How to clean a server of hacked files

If you have gotten hacked recently, there are a few places you should look for files which are malicious.

Since the exploit cannot delete or overwrite files, look mostly for files which have seemingly relivant names but contain malicious content.

  1. Check your lua/autorun and lua/autorun/server files for additions
  2. Search through popular/default addon directories for addons/addonname/lua/autorun
  3. To deem a script malicious, check for the following common commands
    3a) require
    3b) pcall
    3c) file.Read
    3d) for k,v in (player.GetAll()) do
    3e) concommand.Remove
    3f) Any functions with short or non-professiona names
  4. If you think you have a malicious file but are afraid to delete it, simply post the contents in this thread and I will tell you if it is malicious

Happy server hosting,


Excuse me, I would have made this much nicer if I wasn’t posting from an iPhone.

Don’t forget addons/derma/lua/autorun

See 2


Forgot to put http.Get

Yea, saw 2. Some people are literal in their searches though.

Everything you need to fix this is here. Cheers

Thanks. Was that so hard?