As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.
As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.
just because we found two things he did doesn’t mean there aren’t other surprises.
for all we know at this point, he’s implemented a backdoor into instances that use it.
if you’re an instance admin using tesseract and you’re reading this right now, you should probably drop it asap.
Yeah, I could see a credential stealer being smuggled into an alternative frontend…