FYI admins
cross-posted from: https://quokk.au/c/fediverse/p/1066667/tesseract-dev-injects-malicious-code-into-browser-to-illegally-ddos-the-dbzer0-instance
As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.


For this kind of stuff you can easily ask an llm and it will give you a pretty decent rundown of mitigation tactics
Just thought it would be the cherry on top if this final outburst was automatically blocked by a mitigation measure that was already there.