1199
submitted 1 day ago by Quokka@quokk.au to c/fediverse@lemmy.world

As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.

you are viewing a single comment's thread
view the rest of the comments
[-] GreenKnight23@lemmy.world 2 points 5 hours ago

just because we found two things he did doesn't mean there aren't other surprises.

for all we know at this point, he's implemented a backdoor into instances that use it.

if you're an instance admin using tesseract and you're reading this right now, you should probably drop it asap.

[-] pcouy@lemmy.pierre-couy.fr 2 points 1 hour ago

Yeah, I could see a credential stealer being smuggled into an alternative frontend...

this post was submitted on 27 Jul 2026
1199 points (99.0% liked)

Fediverse

43141 readers
1966 users here now

A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, Mbin, etc).

If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!

Rules

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration)

founded 3 years ago
MODERATORS