Skip to content

FiveM backdoor scanner: find hidden code in your resources

Run a FiveM backdoor check in 30 minutes: the warning signs, what to search for, what scanners can’t prove, and how to clean up after a compromised server.

Published 6 min read

A backdoor is hidden code inside one of your resources that lets someone else run commands on your server. It usually arrives in a leaked or “free” copy of a paid script, and some spread from one infected resource into others. You can check for one in about half an hour by searching your files for a few warning signs. If you find one, the safe fix is a clean rebuild. Deleting a single line is rarely enough.

How a backdoor gets onto a server

Most backdoors come in with code you installed yourself. A leaked script from a Discord server or a reupload site is the classic route. Someone took a paid resource, added a few lines and shared it for free. Escrowed resources found outside the creator’s store are a red flag for the same reason, and you can’t read what’s inside them.

Some infections spread after they land. On the Cfx.re forum, server owners have described obfuscated lines showing up in many resources at once, including default ones like mapmanager and hardcap, and coming back after being deleted. Another thread describes new server_scripts entries appearing in fxmanifest.lua files on every boot. In cases like these, the line you see is a symptom. Something else keeps writing it.

Warning signs on your server

  • Players get money, items or admin rights that nobody gave them.
  • Staff get kicked or banned by actions nobody on the team took.
  • Lines you didn’t write appear in fxmanifest.lua or at the top of a script, often as one very long line.
  • A line you deleted comes back after a restart.
  • Unknown files appear in the server folder, such as an executable next to your server files.
  • Your server.cfg has add_ace or add_principal lines you don’t recognize.
  • The server sends web requests to domains you don’t know.

A 30-minute manual check

Work on a copy of your server files. If you already suspect something, stop the live server first. Your developer can run the searches and you can go through the results together. Every hit is a lead to read. On its own it proves nothing, because plenty of honest scripts use the same functions.

  • Search every resource for PerformHttpRequest, the FiveM function scripts use to call a web address. Write down each URL it calls. Your own log webhooks and known APIs are fine. A domain nobody recognizes, or a URL built from scrambled text, needs a closer look.
  • Search Lua files for load(. Lua’s load function turns text into running code. Some libraries use it for honest reasons. The pattern forum reports describe is load running text that was downloaded from the web or decoded from a scrambled string.
  • Look for obfuscated code: long runs of \x escapes or numbers, single lines thousands of characters long and variables with random names. Authors rarely ship open resources like that.
  • Open every fxmanifest.lua and read the server_scripts and shared_scripts entries. Each file listed there runs on your server. Anything you can’t match to what the resource does needs an explanation.
  • Search for RegisterNetEvent names you don’t recognize. A backdoor needs a way in, and a network event that runs whatever it receives is one of them.
  • Compare any suspicious resource with a fresh copy from its original author. A file-compare tool shows exactly which lines were added.
  • Check server.cfg for ACE lines and add_filesystem_permission lines that you didn’t add yourself.

On Windows, run findstr /s /i /n "PerformHttpRequest" *.lua inside your resources folder to list every match with its line number. On Linux, grep -rn "PerformHttpRequest" resources/ does the same. Swap in the other search terms one by one.

Lock down admin rights with ACE permissions

What backdoor scanners can and can’t prove

A FiveM backdoor scanner, free or paid, searches for patterns like the ones above. That makes it a fast first pass. It can’t prove your server is clean. Obfuscated code is written to dodge known patterns, a new variant won’t be on any list yet, and escrowed files can’t be read at all.

Read the results the same way in both directions. A hit means a person should open that file. A clean report means the scanner found nothing it knows about. Neither one is a verdict.

Limit the damage with the FiveM sandbox

FiveM runs resources in a sandbox. According to the Cfx.re docs, a resource can’t write files into another resource, can’t touch the server’s main folder and can’t run system commands through os.execute. Blocked attempts fail with “Permission denied”. That makes it harder for one infected script to copy itself into the rest.

Two server.cfg commands control the exceptions. add_filesystem_permission lets one resource write into another. Only add it when a resource’s own docs ask for it, and remove any you didn’t add. add_convar_permission limits who can read a convar. By default every resource can read every convar, including the one holding your database connection string. Once a convar has a read permission, only the resources you list can read it. The line follows the pattern add_convar_permission <resource> read <convar>. Grant it to your database resource only, and a backdoor in another script can’t simply read your database password.

Already compromised? Contain it first

  • Take the server offline, or lock it to staff, so the backdoor can’t be used while you work.
  • Keep a copy of the infected files for reference, then stop working from them.
  • Rebuild from clean copies: fresh server artifacts, the official cfx-server-data from GitHub and each resource downloaded again from its original author.
  • Change every secret the server could read: database password, Cfx.re server license key, Discord bot tokens and webhook URLs, txAdmin and RCON passwords.
  • Check your database for admin rights, money and items the attacker handed out, and review your ban and permission lists.

Deleting the one line you found is tempting. Forum reports show why it’s risky: the line came back because another file, or a program dropped outside the resources folder, kept writing it. A clean rebuild removes all of it at once. If the attacker banned your staff, our txAdmin ban guide shows where those bans live and how to lift them.

Read the txAdmin ban guide

Keep it from happening again

  • Buy resources from their authors and keep the receipts. Leaked copies are a common way backdoors arrive.
  • Keep your resources in git or in dated backups, so any changed file stands out.
  • Give each developer their own access and remove it when they leave.
  • Read new resources before you install them, or have your developer do it.
  • Keep your server artifacts updated and your server.cfg tidy.

Harden your server.cfg

Where an anticheat helps

An anticheat can’t clean your files for you. It can watch for what a backdoor does while you fix the cause. Daddy Shield includes hidden backdoor detection among its 40+ protections, and you pick whether each protection only watches, blocks, kicks or bans. Use it alongside a clean rebuild, never in place of one.

See every protection

How to stop cheaters on your FiveM server

FAQ

Is a free FiveM backdoor scanner enough? It’s a good first pass. Follow every hit by reading the file, and don’t treat a clean result as proof.

Can I just delete the bad line? Only once you’ve confirmed nothing else writes it back. If it returns after a restart, rebuild from clean copies.

My server.cfg looks fine. Am I safe? Check it, then check the resources. Backdoors usually live inside scripts, and the cfg only shows you part of the picture.

Are escrowed resources safe? Only when they come from the author’s own store. You can’t read escrowed code, so a leaked copy is a blind install.

See plans and pricing

Make the next cheater your easiest ban.

Every plan includes every feature. If it isn’t right for your server, ask for a refund within 7 days of your first payment.