▲ 1372 ▼ Tesseract dev injects malicious code into browser to illegally DDOS the dbzer0 instance (thelemmy.club) submitted 1 month ago by Quokka@quokk.au to c/fediverse@lemmy.world 487 comments fedilink hide all child comments As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.
[–] GreenKnight23@lemmy.world 4 points 1 month ago (1 child) just because we found two things he did doesn't mean there aren't other surprises. for all we know at this point, he's implemented a backdoor into instances that use it. if you're an instance admin using tesseract and you're reading this right now, you should probably drop it asap. permalink fedilink source parent hideshow 2 child comments replies: [–] pcouy@lemmy.pierre-couy.fr 2 points 1 month ago Yeah, I could see a credential stealer being smuggled into an alternative frontend... permalink fedilink source parent
[–] pcouy@lemmy.pierre-couy.fr 2 points 1 month ago Yeah, I could see a credential stealer being smuggled into an alternative frontend... permalink fedilink source parent