วิธีป้องกัน FiveM Server โดนแฮกและป้องกันบัญชี Admin
การป้องกัน FiveM Server โดนแฮกต้องทำหลายชั้นพร้อมกัน ทั้งบัญชี Cfx, txAdmin, ACE Permissions, Network Events, Database, Firewall, Remote Access, Secrets และ Backup เพราะต่อให้ Script ปลอดภัย แต่บัญชี Admin ถูกขโมย ผู้โจมตีก็อาจมีสิทธิ์ Restart Resource, ใช้ Console, แก้ server.cfg หรือจัดการผู้เล่นได้
สิ่งที่ควรทำเป็นอันดับแรกคือ
เปิด 2FA ให้บัญชี Cfx
เก็บ Backup Codes แยกจาก Password
ใช้ Password ไม่ซ้ำ
จำกัดสิทธิ์ txAdmin ตามหน้าที่
อย่าแจก
all_permissionsโดยไม่จำเป็นจำกัดผู้ที่ใช้
manage.adminsป้องกัน Console และ
server.cfgตรวจ Network Events ฝั่ง Server
เก็บ API Keys/Database Password ไว้ Server-side
จำกัด Port ด้วย Firewall
ปิด Remote Services ที่ไม่ใช้
Update FXServer และ Resources
เก็บ Admin Action Logs
Backup Database/Config
เตรียม Incident Response
บทความนี้จาก comsiam จะวาง Security Checklist ตั้งแต่ Account ไปจนถึง Infrastructure เพื่อให้ Server Owner สามารถลดความเสี่ยงได้อย่างเป็นระบบ
① FiveM Server “โดนแฮก” หมายถึงอะไร?
คำนี้ครอบคลุมหลายเหตุการณ์ เช่น
Cfx Account ถูกยึด
txAdmin Account ถูกยึด
Admin Account ถูกขโมย
Network Event ถูก Exploit
Resource มี Backdoor
Database Credential หลุด
VPS/RDP/SSH ถูกยึด
API Token หลุด
Server ถูก DDoS
Admin ใช้สิทธิ์ในทางผิด
แต่ละเหตุการณ์ต้องใช้วิธีป้องกันต่างกัน
② อย่าคิดว่าติด Anti-cheat แล้ว Server ปลอดภัย
Anti-cheat เป็นเพียง Security Layer หนึ่ง
มันไม่ได้แทน
Account Security
Event Validation
Firewall
ACE Permissions
Secure Password
Database Security
Backup
Server Security ต้องเป็น Defense in Depth
③ ป้องกันบัญชี Cfx เป็นอันดับแรก
บัญชี Cfx มีความสำคัญกับระบบ FiveM หลายส่วน
หากบัญชี Owner ถูกยึด ผลกระทบอาจมากกว่าการที่ผู้เล่นทั่วไป Cheat ใน Server
จึงต้องรักษาบัญชีนี้เหมือนบัญชีสำคัญทางธุรกิจ
④ เปิด Two-Factor Authentication
Cfx รองรับ Two-Factor Authentication หรือ 2FA
เมื่อเปิดแล้ว การ Login ต้องใช้
Password
+
รหัสยืนยันแบบมีเวลาจำกัด
ช่วยลดความเสี่ยงเมื่อ Password หลุด
⑤ Cfx รองรับ 2FA แบบใด?
Cfx Support ระบุว่าสามารถใช้
Token-based Authenticator
Physical Security Key
Backup Codes
ตัวอย่าง Authenticator ได้แก่แอปประเภท TOTP
⑥ Security Key ใช้ได้ไหม?
ได้
Cfx Support ระบุว่าสามารถเพิ่ม Physical Security Key เช่นอุปกรณ์ในกลุ่ม YubiKey ได้
สำหรับบัญชี Owner ที่สำคัญมาก Hardware Security Key เป็นตัวเลือกที่ควรพิจารณา
⑦ Backup Codes สำคัญมาก
หลังเปิด 2FA ควรสร้าง Backup Codes
และเก็บไว้ในสถานที่ปลอดภัย
อย่าเก็บ
Password
+
2FA Backup Codes
ไว้ในไฟล์เดียวกันบน Desktop
ถ้าเครื่องถูกยึด ผู้โจมตีจะได้ทั้งสองอย่าง
⑧ Backup Codes ใช้ซ้ำได้หรือไม่?
Cfx ระบุว่า Backup Code ที่ใช้ Recovery แล้วจะไม่สามารถใช้ซ้ำได้
ดังนั้นควรจัดการ Code อย่างเป็นระบบและเก็บชุดปัจจุบันให้ปลอดภัย
⑨ Password ของ Cfx ต้องไม่ซ้ำกับที่อื่น
อย่าใช้ Password เดียวกันกับ
Discord
Email
VPS
Database
txAdmin
Hosting Panel
หากบริการหนึ่งรั่ว ผู้โจมตีอาจนำ Password ไปลองกับบริการอื่น
เรียกว่า Credential Stuffing
⑩ Email Account ก็ต้องเปิด 2FA
การป้องกัน Cfx Account แต่ปล่อย Email ไม่มี 2FA เป็นจุดอ่อน
เพราะ Email มักใช้
Login Verification
Password Reset
Security Notification
ดังนั้น Owner Email ต้องได้รับการป้องกันในระดับเดียวกัน
⑪ Cfx ตรวจ Device/Location ใหม่หรือไม่?
Cfx มีระบบที่อาจขอ Verification เพิ่มเมื่อ Login จาก Device หรือ Location ที่ไม่คุ้นเคย
ถ้าได้รับ Email Login ที่ไม่ได้ทำเอง
ให้ถือเป็น Security Warning
และตรวจบัญชีทันที
⑫ อย่า Approve Login ที่ไม่รู้จัก
ถ้ามีคำขอ Login/Authorize ที่คุณไม่ได้เริ่มเอง
อย่ากด Allow
อาจเป็น
Phishing
Session Attack
ผู้โจมตีที่มี Password แล้ว
ตรวจ Source ก่อนเสมอ
⑬ ป้องกัน txAdmin ต่อจาก Cfx Account
txAdmin เป็น Web Administration Panel ของ FXServer
สามารถทำสิ่งสำคัญ เช่น
Start Server
Stop Server
Restart Server
Restart Resources
Execute Console Commands
Edit
server.cfgBan/Kick Players
จัดการ Admin
ดังนั้นการยึด txAdmin อาจส่งผลร้ายแรงมาก
⑭ txAdmin มีระบบ Login แบบใด?
เอกสาร Cfx.re ระบุว่า txAdmin รองรับ
Password Login
CitizenFX/Cfx Login
และมีระบบ
Admin Permissions
Action Logging
Brute-force Protection
แต่ Server Owner ยังต้องตั้ง Permission ให้ถูกต้อง
⑮ txAdmin Default Port คืออะไร?
ค่าเริ่มต้นของ txAdmin คือ
40120/TCP
และ Interface Default ปัจจุบันคือ
0.0.0.0
ดังนั้นต้องตรวจ Firewall และ Network Exposure ของเครื่องจริงด้วย
⑯ ต้องเปิด txAdmin Port ให้ทั้ง Internet ไหม?
หาก Infrastructure อนุญาต ควรจำกัด Administrative Surface ให้แคบที่สุด
ตัวอย่างแนวคิด
Internet
↓
Firewall
↓
อนุญาตเฉพาะแหล่งที่ต้องใช้
↓
txAdmin
ยิ่ง Admin Panel เปิดกว้าง Attack Surface ยิ่งมาก
⑰ ถ้าต้อง Admin จากหลายที่ทำอย่างไร?
ใช้ระบบ Remote Access ที่ทีมดูแลได้อย่างปลอดภัย
และควรมี
Authentication แข็งแรง
Encryption
Access Control
Logs
อย่าปิด Security ของ Firewall เพียงเพราะต้องการความสะดวก
⑱ txAdmin มี Brute-force Protection แล้วต้องใช้ Password ดีไหม?
ต้อง
Brute-force Protection ช่วยลดการเดารหัส
แต่ไม่ป้องกันกรณี
Password รั่ว
Phishing
Password Reuse
Malware
จึงยังต้องใช้ Unique Strong Password
⑲ อย่าแชร์บัญชี Admin
ไม่ควรมี Account เช่น
username: admin
password: xxxx
แล้วให้ทีม 10 คนใช้ร่วมกัน
ควรให้แต่ละคนมี Account ของตัวเอง
เพื่อให้
ถอนสิทธิ์เป็นรายคน
ดู Log ได้
รู้ว่าใครทำ Action
⑳ ใช้ Least Privilege กับ txAdmin
txAdmin มี Permission System ละเอียด
ไม่จำเป็นต้องให้ Admin ทุกคน
all_permissions
ถ้าหน้าที่ของเขาคือเพียง
Warn
Kick
Ban
ให้เฉพาะ Permission เหล่านั้น
㉑ all_permissions คืออะไร?
txAdmin ระบุว่า
all_permissions
เป็น Root Permission ที่สามารถทำทุก Action
ควรจำกัดให้ Owner หรือบุคคลจำนวนน้อยที่สุด
㉒ manage.admins สำคัญแค่ไหน?
Permission
manage.admins
อนุญาตให้สร้าง แก้ไข และลบ Admin Accounts
นี่เป็น Permission ที่อันตรายมากหากบัญชีถูกยึด
ควรให้เฉพาะผู้ที่ต้องดูแล Admin จริง ๆ
㉓ console.write ก็เป็น Permission สำคัญ
Permission
console.write
อนุญาตเขียน Console Commands
ผู้ใช้ที่มีสิทธิ์นี้อาจสามารถทำ Action ระดับ Server สูงมากได้
อย่าให้ Moderator ทั่วไปโดยไม่จำเป็น
㉔ server.cfg.editor ต้องจำกัด
Permission นี้อนุญาตอ่าน/เขียน server.cfg
Config อาจมี
Server Settings
Resource Config
Security Settings
Sensitive Values บางอย่าง
ดังนั้นไม่ควรให้ Admin ทุกคนเข้าถึง
㉕ control.server ต้องให้ใครบ้าง?
Permission นี้เกี่ยวข้องกับ
Start
Stop
Restart Server
Support Staff ที่ทำเพียง Ticket หรือดูแลผู้เล่นไม่จำเป็นต้องมีสิทธิ์นี้เสมอไป
㉖ commands.resources ก็มีความเสี่ยง
ใช้ Start/Stop Resources
ถ้า Admin Account ถูกยึด ผู้โจมตีอาจปิด
Anti-cheat
Framework Resource
Logging
Security Resource
ได้หากมี Permission มากเกินไป
㉗ แบ่ง Admin Roles ให้ชัด
ตัวอย่าง:
Owner
ทุกสิทธิ์ที่จำเป็น
Developer
Console/Resources ตามงาน
Senior Admin
Ban/Kick/Whitelist
Moderator
Warn/Kick
Support
ดูข้อมูลหรือช่วยผู้เล่นบางส่วน
อย่าใช้ Permission Set เดียวกับทุกคน
㉘ เมื่อ Admin ลาออกต้องทำอะไร?
ทันทีที่คนไม่ต้องใช้สิทธิ์แล้ว
Disable/Delete Admin Access
ลบ ACE
ถอน VPN/SSH/RDP
Rotate Shared Secret ที่เขาเคยเห็น
ตรวจ API Keys ถ้าจำเป็น
อย่าปล่อย Account เก่าค้างไว้
㉙ Admin Account เก่าคือ Attack Surface
Account ที่ไม่มีใครใช้แต่ยังเปิดอยู่เป็นเป้าหมายโดยไม่จำเป็น
ทำ Admin Audit เป็นระยะ
ตรวจว่า
คนนี้ยังทำงานอยู่ไหม?
ยังต้องมี Permission นี้ไหม?
㉚ txAdmin มี Action Logging
Cfx.re ระบุว่า txAdmin มี Action Logging
จึงควรใช้ Log สำหรับตรวจ
ใคร Restart Server
ใคร Ban Player
ใครใช้ Admin Action
มี Action ผิดปกติหรือไม่
Log มีประโยชน์มากหลัง Incident
㉛ Log ต้องถูกตรวจจริง
มี Log แต่ไม่เคยเปิดดูแทบไม่มีประโยชน์
ตรวจอย่างน้อยเมื่อมี
Ban ผิดปกติ
Resource ถูก Stop
Server Restart โดยไม่ทราบสาเหตุ
Permission เปลี่ยน
Admin Account แปลก
㉜ Network Event ยังเป็นช่องโจมตีสำคัญ
แม้ Account Security แข็งแรง Server ก็ยังโดน Exploit ผ่าน Resource ที่เขียนไม่ปลอดภัยได้
Cfx.re เตือนว่า Cheat Client สามารถ Trigger Network Events ได้
จึงต้อง Validate ทุก Event สำคัญฝั่ง Server
㉝ อย่าให้ Client กำหนด Reward
ตัวอย่างที่อันตราย:
RegisterNetEvent('job:finish', function(reward)
AddMoney(source, reward)
end)
ผู้โจมตีสามารถพยายามส่ง Reward เอง
Server ต้องคำนวณ Reward จาก Logic ฝั่ง Server
㉞ Server ต้องตรวจ Position
ถ้า Event ใช้ได้เฉพาะในพื้นที่หนึ่ง
ตรวจ Player Coordinates จาก Server
เช่น
Player ขอขายของ
↓
Server ตรวจตำแหน่ง
↓
อยู่จุดขายจริง
↓
จึงดำเนินการ
ลด Remote Event Abuse
㉟ Server ต้องตรวจ Inventory
อย่าเชื่อ Client ว่า
“ฉันมี Item 50 ชิ้น”
Server ต้องอ่าน Inventory State ที่เป็น Authority ของตัวเอง
แล้วค่อยทำ Transaction
㊱ Server ต้องตรวจ Permission ซ้ำ
Admin Menu ฝั่ง Clientอาจซ่อนจาก Player ธรรมดา
แต่ทุก Admin Event ต้องตรวจ Permission ฝั่ง Serverอีกครั้ง
Client Admin Menu
↓
Server Event
↓
Permission Check
↓
Action
㊲ AddEventHandler กับ RegisterNetEvent ต้องใช้ถูก
Event ที่ไม่จำเป็นต้องข้าม Network ควรใช้ Local Event
อย่าทำทุกอย่างเป็น RegisterNetEvent
เพราะ Network Event เพิ่มสิ่งที่ Client สามารถพยายามเรียกได้
㊳ ใช้ source แทน Player ID จาก Client
ถ้า Event มี Player ผู้เรียกอยู่แล้ว
ใช้
local src = source
แทนการให้ Client ส่ง
myServerId = 123
แล้ว Server เชื่อ
㊴ Rate Limit Event สำคัญ
เช่น
Purchase
Reward
Spawn
Expensive Query
Admin Search
ควรป้องกัน Spam ตาม Use Case
แต่ Rate Limit ต้องใช้ร่วมกับ Validation
㊵ Resource จากแหล่งไม่น่าเชื่อถืออาจเป็น Backdoor
อย่าติดตั้ง Resource เพียงเพราะ
แจกฟรี
มีคนส่ง ZIP มา
เจอใน Discord
ชื่อเหมือน Resource ดัง
ตรวจแหล่งที่มาและ Source ก่อน
㊶ Obfuscated Resource ต้องระวัง
Resource บางตัวถูก Obfuscate อย่างถูกกฎหมายเพื่อป้องกัน Source
แต่ถ้า Resource จากผู้พัฒนาไม่รู้จักและไม่สามารถตรวจ Behavior ได้เลย
ถือเป็น Supply-chain Risk
ใช้ Vendor ที่เชื่อถือได้
㊷ Binary แปลก ๆ ต้องระวัง
ถ้า Package มี
.exe.dllNative Module
Installer
ที่ไม่ได้อธิบายว่าจำเป็นทำไม
อย่ารันบน Production ทันที
ตรวจ Vendor และ Function ก่อน
㊸ อย่า Disable Antivirus/EDR เพื่อติดตั้ง Script แบบสุ่ม
ถ้า Resource บอกให้
“ปิด Antivirus ก่อน”
โดยไม่มีเหตุผลทางเทคนิคที่ตรวจสอบได้
ควรหยุดและตรวจสอบ Source
Security Software ไม่ควรถูกปิดเพื่อความสะดวกในการรันไฟล์ไม่น่าเชื่อถือ
㊹ Secrets ต้องอยู่ Server-side
ห้ามใส่
API Key
Database Password
Discord Bot Token
Private License Secret
ใน
client.lua
NUI JavaScript
HTML
เพราะไฟล์ Client ถูกส่งไปเครื่องผู้เล่น
㊺ Public Git ต้องไม่มี Secrets
ก่อน Push Repository ให้ตรวจ
server.cfg
.env
config.lua
database URL
webhook URLs
API tokens
private keys
ใช้ Secret Management ตาม Infrastructure ที่เหมาะสม
㊻ ถ้า Token หลุดต้อง Rotate
อย่าคิดว่า
“ลบ Git Commit แล้วปลอดภัย”
Secret ที่เคย Public ต้องถือว่า Compromised
ให้
Revoke เดิม
↓
สร้างใหม่
↓
Update Server
㊼ Database Password ต้องแยกจาก Root
สร้าง Database Account สำหรับ Application โดยเฉพาะ
อย่าใช้ DBA/Root Account เป็น Connection String ของ Resource หากไม่จำเป็น
ให้ Permission เท่าที่ Application ต้องใช้
㊽ Database Port ไม่ควรเปิดกว้าง
ถ้า Database ใช้เฉพาะ Game Server
Firewall ควรอนุญาต Connection จาก Source ที่จำเป็น
ไม่ใช่
0.0.0.0/0
→ Database
โดยไม่มีเหตุผล
㊾ RDP ต้องป้องกัน
สำหรับ Windows Server ให้รักษา Remote Desktop อย่างจริงจัง
เช่น
Password แข็งแรง
จำกัด Source IP/VPN เมื่อทำได้
Update Windows
ไม่แชร์ Administrator Account
ปิด Account ที่ไม่ใช้
เพราะถ้า OS ถูกยึด FiveM Security Layer ภายในก็แทบไม่มีความหมาย
㊿ SSH ก็เช่นเดียวกัน
สำหรับ Linux
ควรใช้ Configuration ที่ปลอดภัย เช่น
Unique Accounts
Strong Authentication
จำกัดสิทธิ์
ปิด Account ไม่ใช้
Patch OS
แนวคิดคือไม่เปิด Remote Administrative Surface เกินความจำเป็น
51. อย่าให้ Developer ทุกคนเป็น OS Administrator
Developer ที่ต้อง Upload Resource ไม่จำเป็นต้องมี Full Root/Administrator เสมอไป
แบ่งสิทธิ์ตามงาน
ช่วยลดผลกระทบทั้งจาก
Account ถูกยึด
Human Error
52. FTP แบบไม่ปลอดภัยควรหลีกเลี่ยง
หากต้องส่งไฟล์ไป Server ใช้ Protocol/Tool ที่มี Encryption และ Authentication เหมาะสม
อย่าส่ง Credentials/Source ผ่าน Connection ที่ไม่ป้องกันโดยไม่มีเหตุผล
53. Firewall เปิดเฉพาะ Port ที่จำเป็น
รายการ Port ขึ้นกับ Architecture จริง
เช่น
FiveM Game Port
txAdmin
SSH/RDP
Database
Monitoring
แต่ไม่ควรเปิดทุก Port จาก Internet เพื่อแก้ปัญหา Connection
54. หลัก Default Deny มีประโยชน์
แนวคิด:
Block
↓
Allow เฉพาะสิ่งที่จำเป็น
ดีกว่าเปิดทุกอย่างแล้วค่อยหวังว่า Application จะปลอดภัยเอง
55. txAdmin ไม่จำเป็นต้องเข้าถึงจากทุกประเทศเสมอไป
หากทีม Admin มี Network Pattern ชัดเจน สามารถใช้ Infrastructure Controls ลด Exposure ได้
แต่ต้องออกแบบไม่ให้ Owner Lock ตัวเองออกจากระบบ
มี Recovery Plan เสมอ
56. DDoS ต่างจาก Account Hack
DDoS มีเป้าหมายทำให้ Network/Service ใช้งานไม่ได้
ไม่ได้หมายความว่าผู้โจมตีได้ Password หรือ Control Server
การป้องกันต้องพึ่ง
Hosting Network
DDoS Mitigation
Firewall/Filtering
ตามขนาดการโจมตี
57. อย่าบอกว่าโดน Hack เพียงเพราะ Server เข้าไม่ได้
Server Offline อาจเกิดจาก
DDoS
Crash
Database Down
Resource Error
Hosting Outage
Firewall Config
ต้อง Incident Triage ก่อน
58. Backup เป็น Security Layer สำคัญ
ถ้าเกิด
Database เสีย
Resource ถูกแก้
Admin ลบข้อมูล
Server ถูกบุกรุก
Backup ช่วย Recovery
ควรสำรอง
Database
Resources
server.cfgtxData ที่จำเป็น
Configuration สำคัญ
59. Backup ต้องแยกจากเครื่อง Production
ถ้า Backup อยู่บน Disk เดียวกับ Server
และเครื่องถูกลบ/เข้ารหัสทั้งหมด
Backup อาจหายไปด้วย
อย่างน้อยควรมีสำเนาแยกตามระดับความสำคัญของ Server
60. ต้องทดสอบ Restore
Backup ที่ไม่เคย Restore ยังไม่ควรถูกเชื่อ 100%
ทำ Test เช่น
Backup
↓
Restore Staging
↓
Start Server
↓
ตรวจ Characters
↓
ตรวจ Inventory
↓
ตรวจ Vehicles
61. Update FXServer สำคัญ
ควรใช้ Build ที่ยังได้รับการสนับสนุน
Build เก่ามากอาจพลาด
Security Fixes
Stability Fixes
Platform Improvements
แต่ต้อง Test ก่อน Update Production
62. Resource Dependencies ก็ต้อง Update
เช่น
Framework
Database Library
Admin Resource
Web Backend
Anti-cheat
ไม่ควรปล่อย Dependency ที่เลิกดูแลหลายปีโดยไม่ประเมิน Risk
63. Update ไม่ควรทำ Blindly
ใช้
Backup
↓
Staging
↓
Update
↓
Security Test
↓
Gameplay Test
↓
Production
เพราะ Update อาจสร้าง Breaking Change เช่นกัน
64. Admin PC ต้องปลอดภัยด้วย
Server Security อาจดีมาก แต่ถ้าเครื่อง Owner มี Malware
Credential อาจถูกขโมยจาก
Browser
Password Files
SSH Keys
Session Cookies
Admin Device จึงเป็นส่วนหนึ่งของ Security Boundary
65. อย่าติดโปรแกรม Crack บนเครื่อง Admin
เครื่องที่ใช้จัดการ Production Server ไม่ควรเป็นเครื่องทดลอง
Cracked Software
Unknown Cheat
Unknown Executables
Suspicious Browser Extensions
ลด Attack Surface ให้มากที่สุด
66. Browser Extension ก็มีความเสี่ยง
Extension สามารถมี Permission ต่อ Browser Data
บัญชีที่ใช้จัดการ
Hosting
Cfx
txAdmin
Git
ควรอยู่บน Browser/Profile ที่สะอาดและควบคุมได้
67. Password Manager ช่วยได้
ใช้ Password Manager ที่เชื่อถือได้เพื่อสร้าง
Long Passwords
Unique Passwords
ลดปัญหาการใช้รหัสเดียวทุกบริการ
และลดการเก็บ Password ใน .txt
68. Discord Admin Account ต้องป้องกันด้วย
หลาย Community ใช้ Discord สำหรับ
Staff
Bots
Webhooks
Support
ถ้า Discord Admin ถูกยึด อาจใช้ Social Engineering หลอกทีม Server ต่อได้
เปิด 2FA และจำกัด Role เช่นเดียวกัน
69. Webhook ถือเป็น Secret หรือไม่?
บาง Webhook สามารถถูก Abuse เพื่อส่ง Spam หรือปลอม Log
จึงไม่ควร Publish โดยไม่มีเหตุผล
หากหลุดให้ Rotate/Delete Webhook และสร้างใหม่
70. อย่าฝัง Bot Token ใน Client
Bot Token ถือเป็น Credential สำคัญ
ต้องอยู่ Server/Backend ที่ผู้เล่นไม่สามารถ Download Source ไปดูได้
71. ตรวจ Admin Logs เมื่อมีเหตุผิดปกติ
หากพบว่า Server มี
Ban จำนวนมาก
Resource ถูก Stop
Config เปลี่ยน
Server Restart เอง
ให้ตรวจ
txAdmin Action Logs
OS Login Logs
Hosting Panel Logs
Git/Deployment History
Database Logs
ตาม Infrastructure
72. ถ้าสงสัย Admin Account ถูกยึดต้องทำอะไร?
ลำดับแรก:
Disable Account ต้องสงสัย
เปลี่ยน/Rotate Credential
Revoke Sessions เมื่อระบบรองรับ
ตรวจ Permission Changes
ตรวจ Logs
ตรวจ Resource/Config
ตรวจ Database
ประเมินว่าต้อง Restore หรือไม่
อย่าปล่อย Account ใช้งานต่อระหว่าง Investigation
73. ถ้า Cfx Account ถูกสงสัยว่าหลุด
ให้
เปลี่ยน Password
ตรวจ Email
เปิด/ตรวจ 2FA
Rotate Backup Codes หากจำเป็น
ตรวจ Login/Authorization ที่ผิดปกติ
ติดต่อ Cfx Support เมื่อไม่สามารถกู้บัญชีได้
Account Owner ต้องได้รับ Priority สูงสุด
74. ถ้าพบ Resource แปลกใน Server
อย่าเพียง Delete แล้วเปิด Serverต่อทันที
ตรวจ
มาจากไหน
ใคร Deploy
ถูก Start เมื่อไร
มีการแก้ Config หรือไม่
มี Credential หลุดหรือไม่
เพราะ Resource แปลกอาจเป็นเพียง Indicator ของการเข้าถึงที่ลึกกว่านั้น
75. ถ้า Database ถูกแก้ผิดปกติ
ให้เก็บ Evidence ก่อนถ้าเป็นไปได้
จากนั้นตรวจ
Database Accounts
Source IP
Application Logs
Admin Actions
Recent Resource Changes
แล้ว Rotate Database Credentials
76. อย่าแก้ Incident ด้วยการเปลี่ยน Password ตัวเดียว
ถ้า Server ถูกยึดจริงต้องคิดว่า Credential อื่นอาจหลุดด้วย
ตรวจทั้ง
Cfx
Email
txAdmin
Hosting
RDP/SSH
Database
Git
API Tokens
Discord
ตามระดับการเข้าถึงที่ผู้โจมตีอาจมี
77. Incident Response Plan ควรเตรียมก่อนโดน
เขียนไว้เลยว่า
ใครมีอำนาจปิด Server?
Backup อยู่ไหน?
ใคร Rotate Credentials?
ติดต่อ Hosting อย่างไร?
ใครตรวจ Logs?
วิธี Restore คืออะไร?
เวลาเกิด Incident จะไม่ต้องตัดสินใจทุกอย่างตอนฉุกเฉิน
78. เก็บรายชื่อ Admin Access
ทำ Inventory เช่น
| บุคคล | Cfx/txAdmin | VPS | DB | Git | ระดับ |
|---|---|---|---|---|---|
| Owner | ✅ | ✅ | ✅ | ✅ | สูงสุด |
| Dev A | จำกัด | ✅ | ❌ | ✅ | Developer |
| Admin B | ✅ จำกัด | ❌ | ❌ | ❌ | Moderator |
ช่วยเห็นสิทธิ์ที่มากเกินไป
79. Review Permissions เป็นระยะ
ทุกครั้งที่
Staff เปลี่ยน
Developer ใหม่เข้า
Project จบ
Vendor เปลี่ยน
ควรตรวจ Access ใหม่
Permission ที่ถูกต้องเมื่อ 6 เดือนก่อนอาจไม่จำเป็นแล้ว
80. Security Checklist สำหรับ txAdmin
Owner เปิด 2FA บัญชี Cfx
ใช้ Password Unique
Admin แยก Account
จำกัด
all_permissionsจำกัด
manage.adminsจำกัด
console.writeจำกัด
server.cfg.editorจำกัด
control.serverตรวจ Action Logs
ลบ Staff เก่า
Firewall Port ตามความจำเป็น
81. Security Checklist สำหรับ Scripts
Validate Client Input
Server คำนวณ Reward
Server ตรวจ Inventory
Server ตรวจ Position
Server ตรวจ Permission
Rate Limit Event สำคัญ
Local Event ไม่เปิด Network โดยไม่จำเป็น
ไม่มี Secret ฝั่ง Client
Audit Third-party Resources
82. Security Checklist สำหรับ Infrastructure
OS Update
Firewall
จำกัด RDP/SSH
Database ไม่ Public เกินจำเป็น
Unique Accounts
Unique Passwords
Backups แยกเครื่อง
Monitoring
DDoS Protection
Staging Environment
83. Security Checklist สำหรับ Owner
Cfx 2FA
Email 2FA
Backup Codes
Password Manager
Admin Device สะอาด
ไม่ใช้ Software Crack
ตรวจ Login Alerts
Rotate Secrets เมื่อหลุด
มี Incident Plan
84. สิ่งที่ไม่ควรทำเด็ดขาด
หลีกเลี่ยง
แชร์ Owner Account
ปิด 2FA เพื่อความสะดวก
ใช้ Password เดียวทุกระบบ
ให้ Admin ทุกคน Root
เปิด Database ให้ทั้ง Internet
ฝัง API Key ใน Client
โหลด Resource จากแหล่งไม่รู้จัก
Ignore Admin Logs
Backup ไว้เครื่องเดียว
Restart แล้วคิดว่า Incident จบ
ลบ Evidence ก่อนตรวจ
ใช้ Production เป็นเครื่องทดลอง Script
Security ที่ดีมาจากการลดทั้งโอกาสโจมตีและขนาดความเสียหายเมื่อบาง Layer ถูกเจาะ
85. คำถามที่พบบ่อย
ป้องกัน FiveM Server โดนแฮกอย่างไร?
ป้องกันหลาย Layer ได้แก่ Account 2FA, txAdmin Permissions, Secure Events, Firewall, Database Security, Resource Audit และ Backup
บัญชี Cfx เปิด 2FA ได้ไหม?
ได้ Cfx รองรับ Authenticator, Security Key และ Backup Codes
txAdmin มี Brute-force Protection ไหม?
มีตามเอกสาร Cfx.re แต่ยังต้องใช้ Password แข็งแรงและ Permission ที่เหมาะสม
Admin ทุกคนควรมี all_permissions ไหม?
ไม่ ควรใช้ Least Privilege
Permission ไหนใน txAdmin อันตรายสูง?
เช่น all_permissions, manage.admins, console.write, control.server และ server.cfg.editor
Server Event ต้อง Validate ไหมถ้ามี Anti-cheat?
ต้อง Cfx.re แนะนำให้ตรวจ Network Events ฝั่ง Serverเสมอ
Database Password ใส่ใน client.lua ได้ไหม?
ไม่ได้
txAdmin Port คืออะไร?
ค่า Default คือ TCP 40120
Database เปิด Public Internet ได้ไหม?
ควรจำกัด Source ให้เฉพาะที่จำเป็นเมื่อ Infrastructure รองรับ
ถ้าสงสัย Admin ถูกยึดควรทำอะไรอันดับแรก?
Disable Access, Rotate Credentials และตรวจ Logs/Permission Changesทันที
86. สรุปวิธีป้องกัน FiveM Server โดนแฮกและป้องกันบัญชี Admin
การป้องกัน FiveM Server ที่มีประสิทธิภาพต้องเริ่มจาก บัญชี Owner และ Administrative Access ก่อน เพราะ Account ที่มีสิทธิ์สูงสามารถสร้างความเสียหายได้มากกว่า Exploit ทั่วไปหลายประเภท
Cfx รองรับ 2FA สำหรับบัญชี Cfx โดยสามารถใช้ Token-based Authenticator, Physical Security Key และ Backup Codes
ดังนั้น Owner ควรใช้
Unique Password
+
2FA
+
Backup Codes แยกเก็บ
จากนั้นป้องกัน txAdmin
txAdmin มี Permission System ละเอียด ตั้งแต่
all_permissions
manage.admins
console.write
control.server
commands.resources
server.cfg.editor
ไปจนถึง Permission ระดับ Warn/Kick/Ban
อย่าให้ Admin ทุกคนเป็น Root
ใช้หลัก Least Privilege และสร้าง Account แยกต่อ Staff เพื่อให้สามารถ Audit Action ได้
ต่อมาคือ Scripts
Resource ที่รับ Network Event ต้องคิดเสมอว่า Client สามารถพยายามเรียก Event เองได้
Server จึงต้องตรวจ
Money + Inventory + Position + Player State + Permission + Rate
จาก Server-side Data และต้องเป็นผู้คำนวณ Reward เอง
Infrastructure ก็สำคัญไม่แพ้กัน
จำกัด txAdmin
จำกัด RDP/SSH
จำกัด Database
เปิด Firewall เฉพาะ Port จำเป็น
เก็บ Secrets Server-side
ไม่ติด Resource ไม่น่าเชื่อถือ
Update Platform
มี DDoS Protection ตามระดับความเสี่ยง
สุดท้ายต้องมี Backup และ Incident Response
ถ้าพบ Account หรือ Server ถูกยึด ให้คิดเป็นกระบวนการ
Contain
↓
Disable Access
↓
Rotate Credentials
↓
Preserve / Review Logs
↓
ตรวจ Config / Resources / DB
↓
Recover
↓
Monitor
ไม่ใช่เปลี่ยน Password หนึ่งตัวแล้วเปิด Server ต่อทันที
แนวทางที่ comsiam แนะนำคือแบ่ง Security เป็น 5 ชั้น:
Account Security
→ 2FA, Password, Backup Codes
Admin Security
→ txAdmin Permissions, ACE, Logs
Application Security
→ Secure Events, Server Authority
Infrastructure Security
→ Firewall, OS, Database, Remote Access
Recovery Security
→ Backup, Restore Test, Incident Response
จำสั้น ๆ:
Cfx Owner → เปิด 2FA
Email → เปิด 2FA
Admin → Account แยก
txAdmin → Least Privilege
all_permissions → ให้น้อยคนที่สุด
Network Events → Never Trust Client
Secrets → Server-side เท่านั้น
Database → จำกัด Account และ Network
Resources → ใช้แหล่งเชื่อถือได้
Firewall → เปิดเท่าที่จำเป็น
Logs → ต้องตรวจได้ว่าใครทำอะไร
Backup → ต้อง Restore ได้
Incident → Rotate Credentials ทั้งชุดที่อาจได้รับผลกระทบ
FiveM Server ที่ปลอดภัยจึงไม่ใช่ Server ที่เชื่อว่าไม่มีใครเจาะได้ แต่คือ Server ที่ ทำให้การเจาะยากขึ้น จำกัดความเสียหายเมื่อบัญชีหนึ่งถูกยึด ตรวจพบความผิดปกติได้ และกู้ระบบกลับมาได้โดยไม่สูญเสียข้อมูลทั้งหมด
Comments
Post a Comment