Possible security hole with nui_devTools?

obviously but i actually have a lot of cheats blocked so… i’m just asking how can i stop it.

so basicly fivem is giving a thing that help with developers but it’s also a free cheat

It’s not a free cheat since it can’t be abused, I guess we should also ask Google Chrome to remove the F12 option from browsers since it’s a “free cheat”, not to forget asking curl, postman and all other tools to be removed since you can POST and bypass the client javascript

cmd> curl -X POST https://yourvulnerablewebsite.com/makeadmin.php?admin=indra

curl please remove your tool it can be used as hack!

2 Likes

go to google.com
press f12
congrats, you hacked google

sure? check this Bugga pengar med "msrp_slotmachine" med NUI Devtools (FiveM) - YouTube

it can be easy abused so don’t say that it can’t be abused… Bugga pengar med "msrp_slotmachine" med NUI Devtools (FiveM) - YouTube

1 Like

That’s an issue how the resource is coded, if you take that as abuse then every tool on the internet which can potentially be abused should be removed

it can be abused only if some “great dev” wrote some stupid script like this slot machine script

obviously is an abuse xD

you can do this almost in all scripts

and i was asking for a “help” but thanks fivem “community”

Exactly, we are helping you by not giving some half fix which can be abused in two seconds and actually giving you a good solution. It might sound hard but this is really just an issue with your resources and removing any tools to abuse this would not be a solution.

We are not going to spread some fake “fix” which blocks the devtools since that will lead to people going “waaa” when people still bypass it since they think the fixed the issue, the real issue can be fixed by not trusting the client. There are topics about this already see How hackers can exploit your servers and what to do about it which are trying to help the community fix such issues.

3 Likes

then create your own scripts that dont have such stupid security issues
well, i forgot that anyone who uses ESX cannot event create a simple hello world app in lua, sry

bro i don’t have any server i’m actually DEVELOPER in fivem and i’m searching if this forum is not completely useless

Please read my edited reply above, I’ve added sources which can help you fix this issue. Thank you

TheIndra tries to tell you that problems of non-secure scripts are problems of non-secure scripts and thats all
is this that hard to understand?
ffs, just take a look at the script before starting using it. if it has such exploits that the slot machine script from the video, just DO NO USE IT

Bro do you understand that i don’t have a server, i’m just trying to HELP PEOPLE because a lot of people in this community doesn’t know what is nui_devtools OR WHAT you can do with that. And a lot of people doesn’t know JAVASCRIPT and just lua so perfect ahaha i like this n0bs

Then help people by fixing the resources, patch the resources and pull request fixes to them so it’s fixed for everyone and an actual fix is applied. That’s how you can help people and the community.