[{"data":1,"prerenderedAt":28},["ShallowReactive",2],{"doc-en-detect-fivem-backdoor":3},{"path":4,"slug":5,"title":6,"description":7,"category":8,"subcategory":9,"icon":10,"date":11,"author":12,"order":13,"image":14,"tags":15,"keywords":19,"docGroup":25,"docGroupIcon":25,"link_fr":26,"bodyHtml":27},"\u002Fdocs\u002Fen\u002Fgaming\u002Ffivem\u002Fdetect-fivem-backdoor","detect-fivem-backdoor","How to Detect a Backdoor on Your FiveM Server","Learn to recognize the signs of a backdoor on your FiveM server, suspicious logs, trapped files, and how to react in case of compromise.","jeux","fivem","tabler:file-text","2026-07-24","Winheberg",18,"\u002Fstatics\u002Fimages\u002Fdocs\u002Fen\u002Fgaming\u002Ffivem\u002Fdetect-fivem-backdoor.webp",[9,16,17,18],"backdoor","security","leaked resource",[20,21,22,23,24],"fivem backdoor","leaked resource fivem","fivem server security","suspicious fivem logs","fxmanifest backdoor","","\u002Fdocs\u002Ffivem\u002Fdetecter-backdoor-serveur-fivem","\u003Ch2>Context\u003C\u002Fh2>\n\u003Cp>You manage a \u003Cstrong>FiveM server\u003C\u002Fstrong> (GTA RP) and you have a doubt? Your server is behaving strangely, odd logs are showing up in the console, your server crashes for no apparent reason, or unusual actions are happening in-game. Before panicking, you need to \u003Cstrong>know how to read the signs\u003C\u002Fstrong> of a backdoor to confirm or rule out your fears.\u003C\u002Fp>\n\u003Cp>This guide explains how to \u003Cstrong>recognize the typical behaviors of a backdoor\u003C\u002Fstrong> on a FiveM server, how to react, and what to do if your doubts are confirmed.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-warning\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Cpath d=\"M10.29 3.86L1.82 18a2 2 0 0 0 1.71 3h16.94a2 2 0 0 0 1.71-3L13.71 3.86a2 2 0 0 0-3.42 0z\"\u002F>\u003Cline x1=\"12\" y1=\"9\" x2=\"12\" y2=\"13\"\u002F>\u003Cline x1=\"12\" y1=\"17\" x2=\"12.01\" y2=\"17\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>A backdoor on a FiveM server can lead to \u003Cstrong>player data theft\u003C\u002Fstrong>, the \u003Cstrong>destruction of your database\u003C\u002Fstrong>, or even \u003Cstrong>full takeover\u003C\u002Fstrong> of your infrastructure. Never let a doubt linger.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>What is a backdoor on FiveM?\u003C\u002Fh2>\n\u003Cp>A \u003Cstrong>backdoor\u003C\u002Fstrong> is a piece of malicious code hidden inside an apparently legitimate FiveM resource. It lets its author \u003Cstrong>access your server without your authorization\u003C\u002Fstrong>, \u003Cstrong>run commands\u003C\u002Fstrong>, \u003Cstrong>steal data\u003C\u002Fstrong>, or \u003Cstrong>inject malicious code into other resources\u003C\u002Fstrong> on your server to hide more effectively.\u003C\u002Fp>\n\u003Cp>In the vast majority of cases, FiveM backdoors come from \u003Cstrong>&quot;leaked&quot; resources\u003C\u002Fstrong> (resold or redistributed without the original creator&#39;s consent). That&#39;s the first place to look when you suspect something.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-tip\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cpath d=\"M12 16v-4\"\u002F>\u003Cpath d=\"M12 8h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>Beyond the backdoor risk itself, \u003Cstrong>we strongly discourage using leaked resources\u003C\u002Fstrong>. First out of respect for the work of developers who spend dozens of hours creating these resources, and second because a leaked resource is a prime target for slipping in malicious code without anyone noticing.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>Typical backdoor behaviors\u003C\u002Fh2>\n\u003Cp>A FiveM backdoor generally tries to do three main things.\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Read your configuration files\u003C\u002Fstrong> (particularly \u003Ccode>server.cfg\u003C\u002Fcode>, which holds your MySQL passwords and API keys)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Write into other resources\u003C\u002Fstrong> on your server to \u003Cstrong>inject malicious code elsewhere\u003C\u002Fstrong> and persist even if the original resource is deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Run system commands\u003C\u002Fstrong> to extend its control over the entire server\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>If you notice one or more of these behaviors in your logs, you very likely have an active backdoor.\u003C\u002Fp>\n\u003Ch2>Recognizing suspicious logs\u003C\u002Fh2>\n\u003Cp>FiveM has a \u003Cstrong>strict permission system\u003C\u002Fstrong> that logs and blocks certain sensitive actions. When a resource tries to do something it shouldn&#39;t, you&#39;ll see very specific messages in your server&#39;s console.\u003C\u002Fp>\n\u003Ch3>Reading\u002Fwriting files outside the resource&#39;s own folder\u003C\u002Fh3>\n\u003Cp>A legitimate resource has \u003Cstrong>no reason\u003C\u002Fstrong> to read or write into another resource&#39;s folder or into your server&#39;s root. If you see this type of message.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>[c-scripting-node] Filesystem write permission check from &#39;RESOURCE_NAME&#39; for permission fs.write on resource &#39;\u002Fhome\u002Fcontainer\u002Fresources\u002F[other_resource]\u002Ffile.lua&#39; - write not allowed\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cpre>\u003Ccode>[c-scripting-node] Filesystem permission check from &#39;RESOURCE_NAME&#39; for permission fs.read on resource &#39;.\u002Fserver.cfg&#39; - no device found\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>That&#39;s a \u003Cstrong>very strong signal of a backdoor\u003C\u002Fstrong>. A healthy resource only reads its own files, not other resources&#39; files, and \u003Cstrong>even less so\u003C\u002Fstrong> your \u003Ccode>server.cfg\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-note\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cline x1=\"12\" y1=\"16\" x2=\"12\" y2=\"12\"\u002F>\u003Cline x1=\"12\" y1=\"8\" x2=\"12.01\" y2=\"8\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>One exception worth knowing, some \u003Cstrong>base resources (frameworks) offering a web control panel\u003C\u002Fstrong>, for example to manage resources, logs, or configuration remotely, legitimately need to access other folders on your server to work. Before concluding it&#39;s a backdoor, check whether the resource in question is precisely this kind of base with a web panel, and whether this behavior is documented by its author.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch3>Probing several possible installation paths\u003C\u002Fh3>\n\u003Cp>A common variant is testing several classic FiveM installation paths one after another, without knowing in advance which one is used on the targeted server. Our support team has actually observed this exact case on a client&#39;s server before.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>[c-scripting-node] Filesystem permission check from &#39;signal&#39; for permission fs.read on resource &#39;\u002Fhome\u002Ffivem\u002Fserver\u002Fresources&#39; - no device found\n[c-scripting-node] Filesystem permission check from &#39;signal&#39; for permission fs.read on resource &#39;\u002Fhome\u002Ffivem\u002Fserver-data\u002Fresources&#39; - no device found\n[c-scripting-node] Filesystem permission check from &#39;signal&#39; for permission fs.read on resource &#39;\u002Fopt\u002Ffivem\u002Fserver\u002Fresources&#39; - no device found\n[c-scripting-node] Filesystem permission check from &#39;signal&#39; for permission fs.read on resource &#39;\u002Fopt\u002Ffxserver\u002Fresources&#39; - no device found\n[c-scripting-node] Filesystem permission check from &#39;signal&#39; for permission fs.read on resource &#39;\u002Fsrv\u002Ffivem\u002Fresources&#39; - no device found\n[c-scripting-node] Filesystem permission check from &#39;signal&#39; for permission fs.read on resource &#39;\u002Froot\u002FFXServer\u002Fserver-data\u002Fresources&#39; - no device found\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Here, the resource was named \u003Ccode>signal\u003C\u002Fcode>, which is nothing official or reassuring on its own. A legitimate resource knows its own installation folder, it has no reason to test a list of common paths used by different hosts or FiveM installations looking for the \u003Ccode>resources\u003C\u002Fcode> folder. This behavior is characteristic of code trying to locate itself on an unknown server before navigating the full file tree.\u003C\u002Fp>\n\u003Ch3>Attempted system command execution\u003C\u002Fh3>\n\u003Cp>If you see this type of log.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>[c-scripting-node] Child process permission check from &#39;RESOURCE_NAME&#39; for permission child on resource &#39;\u002Fbin\u002Fsh&#39; - child spawn not allowed\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>This is \u003Cstrong>extremely serious\u003C\u002Fstrong>. The resource is trying to \u003Cstrong>open a shell\u003C\u002Fstrong> on your server, which serves no purpose whatsoever for a normal FiveM resource. It&#39;s one of the most characteristic behaviors of a backdoor trying to take control of your server.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-caution\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cline x1=\"12\" y1=\"8\" x2=\"12\" y2=\"12\"\u002F>\u003Cline x1=\"12\" y1=\"16\" x2=\"12.01\" y2=\"16\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>If you see repeated attempts to access \u003Ccode>\u002Fbin\u002Fsh\u003C\u002Fcode>, \u003Ccode>bash\u003C\u002Fcode>, or any other system executable, \u003Cstrong>immediately stop the resource in question\u003C\u002Fstrong> and launch a full investigation of your server.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch3>Sudden server crashes\u003C\u002Fh3>\n\u003Cp>Based on feedback from our support team, another suspicious behavior we regularly notice is the \u003Cstrong>FiveM server crashing abruptly\u003C\u002Fstrong>, often along with logs like this.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>║ STDERR║ Assertion failed: fd_to_send &gt;= 0 (..\u002Fdeps\u002Fuv\u002Fsrc\u002Funix\u002Fstream.c: uv__try_write: 791)\n║ TXADMIN║ Restarting server: Server process close detected.\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>If your server \u003Cstrong>restarts abruptly\u003C\u002Fstrong> several times a day for no apparent reason, and you see this kind of error in the console, it&#39;s a \u003Cstrong>strong indicator\u003C\u002Fstrong> that a malicious resource is trying to run code that crashes the FiveM process. Combined with the other signs (read\u002Fwrite attempts, child process), the diagnosis leaves little doubt.\u003C\u002Fp>\n\u003Ch3>Other signs to watch for\u003C\u002Fh3>\n\u003Cp>Other behaviors should raise a flag, even without an explicit log message.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Players suddenly getting admin permissions\u003C\u002Fstrong> without any action on your part\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Strange messages appearing in chat\u003C\u002Fstrong> with no legitimate script sending them\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data disappearing or changing\u003C\u002Fstrong> in the database (money, inventory, vehicles)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Unusual connections\u003C\u002Fstrong> in the logs (unknown Steam\u002FDiscord identifiers with elevated permissions)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Resources appearing or changing on their own\u003C\u002Fstrong> on your server\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Unexplained CPU or network usage spikes\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>Inspecting the files of a suspicious resource\u003C\u002Fh2>\n\u003Cp>Even before installing a resource, or if you suspect an already-installed resource is compromised, \u003Cstrong>take the time to open and go through its files\u003C\u002Fstrong>. That&#39;s often where the real surprises hide.\u003C\u002Fp>\n\u003Ch3>Check the fxmanifest.lua\u003C\u002Fh3>\n\u003Cp>The \u003Ccode>fxmanifest.lua\u003C\u002Fcode> file lists every file loaded by the resource (client-side, server-side, shared files). Open it and \u003Cstrong>read every line carefully\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-lua\">client_scripts {\n    &#39;client\u002Fmain.lua&#39;,\n    &#39;client\u002Faafdsd.js&#39;,  -- ⚠️ Suspicious\n}\n\nserver_scripts {\n    &#39;server\u002Fmain.lua&#39;,\n    &#39;server\u002Fx9d2k.js&#39;,   -- ⚠️ Suspicious\n}\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>If you see files with \u003Cstrong>random or meaningless names\u003C\u002Fstrong> (\u003Ccode>aafdsd.js\u003C\u002Fcode>, \u003Ccode>xk2j9.lua\u003C\u002Fcode>, \u003Ccode>_temp.js\u003C\u002Fcode>, etc.) mixed in with consistently named files (\u003Ccode>main.lua\u003C\u002Fcode>, \u003Ccode>config.lua\u003C\u002Fcode>, \u003Ccode>inventory.js\u003C\u002Fcode>), that&#39;s a \u003Cstrong>major red flag\u003C\u002Fstrong>. No serious developer names their files like that. It&#39;s almost always malicious code someone tried to slip in quietly.\u003C\u002Fp>\n\u003Ch3>Check the content of each file\u003C\u002Fh3>\n\u003Cp>Open every \u003Ccode>.lua\u003C\u002Fcode>, \u003Ccode>.js\u003C\u002Fcode>, or \u003Ccode>.json\u003C\u002Fcode> file listed in the \u003Ccode>fxmanifest.lua\u003C\u002Fcode> and look at its content. Here are the most telling signs.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Obfuscated code in a free or leaked resource\u003C\u002Fstrong> (variables and functions replaced with meaningless strings like \u003Ccode>_0x4a8f\u003C\u002Fcode>, \u003Ccode>aA9Z_x\u003C\u002Fcode>, or long base64-encoded strings)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Needlessly complex functions\u003C\u002Fstrong> in an otherwise simple resource\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Suspicious calls\u003C\u002Fstrong> to modules like \u003Ccode>child_process\u003C\u002Fcode>, \u003Ccode>fs\u003C\u002Fcode>, \u003Ccode>http\u003C\u002Fcode>, \u003Ccode>net\u003C\u002Fcode> for no apparent reason\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Unknown URLs\u003C\u002Fstrong> pointing to external servers or Discord webhooks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Commented-out or disabled code\u003C\u002Fstrong> that shouldn&#39;t be there\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cdiv class=\"markdown-alert markdown-alert-important\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Cpath d=\"M12 22c5.523 0 10-4.477 10-10S17.523 2 12 2 2 6.477 2 12s4.477 10 10 10z\"\u002F>\u003Cpath d=\"M12 8v4\"\u002F>\u003Cpath d=\"M12 16h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>Obfuscation isn&#39;t always a bad sign. Legitimate \u003Cstrong>paid resources\u003C\u002Fstrong> (sold on Tebex, for instance) are often obfuscated to protect the developer&#39;s intellectual property. That&#39;s normal and accepted in the FiveM community.\u003C\u002Fp>\n\u003Cp>On the other hand, if you find \u003Cstrong>obfuscated code in a free, open, or leaked resource\u003C\u002Fstrong>, that&#39;s very suspicious. A developer who shares their code for free has no reason to hide it, unless they have something to conceal.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch3>Watch out for files that seem short\u003C\u002Fh3>\n\u003Cp>A very common technique is to \u003Cstrong>make a file look short\u003C\u002Fstrong> when it actually hides malicious code further down.\u003C\u002Fp>\n\u003Cp>The backdoor&#39;s creator places visible code at the top (a few dozen or a few hundred lines that look normal), then adds \u003Cstrong>thousands of blank lines\u003C\u002Fstrong> to push the payload all the way to the bottom of the file. When you open the file in an editor, you see the end of the apparent code and think that&#39;s it, without suspecting that scrolling down reveals thousands of blank lines hiding another block of malicious code.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-tip\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cpath d=\"M12 16v-4\"\u002F>\u003Cpath d=\"M12 8h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>To avoid falling into this trap, run two systematic checks on every suspicious file.\u003C\u002Fp>\n\u003Col>\n\u003Cli>The \u003Cstrong>file&#39;s size\u003C\u002Fstrong> on disk. A \u003Ccode>.lua\u003C\u002Fcode> file with 200 apparent lines that weighs several \u003Cstrong>megabytes\u003C\u002Fstrong> is very suspicious\u003C\u002Fli>\n\u003Cli>The \u003Cstrong>last line number\u003C\u002Fstrong> in your editor (visible in the bottom right in VSCode, for example). If the editor shows \u003Ccode>Line 1 of 87,432\u003C\u002Fcode> while you only see 200 lines of code, immediately jump to the bottom with \u003Ccode>Ctrl+End\u003C\u002Fcode>. That&#39;s almost always where the backdoor is hiding.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>What to do if you suspect a backdoor\u003C\u002Fh2>\n\u003Cp>If the signs above match what you&#39;re observing, here&#39;s what to do.\u003C\u002Fp>\n\u003Ch3>1. Identify the culprit resource\u003C\u002Fh3>\n\u003Cp>In the logs, find the \u003Cstrong>resource name\u003C\u002Fstrong> that appears in the suspicious messages (in quotes). That&#39;s your starting point.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-tip\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cpath d=\"M12 16v-4\"\u002F>\u003Cpath d=\"M12 8h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>Watch out, some backdoors use \u003Cstrong>misleading names\u003C\u002Fstrong> that resemble official or legitimate resources (variants of \u003Ccode>ESX-helper\u003C\u002Fcode>, \u003Ccode>EssentialMode\u003C\u002Fcode>, or even names mimicking an official account like \u003Ccode>root@cfx.re\u003C\u002Fcode>). A name that looks reassuring or official guarantees nothing. Check whether the resource is really the one you think you installed and compare it against official names.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch3>2. Stop the resource immediately\u003C\u002Fh3>\n\u003Cp>From the FiveM console, stop the suspicious resource.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">stop RESOURCE_NAME\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Then \u003Cstrong>comment out\u003C\u002Fstrong> its \u003Ccode>ensure\u003C\u002Fcode> line in your \u003Ccode>server.cfg\u003C\u002Fcode> so it doesn&#39;t start again on the next restart.\u003C\u002Fp>\n\u003Ch3>3. Save the logs\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Before anything else\u003C\u002Fstrong>, save the server&#39;s entire console output to a text file. These logs are essential for analyzing the extent of the infection and determining what information may have been stolen.\u003C\u002Fp>\n\u003Ch3>4. Change all your passwords\u003C\u002Fh3>\n\u003Cp>If the backdoor had access to your \u003Ccode>server.cfg\u003C\u002Fcode>, treat all your credentials as compromised.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>MySQL\u003C\u002Fstrong> password (from your Winheberg panel, \u003Cstrong>Rotate password\u003C\u002Fstrong> option)\u003C\u002Fli>\n\u003Cli>API keys (Discord, Steam, third-party services)\u003C\u002Fli>\n\u003Cli>Your \u003Cstrong>Winheberg account\u003C\u002Fstrong> password\u003C\u002Fli>\n\u003Cli>Any other secret present in \u003Ccode>server.cfg\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>5. Analyze your database\u003C\u002Fh3>\n\u003Cp>Check whether any data has been modified or exfiltrated.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Recently added admin accounts\u003C\u002Fli>\n\u003Cli>Unusual changes to sensitive tables (\u003Ccode>users\u003C\u002Fcode>, \u003Ccode>permissions\u003C\u002Fcode>, \u003Ccode>bans\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>Unknown tables that may have been created by the backdoor\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>6. Remove the resource\u003C\u002Fh3>\n\u003Cp>Once the evidence is saved, \u003Cstrong>completely delete\u003C\u002Fstrong> the compromised resource&#39;s folder. Don&#39;t just disable it, since part of the code may still run under certain conditions.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-caution\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cline x1=\"12\" y1=\"8\" x2=\"12\" y2=\"12\"\u002F>\u003Cline x1=\"12\" y1=\"16\" x2=\"12.01\" y2=\"16\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>If you find that the infection has \u003Cstrong>spread to other resources\u003C\u002Fstrong> on your server (malicious code injected elsewhere, or several resources now showing suspicious behavior), removing a single resource won&#39;t be enough. At that point it&#39;s time to \u003Cstrong>start fresh\u003C\u002Fstrong>, meaning reinstalling your FiveM server cleanly from trusted sources and your last reliable backup, from before the infection.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>Are there tools to scan resources?\u003C\u002Fh2>\n\u003Cp>The FiveM community has developed several \u003Cstrong>resource scanners\u003C\u002Fstrong> capable of automatically detecting known malicious patterns (obfuscation, suspicious calls, suspicious code, etc.). Based on feedback from our support team, these tools work fairly well, but with a few important limitations.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>You need to \u003Cstrong>find a reliable, actively maintained scanning resource\u003C\u002Fstrong>, since patterns keep evolving\u003C\u002Fli>\n\u003Cli>The techniques used by backdoor creators \u003Cstrong>keep evolving\u003C\u002Fstrong>. What passed a scan 6 months ago may now be detected, and conversely, a new technique may fly under the radar\u003C\u002Fli>\n\u003Cli>A scan that detects nothing \u003Cstrong>doesn&#39;t guarantee there&#39;s no backdoor\u003C\u002Fstrong>, it&#39;s just one more data point\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cdiv class=\"markdown-alert markdown-alert-important\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Cpath d=\"M12 22c5.523 0 10-4.477 10-10S17.523 2 12 2 2 6.477 2 12s4.477 10 10 10z\"\u002F>\u003Cpath d=\"M12 8v4\"\u002F>\u003Cpath d=\"M12 16h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>No tool replaces \u003Cstrong>your own vigilance\u003C\u002Fstrong>. A clean scan is reassuring, but never excuses you from checking the sources of your resources yourself, their authors, and regularly monitoring your server&#39;s logs.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>Winheberg can help you investigate\u003C\u002Fh2>\n\u003Cp>If you have a serious doubt about a backdoor, \u003Cstrong>our team can run a network investigation\u003C\u002Fstrong> on your server. In particular, we can check the following.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Whether your server \u003Cstrong>communicates with suspicious IP addresses\u003C\u002Fstrong> linked to known backdoors\u003C\u002Fli>\n\u003Cli>Whether \u003Cstrong>abnormal outbound data flows\u003C\u002Fstrong> indicate an ongoing exfiltration\u003C\u002Fli>\n\u003Cli>What \u003Cstrong>inbound connections\u003C\u002Fstrong> have recently been established with your server\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This analysis lets us \u003Cstrong>confirm or rule out\u003C\u002Fstrong> the presence of an active backdoor and assess the extent of a possible compromise. Contact our support specifying that you suspect a backdoor, and we&#39;ll start the investigation quickly.\u003C\u002Fp>\n\u003Ch2>How to avoid backdoors going forward\u003C\u002Fh2>\n\u003Cp>The best defense against backdoors remains \u003Cstrong>prevention\u003C\u002Fstrong>. A few rules to apply systematically.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Only download resources from official sources\u003C\u002Fstrong> (Tebex, recognized authors&#39; GitHub, FiveM Releases on Cfx.re)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Don&#39;t use leaked resources\u003C\u002Fstrong>. Beyond the massive backdoor risk, it&#39;s also a lack of respect toward the developers who spend dozens of hours designing these resources. Supporting creators also means protecting your own server\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Read the code\u003C\u002Fstrong> of resources before installing them (at least the main \u003Ccode>.lua\u003C\u002Fcode> files and the \u003Ccode>fxmanifest.lua\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Be wary of obfuscated or compiled files\u003C\u002Fstrong> (\u003Ccode>.luac\u003C\u002Fcode>, deliberately unreadable code) if the resource is free or leaked. A developer who shares their work for free has no reason to hide their code\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Regularly monitor your logs\u003C\u002Fstrong> to catch suspicious behavior as early as possible\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Update your FiveM artifacts\u003C\u002Fstrong> regularly to benefit from the latest protections (see our guide on changing FiveM versions)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Make regular backups\u003C\u002Fstrong> of your server and your database\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>Need help?\u003C\u002Fh2>\n\u003Cp>If you have even the slightest doubt about an active backdoor on your server, our team is here. Better a false alarm than a compromise that settles in over time. Open a ticket in the \u003Cstrong>Technical\u003C\u002Fstrong> department from your client area, fill in the \u003Cstrong>Produit lié\u003C\u002Fstrong> field with the server in question, and attach the suspicious logs to your request to speed up our analysis.\u003C\u002Fp>\n\u003Cp>Stay vigilant, and good luck protecting your server 🔒\u003C\u002Fp>\n",1788993140946]