As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.

  • BluescreenOfDeath@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    3 hours ago

    Basically, yes.

    Tesseract was downloading at runtime an obfuscated blocklist of users and instances. One that the dev didn’t tell anyone about, and didn’t give an option to disable/modify.

    db0 was trying to update Tesseract and was unaware that the whole dbzer0 instance was blocked in this way. And because the Tesseract dev is a spherical bastard, rather than saying “this is blocked”, it said there was an API mismatch, which sent db0 down a troubleshooting rabbit hole that ended with him blowing the whistle on the whole thing.

    And you can see how mature and wise the developer is for how he responded.