As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.

  • pcouy@lemmy.pierre-couy.fr
    link
    fedilink
    English
    arrow-up
    8
    ·
    3 hours ago

    It also made my browser freeze for a moment when I first found and loaded his page before I blocked all JS from his domain. Not stealthy at all… Many nerd (like most of us lemmy users are) will instantly open devtools when a random page that’s supposed to be just text freezes the browser for a second.

    Like, c’mon man, setInterval with even 10 ms of delay would have made the attack both stealthier by not insta-freezing the brower on load, and more efficient by getting way more than 2000 request out of each reader…

    Also, their website seems to be down now :)