Jump to content
LOOKING FOR ROBLOX ASSETS? VISIT ROBLOXBAY.COM! ×
THE BEST DISCORD BACKUP BOT | PRESERVE YOUR DISCORD SERVER! ×

RobloxBay

Visit Site

FiveSecured

 

Stop shipping plaintext. FiveSecured encrypts, obfuscates, and licenses your Lua resources so customers run your work without ever holding your source.

Try for Free

funky69

Snail
  • Posts

    24
  • Joined

  • Last visited

Everything posted by funky69

  1. funky69

    red clay rp

    kinda shit leak, nothing in any of the stream folders
  2. please tell me how do i fix this
  3. BACKDOOR - Copy &pasted from chat gpt so it could look through the files Yes. This batch has a backdoor. Do not run this resource as uploaded. The main problem is framework.js. It reads your fxmanifest, loads the configured UI file, extracts a Base64 string from const config, decodes the string, then executes the result with new Function(code)(). Your interface.html contains the Base64 payload inside const config. Decoded, the payload is essentially JavaScript which contacts kim-aki.com, downloads more JavaScript, and executes the downloaded response with eval(). So whoever controls the remote server gets remote code execution inside the FiveM server process. The fxmanifest loads framework.js as a shared script, which activates this loader when the resource starts. There is a second malicious loader in en.lua. This line disguises load using string.char(108, 111, 97, 100), which spells "load". It then reads code hidden inside Roboto.ttf and executes the extracted content. So you have at least two separate hidden execution methods: framework.js → interface.html → Base64 payload → kim-aki.com → downloaded code → execution. en.lua → Roboto.ttf → hidden Lua → load() → execution. There is another security issue. functions(3).lua contains a Discord bot token directly in the source. Treat that token as compromised and regenerate it through Discord immediately. version_checker(1).lua also contacts api.vezironi.com. From the code shown, this request appears to retrieve version information and does not execute the response. Do not only delete framework.js. The en.lua and Roboto.ttf loader would still remain. I would remove framework.js from the resource, remove it from shared_scripts in fxmanifest.lua, delete the malicious config block from interface.html, remove lines 126 to 127 from en.lua, replace Roboto.ttf with a clean copy, and rotate the exposed Discord bot token. If this resource has already run on your server, assume the remote payload had the same permissions as your FXServer process.
    BACKDOOR Yes. This batch has a backdoor. Do not run this resource as uploaded. The main problem is framework.js. It reads your fxmanifest, loads the configured UI file, extracts a Base64 string from const config, decodes the string, then executes the result with new Function(code)(). Your interface.html contains the Base64 payload inside const config. Decoded, the payload is essentially JavaScript which contacts kim-aki.com, downloads more JavaScript, and executes the downloaded response with eval(). So whoever controls the remote server gets remote code execution inside the FiveM server process. The fxmanifest loads framework.js as a shared script, which activates this loader when the resource starts. There is a second malicious loader in en.lua. This line disguises load using string.char(108, 111, 97, 100), which spells "load". It then reads code hidden inside Roboto.ttf and executes the extracted content. So you have at least two separate hidden execution methods: framework.js → interface.html → Base64 payload → kim-aki.com → downloaded code → execution. en.lua → Roboto.ttf → hidden Lua → load() → execution. There is another security issue. functions(3).lua contains a Discord bot token directly in the source. Treat that token as compromised and regenerate it through Discord immediately. version_checker(1).lua also contacts api.vezironi.com. From the code shown, this request appears to retrieve version information and does not execute the response. Do not only delete framework.js. The en.lua and Roboto.ttf loader would still remain. I would remove framework.js from the resource, remove it from shared_scripts in fxmanifest.lua, delete the malicious config block from interface.html, remove lines 126 to 127 from en.lua, replace Roboto.ttf with a clean copy, and rotate the exposed Discord bot token. If this resource has already run on your server, assume the remote payload had the same permissions as your FXServer process.
  4. BACKDOORS ALL OF HIS SCRIPTS HE POSTED HAVE BACK DOORS HERES A SCREENSHOT OF HIS TK DRUGS SCRIPT DONT DOWNLOAD!!!! ITS NOT WORTH YOUR SERVER
    BACKDOORS ALL OF HIS SCRIPTS HE POSTED HAVE BACK DOORS HERES A SCREENSHOT OF HIS TK DRUGS SCRIPT DONT DOWNLOAD!!!! ITS NOT WORTH YOUR SERVER
  5. BACK DOOR DONT DOWNLOAD!!!! NOT WORTH YOUR SERVER, DONT DOWNLOAD ANYTHING FROM THIS COMMUNIST SLUT I HOPE THIS SHIT FACED NIGLET BURNS WHILE ALIVE,(LL staff if you see this i dont mean it)
    BACKDOOR DONT DOWNLOAD, I KNOW ITS A GOOD SCRIPT BUT NOT WORTH YOUR SERVER
  6. funky69

    Wasabi Ambulance

    what is that?
    Vegetation is a definite 10/10 since it covers most of the map and the roads look so nice, well done
  7. just ran everything through miultiple file checkers and checked for webhooks but nothing came up
  8. Is There Actually
  9. funky69

    OLDSKOOLRP

    can you dump a server for me pleaseeeeeee
  10. tennessee State Roleplay (TSRP) Not Whitelisted i dont have discord link but just type tennessee on fiveM and its there
  11. how do i fix this [script:wasabi_police] SCRIPT ERROR: @wasabi_police/game/server/updater.lua:73: bad argument #2 to 'tonumber' (base out of range)
  12. broken link, please fixxxxx
  13. file is fvcked up (corrupted)
  14. it wont let me pull them out it says "unable to use airsoft uzi"
×
×
  • Create New...

Important Information

By continuing on Launcherleaks.net, you agree to our Terms of Use, Guidelines & Privacy Policy