วิธีป้องกัน FiveM Server โดนแฮกและป้องกันบัญชี Admin

การป้องกัน FiveM Server โดนแฮกต้องทำหลายชั้นพร้อมกัน ทั้งบัญชี Cfx, txAdmin, ACE Permissions, Network Events, Database, Firewall, Remote Access, Secrets และ Backup เพราะต่อให้ Script ปลอดภัย แต่บัญชี Admin ถูกขโมย ผู้โจมตีก็อาจมีสิทธิ์ Restart Resource, ใช้ Console, แก้ server.cfg หรือจัดการผู้เล่นได้

สิ่งที่ควรทำเป็นอันดับแรกคือ

  • เปิด 2FA ให้บัญชี Cfx

  • เก็บ Backup Codes แยกจาก Password

  • ใช้ Password ไม่ซ้ำ

  • จำกัดสิทธิ์ txAdmin ตามหน้าที่

  • อย่าแจก all_permissions โดยไม่จำเป็น

  • จำกัดผู้ที่ใช้ manage.admins

  • ป้องกัน Console และ server.cfg

  • ตรวจ Network Events ฝั่ง Server

  • เก็บ API Keys/Database Password ไว้ Server-side

  • จำกัด Port ด้วย Firewall

  • ปิด Remote Services ที่ไม่ใช้

  • Update FXServer และ Resources

  • เก็บ Admin Action Logs

  • Backup Database/Config

  • เตรียม Incident Response

บทความนี้จาก comsiam จะวาง Security Checklist ตั้งแต่ Account ไปจนถึง Infrastructure เพื่อให้ Server Owner สามารถลดความเสี่ยงได้อย่างเป็นระบบ

① FiveM Server “โดนแฮก” หมายถึงอะไร?

คำนี้ครอบคลุมหลายเหตุการณ์ เช่น

  • Cfx Account ถูกยึด

  • txAdmin Account ถูกยึด

  • Admin Account ถูกขโมย

  • Network Event ถูก Exploit

  • Resource มี Backdoor

  • Database Credential หลุด

  • VPS/RDP/SSH ถูกยึด

  • API Token หลุด

  • Server ถูก DDoS

  • Admin ใช้สิทธิ์ในทางผิด

แต่ละเหตุการณ์ต้องใช้วิธีป้องกันต่างกัน

② อย่าคิดว่าติด Anti-cheat แล้ว Server ปลอดภัย

Anti-cheat เป็นเพียง Security Layer หนึ่ง

มันไม่ได้แทน

  • Account Security

  • Event Validation

  • Firewall

  • ACE Permissions

  • Secure Password

  • Database Security

  • Backup

Server Security ต้องเป็น Defense in Depth

③ ป้องกันบัญชี Cfx เป็นอันดับแรก

บัญชี Cfx มีความสำคัญกับระบบ FiveM หลายส่วน

หากบัญชี Owner ถูกยึด ผลกระทบอาจมากกว่าการที่ผู้เล่นทั่วไป Cheat ใน Server

จึงต้องรักษาบัญชีนี้เหมือนบัญชีสำคัญทางธุรกิจ

④ เปิด Two-Factor Authentication

Cfx รองรับ Two-Factor Authentication หรือ 2FA

เมื่อเปิดแล้ว การ Login ต้องใช้

Password
+
รหัสยืนยันแบบมีเวลาจำกัด

ช่วยลดความเสี่ยงเมื่อ Password หลุด

⑤ Cfx รองรับ 2FA แบบใด?

Cfx Support ระบุว่าสามารถใช้

  • Token-based Authenticator

  • Physical Security Key

  • Backup Codes

ตัวอย่าง Authenticator ได้แก่แอปประเภท TOTP

⑥ Security Key ใช้ได้ไหม?

ได้

Cfx Support ระบุว่าสามารถเพิ่ม Physical Security Key เช่นอุปกรณ์ในกลุ่ม YubiKey ได้

สำหรับบัญชี Owner ที่สำคัญมาก Hardware Security Key เป็นตัวเลือกที่ควรพิจารณา

⑦ Backup Codes สำคัญมาก

หลังเปิด 2FA ควรสร้าง Backup Codes

และเก็บไว้ในสถานที่ปลอดภัย

อย่าเก็บ

Password
+
2FA Backup Codes

ไว้ในไฟล์เดียวกันบน Desktop

ถ้าเครื่องถูกยึด ผู้โจมตีจะได้ทั้งสองอย่าง

⑧ Backup Codes ใช้ซ้ำได้หรือไม่?

Cfx ระบุว่า Backup Code ที่ใช้ Recovery แล้วจะไม่สามารถใช้ซ้ำได้

ดังนั้นควรจัดการ Code อย่างเป็นระบบและเก็บชุดปัจจุบันให้ปลอดภัย

⑨ Password ของ Cfx ต้องไม่ซ้ำกับที่อื่น

อย่าใช้ Password เดียวกันกับ

  • Discord

  • Email

  • VPS

  • Database

  • txAdmin

  • Hosting Panel

หากบริการหนึ่งรั่ว ผู้โจมตีอาจนำ Password ไปลองกับบริการอื่น

เรียกว่า Credential Stuffing

⑩ Email Account ก็ต้องเปิด 2FA

การป้องกัน Cfx Account แต่ปล่อย Email ไม่มี 2FA เป็นจุดอ่อน

เพราะ Email มักใช้

  • Login Verification

  • Password Reset

  • Security Notification

ดังนั้น Owner Email ต้องได้รับการป้องกันในระดับเดียวกัน

⑪ Cfx ตรวจ Device/Location ใหม่หรือไม่?

Cfx มีระบบที่อาจขอ Verification เพิ่มเมื่อ Login จาก Device หรือ Location ที่ไม่คุ้นเคย

ถ้าได้รับ Email Login ที่ไม่ได้ทำเอง

ให้ถือเป็น Security Warning

และตรวจบัญชีทันที

⑫ อย่า Approve Login ที่ไม่รู้จัก

ถ้ามีคำขอ Login/Authorize ที่คุณไม่ได้เริ่มเอง

อย่ากด Allow

อาจเป็น

  • Phishing

  • Session Attack

  • ผู้โจมตีที่มี Password แล้ว

ตรวจ Source ก่อนเสมอ

⑬ ป้องกัน txAdmin ต่อจาก Cfx Account

txAdmin เป็น Web Administration Panel ของ FXServer

สามารถทำสิ่งสำคัญ เช่น

  • Start Server

  • Stop Server

  • Restart Server

  • Restart Resources

  • Execute Console Commands

  • Edit server.cfg

  • Ban/Kick Players

  • จัดการ Admin

ดังนั้นการยึด txAdmin อาจส่งผลร้ายแรงมาก

⑭ txAdmin มีระบบ Login แบบใด?

เอกสาร Cfx.re ระบุว่า txAdmin รองรับ

  • Password Login

  • CitizenFX/Cfx Login

และมีระบบ

  • Admin Permissions

  • Action Logging

  • Brute-force Protection

แต่ Server Owner ยังต้องตั้ง Permission ให้ถูกต้อง

⑮ txAdmin Default Port คืออะไร?

ค่าเริ่มต้นของ txAdmin คือ

40120/TCP

และ Interface Default ปัจจุบันคือ

0.0.0.0

ดังนั้นต้องตรวจ Firewall และ Network Exposure ของเครื่องจริงด้วย

⑯ ต้องเปิด txAdmin Port ให้ทั้ง Internet ไหม?

หาก Infrastructure อนุญาต ควรจำกัด Administrative Surface ให้แคบที่สุด

ตัวอย่างแนวคิด

Internet
↓
Firewall
↓
อนุญาตเฉพาะแหล่งที่ต้องใช้
↓
txAdmin

ยิ่ง Admin Panel เปิดกว้าง Attack Surface ยิ่งมาก

⑰ ถ้าต้อง Admin จากหลายที่ทำอย่างไร?

ใช้ระบบ Remote Access ที่ทีมดูแลได้อย่างปลอดภัย

และควรมี

  • Authentication แข็งแรง

  • Encryption

  • Access Control

  • Logs

อย่าปิด Security ของ Firewall เพียงเพราะต้องการความสะดวก

⑱ txAdmin มี Brute-force Protection แล้วต้องใช้ Password ดีไหม?

ต้อง

Brute-force Protection ช่วยลดการเดารหัส

แต่ไม่ป้องกันกรณี

  • Password รั่ว

  • Phishing

  • Password Reuse

  • Malware

จึงยังต้องใช้ Unique Strong Password

⑲ อย่าแชร์บัญชี Admin

ไม่ควรมี Account เช่น

username: admin
password: xxxx

แล้วให้ทีม 10 คนใช้ร่วมกัน

ควรให้แต่ละคนมี Account ของตัวเอง

เพื่อให้

  • ถอนสิทธิ์เป็นรายคน

  • ดู Log ได้

  • รู้ว่าใครทำ Action

⑳ ใช้ Least Privilege กับ txAdmin

txAdmin มี Permission System ละเอียด

ไม่จำเป็นต้องให้ Admin ทุกคน

all_permissions

ถ้าหน้าที่ของเขาคือเพียง

  • Warn

  • Kick

  • Ban

ให้เฉพาะ Permission เหล่านั้น

㉑ all_permissions คืออะไร?

txAdmin ระบุว่า

all_permissions

เป็น Root Permission ที่สามารถทำทุก Action

ควรจำกัดให้ Owner หรือบุคคลจำนวนน้อยที่สุด

㉒ manage.admins สำคัญแค่ไหน?

Permission

manage.admins

อนุญาตให้สร้าง แก้ไข และลบ Admin Accounts

นี่เป็น Permission ที่อันตรายมากหากบัญชีถูกยึด

ควรให้เฉพาะผู้ที่ต้องดูแล Admin จริง ๆ

㉓ console.write ก็เป็น Permission สำคัญ

Permission

console.write

อนุญาตเขียน Console Commands

ผู้ใช้ที่มีสิทธิ์นี้อาจสามารถทำ Action ระดับ Server สูงมากได้

อย่าให้ Moderator ทั่วไปโดยไม่จำเป็น

㉔ server.cfg.editor ต้องจำกัด

Permission นี้อนุญาตอ่าน/เขียน server.cfg

Config อาจมี

  • Server Settings

  • Resource Config

  • Security Settings

  • Sensitive Values บางอย่าง

ดังนั้นไม่ควรให้ Admin ทุกคนเข้าถึง

㉕ control.server ต้องให้ใครบ้าง?

Permission นี้เกี่ยวข้องกับ

  • Start

  • Stop

  • Restart Server

Support Staff ที่ทำเพียง Ticket หรือดูแลผู้เล่นไม่จำเป็นต้องมีสิทธิ์นี้เสมอไป

㉖ commands.resources ก็มีความเสี่ยง

ใช้ Start/Stop Resources

ถ้า Admin Account ถูกยึด ผู้โจมตีอาจปิด

  • Anti-cheat

  • Framework Resource

  • Logging

  • Security Resource

ได้หากมี Permission มากเกินไป

㉗ แบ่ง Admin Roles ให้ชัด

ตัวอย่าง:

Owner

ทุกสิทธิ์ที่จำเป็น

Developer

Console/Resources ตามงาน

Senior Admin

Ban/Kick/Whitelist

Moderator

Warn/Kick

Support

ดูข้อมูลหรือช่วยผู้เล่นบางส่วน

อย่าใช้ Permission Set เดียวกับทุกคน

㉘ เมื่อ Admin ลาออกต้องทำอะไร?

ทันทีที่คนไม่ต้องใช้สิทธิ์แล้ว

  • Disable/Delete Admin Access

  • ลบ ACE

  • ถอน VPN/SSH/RDP

  • Rotate Shared Secret ที่เขาเคยเห็น

  • ตรวจ API Keys ถ้าจำเป็น

อย่าปล่อย Account เก่าค้างไว้

㉙ Admin Account เก่าคือ Attack Surface

Account ที่ไม่มีใครใช้แต่ยังเปิดอยู่เป็นเป้าหมายโดยไม่จำเป็น

ทำ Admin Audit เป็นระยะ

ตรวจว่า

คนนี้ยังทำงานอยู่ไหม?
ยังต้องมี Permission นี้ไหม?

㉚ txAdmin มี Action Logging

Cfx.re ระบุว่า txAdmin มี Action Logging

จึงควรใช้ Log สำหรับตรวจ

  • ใคร Restart Server

  • ใคร Ban Player

  • ใครใช้ Admin Action

  • มี Action ผิดปกติหรือไม่

Log มีประโยชน์มากหลัง Incident

㉛ Log ต้องถูกตรวจจริง

มี Log แต่ไม่เคยเปิดดูแทบไม่มีประโยชน์

ตรวจอย่างน้อยเมื่อมี

  • Ban ผิดปกติ

  • Resource ถูก Stop

  • Server Restart โดยไม่ทราบสาเหตุ

  • Permission เปลี่ยน

  • Admin Account แปลก

㉜ Network Event ยังเป็นช่องโจมตีสำคัญ

แม้ Account Security แข็งแรง Server ก็ยังโดน Exploit ผ่าน Resource ที่เขียนไม่ปลอดภัยได้

Cfx.re เตือนว่า Cheat Client สามารถ Trigger Network Events ได้

จึงต้อง Validate ทุก Event สำคัญฝั่ง Server

㉝ อย่าให้ Client กำหนด Reward

ตัวอย่างที่อันตราย:

RegisterNetEvent('job:finish', function(reward)
    AddMoney(source, reward)
end)

ผู้โจมตีสามารถพยายามส่ง Reward เอง

Server ต้องคำนวณ Reward จาก Logic ฝั่ง Server

㉞ Server ต้องตรวจ Position

ถ้า Event ใช้ได้เฉพาะในพื้นที่หนึ่ง

ตรวจ Player Coordinates จาก Server

เช่น

Player ขอขายของ
↓
Server ตรวจตำแหน่ง
↓
อยู่จุดขายจริง
↓
จึงดำเนินการ

ลด Remote Event Abuse

㉟ Server ต้องตรวจ Inventory

อย่าเชื่อ Client ว่า

“ฉันมี Item 50 ชิ้น”

Server ต้องอ่าน Inventory State ที่เป็น Authority ของตัวเอง

แล้วค่อยทำ Transaction

㊱ Server ต้องตรวจ Permission ซ้ำ

Admin Menu ฝั่ง Clientอาจซ่อนจาก Player ธรรมดา

แต่ทุก Admin Event ต้องตรวจ Permission ฝั่ง Serverอีกครั้ง

Client Admin Menu
↓
Server Event
↓
Permission Check
↓
Action

㊲ AddEventHandler กับ RegisterNetEvent ต้องใช้ถูก

Event ที่ไม่จำเป็นต้องข้าม Network ควรใช้ Local Event

อย่าทำทุกอย่างเป็น RegisterNetEvent

เพราะ Network Event เพิ่มสิ่งที่ Client สามารถพยายามเรียกได้

㊳ ใช้ source แทน Player ID จาก Client

ถ้า Event มี Player ผู้เรียกอยู่แล้ว

ใช้

local src = source

แทนการให้ Client ส่ง

myServerId = 123

แล้ว Server เชื่อ

㊴ Rate Limit Event สำคัญ

เช่น

  • Purchase

  • Reward

  • Spawn

  • Expensive Query

  • Admin Search

ควรป้องกัน Spam ตาม Use Case

แต่ Rate Limit ต้องใช้ร่วมกับ Validation

㊵ Resource จากแหล่งไม่น่าเชื่อถืออาจเป็น Backdoor

อย่าติดตั้ง Resource เพียงเพราะ

  • แจกฟรี

  • มีคนส่ง ZIP มา

  • เจอใน Discord

  • ชื่อเหมือน Resource ดัง

ตรวจแหล่งที่มาและ Source ก่อน

㊶ Obfuscated Resource ต้องระวัง

Resource บางตัวถูก Obfuscate อย่างถูกกฎหมายเพื่อป้องกัน Source

แต่ถ้า Resource จากผู้พัฒนาไม่รู้จักและไม่สามารถตรวจ Behavior ได้เลย

ถือเป็น Supply-chain Risk

ใช้ Vendor ที่เชื่อถือได้

㊷ Binary แปลก ๆ ต้องระวัง

ถ้า Package มี

  • .exe

  • .dll

  • Native Module

  • Installer

ที่ไม่ได้อธิบายว่าจำเป็นทำไม

อย่ารันบน Production ทันที

ตรวจ Vendor และ Function ก่อน

㊸ อย่า Disable Antivirus/EDR เพื่อติดตั้ง Script แบบสุ่ม

ถ้า Resource บอกให้

“ปิด Antivirus ก่อน”

โดยไม่มีเหตุผลทางเทคนิคที่ตรวจสอบได้

ควรหยุดและตรวจสอบ Source

Security Software ไม่ควรถูกปิดเพื่อความสะดวกในการรันไฟล์ไม่น่าเชื่อถือ

㊹ Secrets ต้องอยู่ Server-side

ห้ามใส่

  • API Key

  • Database Password

  • Discord Bot Token

  • Private License Secret

ใน

client.lua
NUI JavaScript
HTML

เพราะไฟล์ Client ถูกส่งไปเครื่องผู้เล่น

㊺ Public Git ต้องไม่มี Secrets

ก่อน Push Repository ให้ตรวจ

server.cfg
.env
config.lua
database URL
webhook URLs
API tokens
private keys

ใช้ Secret Management ตาม Infrastructure ที่เหมาะสม

㊻ ถ้า Token หลุดต้อง Rotate

อย่าคิดว่า

“ลบ Git Commit แล้วปลอดภัย”

Secret ที่เคย Public ต้องถือว่า Compromised

ให้

Revoke เดิม
↓
สร้างใหม่
↓
Update Server

㊼ Database Password ต้องแยกจาก Root

สร้าง Database Account สำหรับ Application โดยเฉพาะ

อย่าใช้ DBA/Root Account เป็น Connection String ของ Resource หากไม่จำเป็น

ให้ Permission เท่าที่ Application ต้องใช้

㊽ Database Port ไม่ควรเปิดกว้าง

ถ้า Database ใช้เฉพาะ Game Server

Firewall ควรอนุญาต Connection จาก Source ที่จำเป็น

ไม่ใช่

0.0.0.0/0
→ Database

โดยไม่มีเหตุผล

㊾ RDP ต้องป้องกัน

สำหรับ Windows Server ให้รักษา Remote Desktop อย่างจริงจัง

เช่น

  • Password แข็งแรง

  • จำกัด Source IP/VPN เมื่อทำได้

  • Update Windows

  • ไม่แชร์ Administrator Account

  • ปิด Account ที่ไม่ใช้

เพราะถ้า OS ถูกยึด FiveM Security Layer ภายในก็แทบไม่มีความหมาย

㊿ SSH ก็เช่นเดียวกัน

สำหรับ Linux

ควรใช้ Configuration ที่ปลอดภัย เช่น

  • Unique Accounts

  • Strong Authentication

  • จำกัดสิทธิ์

  • ปิด Account ไม่ใช้

  • Patch OS

แนวคิดคือไม่เปิด Remote Administrative Surface เกินความจำเป็น

51. อย่าให้ Developer ทุกคนเป็น OS Administrator

Developer ที่ต้อง Upload Resource ไม่จำเป็นต้องมี Full Root/Administrator เสมอไป

แบ่งสิทธิ์ตามงาน

ช่วยลดผลกระทบทั้งจาก

  • Account ถูกยึด

  • Human Error

52. FTP แบบไม่ปลอดภัยควรหลีกเลี่ยง

หากต้องส่งไฟล์ไป Server ใช้ Protocol/Tool ที่มี Encryption และ Authentication เหมาะสม

อย่าส่ง Credentials/Source ผ่าน Connection ที่ไม่ป้องกันโดยไม่มีเหตุผล

53. Firewall เปิดเฉพาะ Port ที่จำเป็น

รายการ Port ขึ้นกับ Architecture จริง

เช่น

  • FiveM Game Port

  • txAdmin

  • SSH/RDP

  • Database

  • Monitoring

แต่ไม่ควรเปิดทุก Port จาก Internet เพื่อแก้ปัญหา Connection

54. หลัก Default Deny มีประโยชน์

แนวคิด:

Block
↓
Allow เฉพาะสิ่งที่จำเป็น

ดีกว่าเปิดทุกอย่างแล้วค่อยหวังว่า Application จะปลอดภัยเอง

55. txAdmin ไม่จำเป็นต้องเข้าถึงจากทุกประเทศเสมอไป

หากทีม Admin มี Network Pattern ชัดเจน สามารถใช้ Infrastructure Controls ลด Exposure ได้

แต่ต้องออกแบบไม่ให้ Owner Lock ตัวเองออกจากระบบ

มี Recovery Plan เสมอ

56. DDoS ต่างจาก Account Hack

DDoS มีเป้าหมายทำให้ Network/Service ใช้งานไม่ได้

ไม่ได้หมายความว่าผู้โจมตีได้ Password หรือ Control Server

การป้องกันต้องพึ่ง

  • Hosting Network

  • DDoS Mitigation

  • Firewall/Filtering

ตามขนาดการโจมตี

57. อย่าบอกว่าโดน Hack เพียงเพราะ Server เข้าไม่ได้

Server Offline อาจเกิดจาก

  • DDoS

  • Crash

  • Database Down

  • Resource Error

  • Hosting Outage

  • Firewall Config

ต้อง Incident Triage ก่อน

58. Backup เป็น Security Layer สำคัญ

ถ้าเกิด

  • Database เสีย

  • Resource ถูกแก้

  • Admin ลบข้อมูล

  • Server ถูกบุกรุก

Backup ช่วย Recovery

ควรสำรอง

  • Database

  • Resources

  • server.cfg

  • txData ที่จำเป็น

  • Configuration สำคัญ

59. Backup ต้องแยกจากเครื่อง Production

ถ้า Backup อยู่บน Disk เดียวกับ Server

และเครื่องถูกลบ/เข้ารหัสทั้งหมด

Backup อาจหายไปด้วย

อย่างน้อยควรมีสำเนาแยกตามระดับความสำคัญของ Server

60. ต้องทดสอบ Restore

Backup ที่ไม่เคย Restore ยังไม่ควรถูกเชื่อ 100%

ทำ Test เช่น

Backup
↓
Restore Staging
↓
Start Server
↓
ตรวจ Characters
↓
ตรวจ Inventory
↓
ตรวจ Vehicles

61. Update FXServer สำคัญ

ควรใช้ Build ที่ยังได้รับการสนับสนุน

Build เก่ามากอาจพลาด

  • Security Fixes

  • Stability Fixes

  • Platform Improvements

แต่ต้อง Test ก่อน Update Production

62. Resource Dependencies ก็ต้อง Update

เช่น

  • Framework

  • Database Library

  • Admin Resource

  • Web Backend

  • Anti-cheat

ไม่ควรปล่อย Dependency ที่เลิกดูแลหลายปีโดยไม่ประเมิน Risk

63. Update ไม่ควรทำ Blindly

ใช้

Backup
↓
Staging
↓
Update
↓
Security Test
↓
Gameplay Test
↓
Production

เพราะ Update อาจสร้าง Breaking Change เช่นกัน

64. Admin PC ต้องปลอดภัยด้วย

Server Security อาจดีมาก แต่ถ้าเครื่อง Owner มี Malware

Credential อาจถูกขโมยจาก

  • Browser

  • Password Files

  • SSH Keys

  • Session Cookies

Admin Device จึงเป็นส่วนหนึ่งของ Security Boundary

65. อย่าติดโปรแกรม Crack บนเครื่อง Admin

เครื่องที่ใช้จัดการ Production Server ไม่ควรเป็นเครื่องทดลอง

  • Cracked Software

  • Unknown Cheat

  • Unknown Executables

  • Suspicious Browser Extensions

ลด Attack Surface ให้มากที่สุด

66. Browser Extension ก็มีความเสี่ยง

Extension สามารถมี Permission ต่อ Browser Data

บัญชีที่ใช้จัดการ

  • Hosting

  • Cfx

  • txAdmin

  • Git

ควรอยู่บน Browser/Profile ที่สะอาดและควบคุมได้

67. Password Manager ช่วยได้

ใช้ Password Manager ที่เชื่อถือได้เพื่อสร้าง

  • Long Passwords

  • Unique Passwords

ลดปัญหาการใช้รหัสเดียวทุกบริการ

และลดการเก็บ Password ใน .txt

68. Discord Admin Account ต้องป้องกันด้วย

หลาย Community ใช้ Discord สำหรับ

  • Staff

  • Bots

  • Webhooks

  • Support

ถ้า Discord Admin ถูกยึด อาจใช้ Social Engineering หลอกทีม Server ต่อได้

เปิด 2FA และจำกัด Role เช่นเดียวกัน

69. Webhook ถือเป็น Secret หรือไม่?

บาง Webhook สามารถถูก Abuse เพื่อส่ง Spam หรือปลอม Log

จึงไม่ควร Publish โดยไม่มีเหตุผล

หากหลุดให้ Rotate/Delete Webhook และสร้างใหม่

70. อย่าฝัง Bot Token ใน Client

Bot Token ถือเป็น Credential สำคัญ

ต้องอยู่ Server/Backend ที่ผู้เล่นไม่สามารถ Download Source ไปดูได้

71. ตรวจ Admin Logs เมื่อมีเหตุผิดปกติ

หากพบว่า Server มี

  • Ban จำนวนมาก

  • Resource ถูก Stop

  • Config เปลี่ยน

  • Server Restart เอง

ให้ตรวจ

  1. txAdmin Action Logs

  2. OS Login Logs

  3. Hosting Panel Logs

  4. Git/Deployment History

  5. Database Logs

ตาม Infrastructure

72. ถ้าสงสัย Admin Account ถูกยึดต้องทำอะไร?

ลำดับแรก:

  1. Disable Account ต้องสงสัย

  2. เปลี่ยน/Rotate Credential

  3. Revoke Sessions เมื่อระบบรองรับ

  4. ตรวจ Permission Changes

  5. ตรวจ Logs

  6. ตรวจ Resource/Config

  7. ตรวจ Database

  8. ประเมินว่าต้อง Restore หรือไม่

อย่าปล่อย Account ใช้งานต่อระหว่าง Investigation

73. ถ้า Cfx Account ถูกสงสัยว่าหลุด

ให้

  • เปลี่ยน Password

  • ตรวจ Email

  • เปิด/ตรวจ 2FA

  • Rotate Backup Codes หากจำเป็น

  • ตรวจ Login/Authorization ที่ผิดปกติ

  • ติดต่อ Cfx Support เมื่อไม่สามารถกู้บัญชีได้

Account Owner ต้องได้รับ Priority สูงสุด

74. ถ้าพบ Resource แปลกใน Server

อย่าเพียง Delete แล้วเปิด Serverต่อทันที

ตรวจ

  • มาจากไหน

  • ใคร Deploy

  • ถูก Start เมื่อไร

  • มีการแก้ Config หรือไม่

  • มี Credential หลุดหรือไม่

เพราะ Resource แปลกอาจเป็นเพียง Indicator ของการเข้าถึงที่ลึกกว่านั้น

75. ถ้า Database ถูกแก้ผิดปกติ

ให้เก็บ Evidence ก่อนถ้าเป็นไปได้

จากนั้นตรวจ

  • Database Accounts

  • Source IP

  • Application Logs

  • Admin Actions

  • Recent Resource Changes

แล้ว Rotate Database Credentials

76. อย่าแก้ Incident ด้วยการเปลี่ยน Password ตัวเดียว

ถ้า Server ถูกยึดจริงต้องคิดว่า Credential อื่นอาจหลุดด้วย

ตรวจทั้ง

Cfx
Email
txAdmin
Hosting
RDP/SSH
Database
Git
API Tokens
Discord

ตามระดับการเข้าถึงที่ผู้โจมตีอาจมี

77. Incident Response Plan ควรเตรียมก่อนโดน

เขียนไว้เลยว่า

ใครมีอำนาจปิด Server?
Backup อยู่ไหน?
ใคร Rotate Credentials?
ติดต่อ Hosting อย่างไร?
ใครตรวจ Logs?
วิธี Restore คืออะไร?

เวลาเกิด Incident จะไม่ต้องตัดสินใจทุกอย่างตอนฉุกเฉิน

78. เก็บรายชื่อ Admin Access

ทำ Inventory เช่น

บุคคลCfx/txAdminVPSDBGitระดับ
Owner✅✅✅✅สูงสุด
Dev Aจำกัด✅❌✅Developer
Admin B✅ จำกัด❌❌❌Moderator

ช่วยเห็นสิทธิ์ที่มากเกินไป

79. Review Permissions เป็นระยะ

ทุกครั้งที่

  • Staff เปลี่ยน

  • Developer ใหม่เข้า

  • Project จบ

  • Vendor เปลี่ยน

ควรตรวจ Access ใหม่

Permission ที่ถูกต้องเมื่อ 6 เดือนก่อนอาจไม่จำเป็นแล้ว

80. Security Checklist สำหรับ txAdmin

  • Owner เปิด 2FA บัญชี Cfx

  • ใช้ Password Unique

  • Admin แยก Account

  • จำกัด all_permissions

  • จำกัด manage.admins

  • จำกัด console.write

  • จำกัด server.cfg.editor

  • จำกัด control.server

  • ตรวจ Action Logs

  • ลบ Staff เก่า

  • Firewall Port ตามความจำเป็น

81. Security Checklist สำหรับ Scripts

  • Validate Client Input

  • Server คำนวณ Reward

  • Server ตรวจ Inventory

  • Server ตรวจ Position

  • Server ตรวจ Permission

  • Rate Limit Event สำคัญ

  • Local Event ไม่เปิด Network โดยไม่จำเป็น

  • ไม่มี Secret ฝั่ง Client

  • Audit Third-party Resources

82. Security Checklist สำหรับ Infrastructure

  • OS Update

  • Firewall

  • จำกัด RDP/SSH

  • Database ไม่ Public เกินจำเป็น

  • Unique Accounts

  • Unique Passwords

  • Backups แยกเครื่อง

  • Monitoring

  • DDoS Protection

  • Staging Environment

83. Security Checklist สำหรับ Owner

  • Cfx 2FA

  • Email 2FA

  • Backup Codes

  • Password Manager

  • Admin Device สะอาด

  • ไม่ใช้ Software Crack

  • ตรวจ Login Alerts

  • Rotate Secrets เมื่อหลุด

  • มี Incident Plan

84. สิ่งที่ไม่ควรทำเด็ดขาด

หลีกเลี่ยง

  • แชร์ Owner Account

  • ปิด 2FA เพื่อความสะดวก

  • ใช้ Password เดียวทุกระบบ

  • ให้ Admin ทุกคน Root

  • เปิด Database ให้ทั้ง Internet

  • ฝัง API Key ใน Client

  • โหลด Resource จากแหล่งไม่รู้จัก

  • Ignore Admin Logs

  • Backup ไว้เครื่องเดียว

  • Restart แล้วคิดว่า Incident จบ

  • ลบ Evidence ก่อนตรวจ

  • ใช้ Production เป็นเครื่องทดลอง Script

Security ที่ดีมาจากการลดทั้งโอกาสโจมตีและขนาดความเสียหายเมื่อบาง Layer ถูกเจาะ

85. คำถามที่พบบ่อย

ป้องกัน FiveM Server โดนแฮกอย่างไร?

ป้องกันหลาย Layer ได้แก่ Account 2FA, txAdmin Permissions, Secure Events, Firewall, Database Security, Resource Audit และ Backup

บัญชี Cfx เปิด 2FA ได้ไหม?

ได้ Cfx รองรับ Authenticator, Security Key และ Backup Codes

txAdmin มี Brute-force Protection ไหม?

มีตามเอกสาร Cfx.re แต่ยังต้องใช้ Password แข็งแรงและ Permission ที่เหมาะสม

Admin ทุกคนควรมี all_permissions ไหม?

ไม่ ควรใช้ Least Privilege

Permission ไหนใน txAdmin อันตรายสูง?

เช่น all_permissions, manage.admins, console.write, control.server และ server.cfg.editor

Server Event ต้อง Validate ไหมถ้ามี Anti-cheat?

ต้อง Cfx.re แนะนำให้ตรวจ Network Events ฝั่ง Serverเสมอ

Database Password ใส่ใน client.lua ได้ไหม?

ไม่ได้

txAdmin Port คืออะไร?

ค่า Default คือ TCP 40120

Database เปิด Public Internet ได้ไหม?

ควรจำกัด Source ให้เฉพาะที่จำเป็นเมื่อ Infrastructure รองรับ

ถ้าสงสัย Admin ถูกยึดควรทำอะไรอันดับแรก?

Disable Access, Rotate Credentials และตรวจ Logs/Permission Changesทันที

86. สรุปวิธีป้องกัน FiveM Server โดนแฮกและป้องกันบัญชี Admin

การป้องกัน FiveM Server ที่มีประสิทธิภาพต้องเริ่มจาก บัญชี Owner และ Administrative Access ก่อน เพราะ Account ที่มีสิทธิ์สูงสามารถสร้างความเสียหายได้มากกว่า Exploit ทั่วไปหลายประเภท

Cfx รองรับ 2FA สำหรับบัญชี Cfx โดยสามารถใช้ Token-based Authenticator, Physical Security Key และ Backup Codes

ดังนั้น Owner ควรใช้

Unique Password
+
2FA
+
Backup Codes แยกเก็บ

จากนั้นป้องกัน txAdmin

txAdmin มี Permission System ละเอียด ตั้งแต่

all_permissions
manage.admins
console.write
control.server
commands.resources
server.cfg.editor

ไปจนถึง Permission ระดับ Warn/Kick/Ban

อย่าให้ Admin ทุกคนเป็น Root

ใช้หลัก Least Privilege และสร้าง Account แยกต่อ Staff เพื่อให้สามารถ Audit Action ได้

ต่อมาคือ Scripts

Resource ที่รับ Network Event ต้องคิดเสมอว่า Client สามารถพยายามเรียก Event เองได้

Server จึงต้องตรวจ

Money + Inventory + Position + Player State + Permission + Rate

จาก Server-side Data และต้องเป็นผู้คำนวณ Reward เอง

Infrastructure ก็สำคัญไม่แพ้กัน

  • จำกัด txAdmin

  • จำกัด RDP/SSH

  • จำกัด Database

  • เปิด Firewall เฉพาะ Port จำเป็น

  • เก็บ Secrets Server-side

  • ไม่ติด Resource ไม่น่าเชื่อถือ

  • Update Platform

  • มี DDoS Protection ตามระดับความเสี่ยง

สุดท้ายต้องมี Backup และ Incident Response

ถ้าพบ Account หรือ Server ถูกยึด ให้คิดเป็นกระบวนการ

Contain
↓
Disable Access
↓
Rotate Credentials
↓
Preserve / Review Logs
↓
ตรวจ Config / Resources / DB
↓
Recover
↓
Monitor

ไม่ใช่เปลี่ยน Password หนึ่งตัวแล้วเปิด Server ต่อทันที

แนวทางที่ comsiam แนะนำคือแบ่ง Security เป็น 5 ชั้น:

Account Security

→ 2FA, Password, Backup Codes

Admin Security

→ txAdmin Permissions, ACE, Logs

Application Security

→ Secure Events, Server Authority

Infrastructure Security

→ Firewall, OS, Database, Remote Access

Recovery Security

→ Backup, Restore Test, Incident Response

จำสั้น ๆ:

Cfx Owner → เปิด 2FA

Email → เปิด 2FA

Admin → Account แยก

txAdmin → Least Privilege

all_permissions → ให้น้อยคนที่สุด

Network Events → Never Trust Client

Secrets → Server-side เท่านั้น

Database → จำกัด Account และ Network

Resources → ใช้แหล่งเชื่อถือได้

Firewall → เปิดเท่าที่จำเป็น

Logs → ต้องตรวจได้ว่าใครทำอะไร

Backup → ต้อง Restore ได้

Incident → Rotate Credentials ทั้งชุดที่อาจได้รับผลกระทบ

FiveM Server ที่ปลอดภัยจึงไม่ใช่ Server ที่เชื่อว่าไม่มีใครเจาะได้ แต่คือ Server ที่ ทำให้การเจาะยากขึ้น จำกัดความเสียหายเมื่อบัญชีหนึ่งถูกยึด ตรวจพบความผิดปกติได้ และกู้ระบบกลับมาได้โดยไม่สูญเสียข้อมูลทั้งหมด

Comments

Popular posts from this blog

FiveM ยังน่าเล่นไหม? Enhanced เปลี่ยน FiveM แค่ไหน

FiveM คืออะไร เล่นอย่างไร สำหรับมือใหม่ เริ่มต้นตั้งแต่ศูนย์

วิธีตั้ง Admin Permission ด้วย add_ace และ add_principal FiveM แบบละเอียด