dll`, winning over anadius's detour) so the game
|
|
proceeds to `ProtoSSLConnect`.
|
|
- `TODO/CONFIRM`: whether out-hooking the getter is sufficient, or secondary
|
|
checks (auth-token presence) also gate the attempt.
|