feaff0443f
Hook-side tooling for the LSX/Blaze reverse-engineering effort: - probe.rs (new, `probe` feature): passive logging detours on FIFA's online-flow functions via the unhook/rehook pattern (no trampoline/relocation, works on RIP-relative prologues). Deferred install waits for anadius64.dll to load, then logs enter/return for GoOnline + GetInternetConnectedState (anadius) and the OnlineStatusEvent/Login deserializers (FIFA23.exe). Revealed that our pushed LSX events reach FIFA and parse OK, while GoOnline never fires — localizing the online gate to FIFA's game-side event consumer. - connect_hook.rs: redirect FIFA's LSX connect :3216 → :3217 so it lands on the native openfut-bridge LSX server (slips past anadius's in-process :3216 intercept); gated off under the `capture_baseline` feature. - recv_hook.rs: boundary-safe trampolines + LSX peer filtering for the capture_baseline path (log anadius's real LSX frames when the redirect is off). Build the instrumented DLL with `--features probe` (or `--features capture_baseline` for the anadius-baseline capture). Both features are off by default. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
124 lines
5.7 KiB
Rust
124 lines
5.7 KiB
Rust
mod config;
|
|
mod connect_hook;
|
|
mod connectex_hook;
|
|
mod hooks;
|
|
mod iat;
|
|
mod origin_spy;
|
|
#[cfg(feature = "probe")]
|
|
mod probe;
|
|
#[cfg(feature = "capture_baseline")]
|
|
mod recv_hook;
|
|
mod ssl_patch;
|
|
mod tls_bypass;
|
|
|
|
use windows_sys::Win32::{
|
|
Foundation::{BOOL, HMODULE, TRUE},
|
|
System::SystemServices::DLL_PROCESS_ATTACH,
|
|
Networking::WinSock::ADDRINFOA,
|
|
};
|
|
|
|
pub(crate) fn write_log(msg: &str) {
|
|
use std::io::Write;
|
|
if let Ok(mut f) = std::fs::OpenOptions::new()
|
|
.create(true).append(true)
|
|
.open(r"C:\openfut_hook.log")
|
|
{ let _ = f.write_all(msg.as_bytes()); }
|
|
}
|
|
|
|
#[no_mangle]
|
|
pub unsafe extern "system" fn DllMain(module: HMODULE, reason: u32, _: *mut ()) -> BOOL {
|
|
if reason == DLL_PROCESS_ATTACH { install_hooks(module); }
|
|
TRUE
|
|
}
|
|
|
|
unsafe fn install_hooks(module: HMODULE) {
|
|
write_log("openfut_hook: DllMain fired\n");
|
|
let ip = config::read_redirect_ip(module);
|
|
hooks::set_redirect_ip(ip);
|
|
|
|
let ga = iat::resolve(b"ws2_32.dll\0", b"getaddrinfo\0");
|
|
if !ga.is_null() {
|
|
let f: unsafe extern "system" fn(*const u8,*const u8,*const ADDRINFOA,*mut *mut ADDRINFOA)->i32
|
|
= std::mem::transmute(ga);
|
|
hooks::set_real(f);
|
|
let n = iat::patch_iat(ga, hooks::hooked_getaddrinfo as *const ());
|
|
let m = iat::patch_iat_in(b"EAWebKit.dll\0", ga, hooks::hooked_getaddrinfo as *const ());
|
|
write_log(&format!("openfut_hook: getaddrinfo IAT patched {n}+{m}\n"));
|
|
}
|
|
|
|
if ssl_patch::patch_main_exe_cert_verify() { write_log("ssl: main exe cert-verify patched\n"); }
|
|
else { write_log("ssl: main exe cert-verify NOT FOUND\n"); }
|
|
if ssl_patch::patch_eawebkit_cert_verify() { write_log("ssl: EAWebKit cert-verify patched\n"); }
|
|
else { write_log("ssl: EAWebKit cert-verify deferred\n"); }
|
|
|
|
if connect_hook::install_inline_connect_hook() { write_log("connect: inline-hooked\n"); }
|
|
else { write_log("connect: hook FAILED\n"); }
|
|
let wp = iat::resolve(b"ws2_32.dll\0", b"WSAConnect\0");
|
|
if !wp.is_null() {
|
|
let f: unsafe extern "system" fn(usize,*const u8,i32,*const(),*const(),*const(),*const())->i32
|
|
= std::mem::transmute(wp);
|
|
connect_hook::set_real_wsa_connect(f);
|
|
iat::patch_iat(wp, connect_hook::hooked_wsa_connect as *const ());
|
|
write_log("connect: WSAConnect IAT patched\n");
|
|
}
|
|
|
|
if connectex_hook::install_wsaioctl_hook() { write_log("connectex: WSAIoctl inline-hooked\n"); }
|
|
else { write_log("connectex: WSAIoctl hook FAILED\n"); }
|
|
|
|
// RE instrumentation: passive logging detours on FIFA's in-process online-flow
|
|
// functions (GoOnline, GetInternetConnectedState, event deserializers) to see
|
|
// where FIFA stalls after our pushed LSX events. Deferred until anadius loads.
|
|
#[cfg(feature = "probe")]
|
|
{ probe::install_probes_deferred(); write_log("probe: deferred install scheduled\n"); }
|
|
|
|
// recv/send hooks removed — LSX is now handled by the native openfut-bridge
|
|
// LSX server (port 3216), so in-process interception is no longer needed.
|
|
//
|
|
// Except in the `capture_baseline` build: with the LSX redirect off, FIFA talks
|
|
// to anadius directly, and these hooks log anadius's real LSX request/response
|
|
// frames (pass-through, no emulation) so we can diff them against our bridge.
|
|
#[cfg(feature = "capture_baseline")]
|
|
{
|
|
if recv_hook::install_recv_hook() { write_log("CAP: recv inline-hooked\n"); }
|
|
else { write_log("CAP: recv hook FAILED\n"); }
|
|
if recv_hook::install_send_hook() { write_log("CAP: send inline-hooked\n"); }
|
|
else { write_log("CAP: send hook FAILED\n"); }
|
|
}
|
|
|
|
macro_rules! hook_iat {
|
|
($dll:expr, $sym:expr, $setter:ident, $handler:expr, $ty:ty) => {{
|
|
let ptr = iat::resolve($dll, $sym);
|
|
if !ptr.is_null() {
|
|
let f: $ty = std::mem::transmute(ptr);
|
|
origin_spy::$setter(f);
|
|
iat::patch_iat(ptr, $handler as *const ());
|
|
"ok"
|
|
} else { "miss" }
|
|
}};
|
|
}
|
|
let ra = hook_iat!(b"advapi32.dll\0", b"RegQueryValueExA\0", set_real_reg_a,
|
|
origin_spy::hooked_reg_query_a,
|
|
unsafe extern "system" fn(isize,*const u8,*mut u32,*mut u32,*mut u8,*mut u32)->i32);
|
|
let rw = hook_iat!(b"advapi32.dll\0", b"RegQueryValueExW\0", set_real_reg_w,
|
|
origin_spy::hooked_reg_query_w,
|
|
unsafe extern "system" fn(isize,*const u16,*mut u32,*mut u32,*mut u8,*mut u32)->i32);
|
|
let ma = hook_iat!(b"kernel32.dll\0", b"OpenMutexA\0", set_real_mutex_a,
|
|
origin_spy::hooked_open_mutex_a,
|
|
unsafe extern "system" fn(u32,i32,*const u8)->isize);
|
|
let mw = hook_iat!(b"kernel32.dll\0", b"OpenMutexW\0", set_real_mutex_w,
|
|
origin_spy::hooked_open_mutex_w,
|
|
unsafe extern "system" fn(u32,i32,*const u16)->isize);
|
|
write_log(&format!("origin_spy: RegA={ra} RegW={rw} MutexA={ma} MutexW={mw}\n"));
|
|
|
|
let cv = iat::resolve(b"crypt32.dll\0", b"CertVerifyCertificateChainPolicy\0");
|
|
if !cv.is_null() {
|
|
let f: unsafe extern "system" fn(*const u8,*const(),*const(),*mut u32)->BOOL
|
|
= std::mem::transmute(cv);
|
|
tls_bypass::set_real(f);
|
|
iat::patch_iat(cv, tls_bypass::hooked_cert_verify_chain_policy as *const ());
|
|
iat::patch_iat_in(b"EAWebKit.dll\0", cv, tls_bypass::hooked_cert_verify_chain_policy as *const ());
|
|
iat::patch_iat_in(b"winhttp.dll\0", cv, tls_bypass::hooked_cert_verify_chain_policy as *const ());
|
|
iat::patch_iat_in(b"wininet.dll\0", cv, tls_bypass::hooked_cert_verify_chain_policy as *const ());
|
|
}
|
|
}
|