FYI admins
cross-posted from: https://quokk.au/c/fediverse/p/1066667/tesseract-dev-injects-malicious-code-into-browser-to-illegally-ddos-the-dbzer0-instance
As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.


The domain is registered to SquareSpace: https://who.is/whois/dubvee.org
The IP associated with the domain points to Inmotion: https://who.is/whois-ip/ip-address/107.161.30.39
Looks like both are true, hopefully Inmotion will take appropriate action based on your report. Worthwhile reporting to SquareSpace too so he can’t just rehost an attack elsewhere.
Check startrek.website too. They defederated us immediately after banning someone who claimed to be an alt of Admiral Patrick. If their domain is less protected we might be able to bring him to justice over this.
Registrar and hosting are different things.
Registrar is who you bought and manage the domain name you use on your site through. Hosting is where it lives.
Most domain name registrars do not give a single shit what you do with a domain name, unless they’re somehow on the hook. Hosting on the other hand…
I understand how it works.
All I’m saying is the registrar should also be notified otherwise the site can be moved to another hosting platform.
If the registrar can be convinced to take action, at least the domain can’t be used for future attacks.