FYI admins
cross-posted from: https://quokk.au/c/fediverse/p/1066667/tesseract-dev-injects-malicious-code-into-browser-to-illegally-ddos-the-dbzer0-instance
As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.


I understand how it works.
All I’m saying is the registrar should also be notified otherwise the site can be moved to another hosting platform.
If the registrar can be convinced to take action, at least the domain can’t be used for future attacks.