#Fw: I don't have any leaked script! Any!

1 messages Β· Page 1 of 1 (latest)

rancid edgeBOT
near roost
#

Open your resources folder in vscode and type const _ = Buffer.from

#

And show me the result of it

slim crown
near roost
#

Go into vscode, press "File" in the top left, click "open folder"

#

Then select your resources folder

slim crown
#

it appear only this

near roost
#

That is not your whole resources folder

#

You clicked open file

slim crown
#

yeah

near roost
#

Click "open folder"

slim crown
#

i did

#

but i have it πŸ˜„

near roost
#

So your resources are hosted somewhere else?

slim crown
#

VPS

#

yeah

near roost
#

Any chance you can provide me credentials for that VPS? Only if you agree

#

So I can take a look myself

slim crown
#

I can give you anydesk

rancid edgeBOT
slim crown
#

if you want

near roost
#

Nah

slim crown
#

Le me explain something

#

Could i?

#

I just tried this:

I did fresh install on VPS.
Then i uploaded server with oxmysql(version 2.12.0) and fxversion: 12966
The server crashing and crashing.. Just like for everyone!

Then i tried to install newest oxmysql(version 2.13.0) and fxversion: 12966

Then i restarted the server and automatically gone the fxversion 12746 πŸ™‚
And just crashes πŸ™‚

#

Probably.. Yeah! It is possible to be leaked script! Fine! I agree with you!

#

Incorrect but i agree!

#

But there is no logic just after installing oxmysql 2.13.0 and all vps fxversion t o go 12746 from 12966.

near roost
#

The OS is infected

slim crown
#

so.. I just started new vps

#

moved all server without artefacts and oxmysql

#

I tried with version oxmysql 2.12.0

near roost
#

How do you even edit resources if you can't open them in vscode or so

slim crown
#

Then i just installed again newest oxmysql - 2.13.0

#

restarted the server

near roost
slim crown
#

and bum

slim crown
near roost
#

Can you do that for the whole folder?

slim crown
#

Nope

slim crown
near roost
#

Connect to the VPS using SSH extension in vscode

slim crown
#

yep

#

im trying it

#

give me some minutes

near roost
#

Sure

slim crown
near roost
#

So when you've opened your resources folder, you press ctrl + shift + F

#

and then paste it there

slim crown
#

wait

#

everything just

#

get crazy

near roost
#

:O

slim crown
#

Even this which i bought?

near roost
#

Cooked

slim crown
#

holy

#

moly

#

but this is even scripts from github

near roost
#

Github scripts can contain backdoors as well

slim crown
#

okay

#

thats new info for me

#

πŸ˜„

slim crown
elfin tulip
#

Yea

#

A big backdoor lol

slim crown
#

in RageUI also??

elfin tulip
#

Yea

slim crown
#

and in all esx scripts?

near roost
#

The issue usually stems from 1 leaked resource, whether you knew if it was leaked or not, it just injects itself into basically everything

elfin tulip
#

In every script

near roost
#

Yeah

slim crown
#

give me your paypal

#

if you want

near roost
#

Nah

#

Its fine

slim crown
#

You sure?

near roost
#

Yes

slim crown
#

Its 100$ dude πŸ˜„

#

Okay..

#

You know best

plush lion
near roost
#

I dont feel like giving you my full name πŸ’€

#

Good luck with your OS tho and in the future only get your resources from trusted locations

slim crown
#

Thank you Yorick

#

I have only one more question

near roost
#

Ofc

plush lion
slim crown
#

All this files are generated by the backdoor script right?

severe pawn
#

And what's the point of doing that and people who can't buy scripts?

slim crown
#

I mean.. It infected all others?

near roost
severe pawn
slim crown
plush lion
slim crown
#

and if is okay.. Insert it in the machine

slim crown
slim crown
#

I mean.. All is the same

near roost
#

Yeah that is a Base64 string and if you decode it it will show you a URL

#

Throw it in here

slim crown
#

check this out

#

lol

#

πŸ˜„

near roost
#

Yeah that one has been known

wet vault
#

as I see, many of us have this problem, if anyone wants they can contact me in DM to see what resource we have in common from github which had a backdoor

#

(also if it is not github, just to understand because the backdoor its literally the same one...)

slim crown
rancid edgeBOT
wet vault
#

but why it was working and now it is not if also before it had a backdoor?

slim crown
#

Just there is no logic in that..

I just tried this:

I did fresh install on VPS.
Then i uploaded server with oxmysql(version 2.12.0) and fxversion: 12966
The server crashing and crashing.. Just like for everyone!

Then i tried to install newest oxmysql(version 2.13.0) and fxversion: 12966

Then i restarted the server and automatically gone the fxversion 12746 πŸ™‚
And just crashes πŸ™‚
Probably.. Yeah! It is possible to be leaked script! Fine! I agree with you!
Incorrect but i agree!
But there is no logic just after installing oxmysql 2.13.0 and all vps fxversion to go 12746 from 12966.

wet vault
wet vault
#

that is what is going on

#

i guess we are dump yes.. its a game YES! but how is this possible ...

slim crown
#

Just there is no logic in that.. This cannot happen only from backdoor.

#

And to happen for 100+ customers of cfx.

wet vault
#

they also told me "man its maybe due fivegua**rd that is overdoing something with artifacts" but it was on a fresh VPS and a fresh ESX server πŸ˜‚

wet vault
slim crown
#

In the past i had backdoors also.

#

But.. Never this happend.

wet vault
slim crown
#

Idk why.. But after i think that oxmysql is the problem with this nodeJS 22.

wet vault
#

we tryed also to do a oxmysql + artifacts downgrade

slim crown
#

same

#

and the server can't start

wet vault
#

but in the .dmp it always show the same artifacts lol

slim crown
#

because big delay

#

and ram leak

wet vault
wet vault
rancid edgeBOT
# wet vault exactly

:rocket: Congratulations @wet vault, you leveled up to <@&828359841512816671>!

slim crown
#

I know πŸ™‚

wet vault
#

did it show you some "tick" on ?

slim crown
#

Yep

wet vault
slim crown
#

from 200ms.. To 30 000ms πŸ™‚

#

Just like starting

wet vault
slim crown
#

just you see "server thread hitching"

wet vault
slim crown
wet vault
slim crown
#

Probably this is the end of FiveM era for a lot of peoples just like us πŸ˜„

slim crown
#

Other think is..
Probably a lot of peoples just had backdoors in their servers.
And after installing oxmysql 2.13.0.. Then somehow oxmysql activated this backdoors and fcked up all our servers.

wet vault
#

we didnt had them in the january backup

#

they showed up later

#

but now which type of artifacts and oxmysql you are gonna put?

slim crown
#

12933 and 2.13.0

#

And i'm starting my server just from zero. πŸ™‚

#

I will check every scripts before i add it. πŸ™‚

#

Yesterday i just started new vps. I installed qbx and oxmysql on latests artefacts and there haven't problem. πŸ™‚

cerulean kernel
#

i will see a few days later 🀣

slim crown
#

cuz no sleep :X

wet vault
#

we are cleaning it, now its going everything under .zip we will reinstall the OS and will try with the latest artifacts

slim crown
#

I tried same.

#

Didn't helped.

wet vault
slim crown
#

Find the script first which inject backdoor in other resources.

#

Then clean everything.

near roost
#

@wet vault

#

Wrote a little doc for it

wet vault
#

also we searched for the specific base64 string of the backdoor

#

we found more than 130+ file

#

now we reinstalled the OS

#

did the VPS setup and now its installing the .zip backup

#

we will do another search about it just to be sure its everything ok

#

(we didnt saved our cache/artifacts just to be sure)

wet vault
# wet vault

do you think this is gonna be the right artifacts choice or we should go for the last?

#

i think this one its pretty stable

#

@near roost

near roost
#

Idk

wet vault
wet vault
#

we are pretty sure there was something inside the artifacts

#

we also did a reebot of the server several time (with the same resources)

slim crown
#

Yep.. In 12746 :]

wet vault
#

0 backdoor

wet vault
wet vault