5.0 KiB
OpenFUT FIFA 17 - native Windows client
The FIFA 17 client host (10.10.0.105, Windows 11 Pro) runs FIFA 17 natively
(no Wine/Proton/umu). This directory holds the read-only preflight verifier and
documents the native launch/routing/rollback model.
Install layout (C:\FIFA 17)
| File | Role |
|---|---|
FIFA17.exe |
retail game exe (sha256 29C31CEF…). Never modify/patch. ImageBase 0x140000000. |
_fifa17.exe |
native crack loader (Chemicalflood). This is what you launch. asInvoker manifest -> must be elevated externally. |
version.dll |
OpenFUT hook (in-process via the version.dll load-order hijack). ImageBase 0x180000000. |
version.dll.stale-849k.bak |
rollback copy of the previous hook. |
CardsDLL_Win64_retail.dll |
FUT card/SBC/kit logic. ImageBase 0x180000000. |
powdll_Win64_retail.dll |
Pack-Opening-World (EASFC store). ImageBase 0x180000000. |
sysdll_Win64_retail.dll |
EA networking / ProtoSSL (cert, ea.com). |
stp-origin_emu.dll + stp-origin_emu.ini |
Origin/LSX login emulator (in-process; opens LSX :4216 locally at runtime). Persona configured in the .ini. |
stp-selector.exe |
ssl/LSX selector companion. |
openfut.cfg |
operator-facing routing override (see below). |
Launch (native - there is NO launcher script by design)
Run C:\FIFA 17\_fifa17.exe as Administrator. The correct, reproducible way:
- Double-click the "FIFA 17 (OpenFUT)" shortcut (Desktop and Start Menu).
It targets
_fifa17.exe, working dirC:\FIFA 17, with the RunAsAdmin bit set. _fifa17.exeis also flaggedRUNASADMINinHKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers, so any launch (Explorer double-click included) elevates via UAC.
On launch the Windows loader maps version.dll from the game directory (hijack),
stp-origin_emu.dll emulates Origin login for the configured persona, and the
hook redirects EA endpoints to the OpenFUT backend.
Do not wrap the launch in a script. The elevation + shortcut is the supported mechanism. FIFA under native Windows also ignores synthetic input, so in-game steps are performed by the operator one at a time.
OpenFUT Launcher (GUI)
The openfut-launcher egui app runs natively on Windows (built for
x86_64-pc-windows-gnu; the Linux Proton path is cfg-gated out). It is the
one-button front end: it checks the backend, reconciles openfut.cfg from its
settings, and starts the game.
- Binary:
C:\OpenFUT\openfut-launcher.exe; config:%APPDATA%\openfut-launcher\config.json. - Launch it from the "OpenFUT Launcher" shortcut (Desktop / Start Menu). The
launcher itself is flagged
RUNASADMIN, so it elevates once at start; the game it spawns inherits that elevation (no second UAC prompt, no crack loader "run as admin" failure). - On Windows the launcher does NOT spawn LSX/autopatch (they are in-process:
stp-origin_emu.dll+ theversion.dllhook) and does NOT arm the host (routing is purelyopenfut.cfg, which it writes intoC:\FIFA 17). - Rebuild from Linux:
cargo build -p openfut-launcher --release --target x86_64-pc-windows-gnu.
Routing (openfut.cfg)
host=10.10.0.120
https_port=8443
blaze_redirector_port=42127
blaze_main_port=42130
The hook carries 10.10.0.120 as its baked-in default; openfut.cfg is the
override. 10.10.0.120 hosts both production and staging.
Production safety:
blaze_main_port=42130is the production Blaze. Before any match/economy exercise, repointblaze_main_port(and the matching UTAS/HTTPS route) to the staging port so no traffic reaches the prod container. The preflight raises a WARN whenever42130is configured.
Rollback
The hook is a single file swap; no installer state.
# disable OpenFUT hook (restore previous DLL)
Copy-Item 'C:\FIFA 17\version.dll' 'C:\FIFA 17\version.dll.disabled.bak' -Force
Copy-Item 'C:\FIFA 17\version.dll.stale-849k.bak' 'C:\FIFA 17\version.dll' -Force
# re-arm: copy the desired hook build over version.dll again
Always keep a *.bak of the live hook before redeploying (the preflight checks
that a rollback backup exists and differs from the live DLL).
Preflight
openfut-client-preflight.ps1 is read-only: it never launches the game,
never elevates, never writes game files, never mutates economy state. It verifies
the retail exe hash, companion DLLs, hook + rollback, routing + backend
reachability, login persona, launcher elevation, and the RE toolchain
(x64dbg, cargo). Exit 0 = OK, 1 = blocking failure.
powershell -NoProfile -ExecutionPolicy Bypass -File .\openfut-client-preflight.ps1
Runtime RE (x64dbg)
See the Vault note 02 Reverse Engineering/FIFA 17/Windows Client Runtime & x64dbg.md
for the attach workflow and the RVA<->VA (ASLR) math. In short: these modules'
preferred ImageBase is 0x180000000 (0x140000000 for FIFA17.exe); in x64dbg
a module name evaluates to its runtime (ASLR) base, so a Ghidra address maps to a
breakpoint as bp CardsDLL_Win64_retail.dll+<RVA> where
RVA = ghidra_addr - 0x180000000.