funman300 e4108fcff8 feat(xref): objdump-based string-literal cross-reference tool
New CLI (openfut-bridge-xref) that finds every code site referencing chosen
.rdata string literals and prints the guarding-branch context. Shells out to
system objdump only (no disassembler crate) and exploits objdump's resolved
'# <hex>' RIP-relative target comments. Phases: discovery (ImageBase + section
table via -p/-h), harvest (-s -j .rdata → NUL-terminated ASCII matching anchors,
with VAs), streaming xref (-d, ring-buffer context, int3-boundary function
synthesis for this stripped PE), grouped report flagging control-flow lines.

Self-test (anchor nucleusConnectREST) PASSES: harvests VA 0x1480db550 and finds
the load site 0x142861942 in fn 0x142861910 (which calls the map-lookup at
0x145057670). First payoff: gosredirector hostnames have ZERO code refs — they
sit in a 4-entry env→URL data table at 0x1483fc858, so env selection is
table-indexed, not a direct code lea.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 19:10:12 -07:00
2026-06-25 15:09:47 -07:00
2026-06-25 15:09:47 -07:00

OpenFUT Bridge

FIFA 23 integration layer and reverse-engineering proxy.

OpenFUT Bridge sits between the FIFA 23 client and the internet. It intercepts all FUT API traffic, logs every request, and routes known endpoints to OpenFUT Core. Unknown endpoints receive safe placeholder responses so the client keeps running.


What it does

  • Transparent HTTP proxy — point FIFA 23 here instead of EA's servers
  • Logs every request (method, path, headers, body, timestamp) to captures/
  • Maps known FUT endpoints to OpenFUT Core API calls
  • Returns placeholder JSON for unknown endpoints (prevents client crashes)
  • Admin API for reviewing captures and identifying unmapped routes
  • Foundation for building the full FIFA 23 integration

Architecture

FIFA 23 client
      │
      ▼
OpenFUT Bridge (port 8443)
      │
      ├── Known route → OpenFUT Core (port 8080)
      └── Unknown route → Placeholder JSON + saved to captures/

Quick Start

# Run Core first
cd ../openfut-core && cargo run

# Run Bridge
cargo run

# Or with config
CORE_URL=http://127.0.0.1:8080 BRIDGE_LISTEN_ADDR=127.0.0.1:8443 cargo run

Environment Variables

Variable Default Description
BRIDGE_LISTEN_ADDR 127.0.0.1:8443 Bridge listen address
CORE_URL http://127.0.0.1:8080 OpenFUT Core URL
CAPTURES_DIR captures Where to save captured requests
PLACEHOLDER_MODE true Return 200 for unknown endpoints

Admin API

Method Path Description
GET /_bridge/health Bridge status
GET /_bridge/captures All captured requests
GET /_bridge/unknown Unknown endpoints only

Reverse Engineering Workflow

  1. Point FIFA 23 at the Bridge (see docs/setup-notes.md for proxy setup)
  2. Start a game session
  3. Check captures/ or /_bridge/unknown for new endpoints
  4. Document the endpoint in docs/endpoint-map.md
  5. Add a mapping in src/mapper.rs
  6. Implement the Core handler

Proxy Setup (Research Notes)

See docs/setup-notes.md for notes on:

  • Windows hosts file redirection
  • RPCS3 network config (PS3)
  • Certificate bypass approaches
  • mitmproxy integration

Development

cargo fmt
cargo clippy -- -D warnings
cargo test

License

MIT

S
Description
FIFA 23 integration layer and reverse-engineering proxy
Readme 1.1 MiB
Languages
Rust 61.7%
HTML 38.3%