Live data from Hacker News

WordPress theme provider Pipdig using customer sites to DDoS competitors

jemjabella.co.uk

11–20 of 87 posts

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#12
post #10
post #2

From pipdig https://www.pipdig.co/blog/sad-times/

It sounds like they got a little overaggressive fighting with the company that had hijacked their themes and were selling them last year. They were probably obfuscating those functions to hide them from the people selling their themes. Sounds like they were also disabling this plugin as well. But they definitely went about things the wrong way, including functions like that and obfuscating them is definitely not the…

> It sounds like they got a little overaggressive fighting with the company that had hijacked their themes and were selling them last year.

Some of this might be explainable in this fashion, but not all.

https://www.wordfence.com/blog/2019/03/peculiar-php-present-...

> Firstly, the plugin includes a content filter that automatically replaces references to Blogerize, a service which claims to be a beginner’s blogging course, with references to Pipdig’s own services.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#13

Here's a second writeup, which also contains a response from pipdig: https://www.wordfence.com/blog/2019/03/peculiar-php-present-...

Thanks. My crew put this write-up together. We're here if you have any questions. Jem and us published almost at the same time although I think we beat her by an hour or so. We're in contact. Funny coincidence we were working on the same story at the same time.

This has blown up on Twitter. Our team has stayed out of the online debate mostly other than answering questions. We're trying to just focus on the data here.

They took their public repo offline, but we mirrored it before they did that. It contradicts some claims they're making re timing. We're publishing a timeline tomorrow and are recording our weekly podcast tonight instead of tomorrow as per normal because of this insanity. We'll break it down on the show.

I guess what really jumps out at me here is how they're trying to gaslight the thing.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#14

Here's a second writeup, which also contains a response from pipdig: https://www.wordfence.com/blog/2019/03/peculiar-php-present-...

Thanks. My crew put this write-up together. We're here if you have any questions. Jem and us published almost at the same time although I think we beat her by an hour or so. We're in contact. Funny coincidence we were working on the same story at the same time. This has blown up on Twitter. Our team has stayed out of the online debate mostly other than answering questions. We're trying to just focus on the data here.…

I'd also like to add that the DDoS functionality isn't what really jumped out at me. It was the ability to reset your site's admin password remotely using a hard-coded password that anyone can read. And then there is also the ability to drop all your tables.

When we contacted them before publishing via email, they explained that someone had been pirating their software so this was a countermeasure. (quote is in the Wordfence post above) I guess the idea was that they would destroy sites using pirated licenses. Then they backpedalled that later on after this went viral.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#15
post #3
post #2

From pipdig https://www.pipdig.co/blog/sad-times/

A pretty sad attempt at turning themselves into the victims, by my reading.

They seem to be getting some support on Twitter: https://twitter.com/pipdig/status/1112310062956064768

It's easy enough these days to blame things on journalists and "fake news".

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#19
post #16

Did they seriously have the audacity to deny all this after all those code examples were shown? Edit: Wow, peoples' responses on Twitter are even more delusional. Wtf?

> Wow, peoples' responses on Twitter are even more delusional. Wtf?

I find this so baffling. It's like being shown the bodies of a serial killer's victims, and publicly stating "oh, but he never murdered me, so why are you all complaining?"

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#20
post #10

Earlier quoted context omitted.

It sounds like they got a little overaggressive fighting with the company that had hijacked their themes and were selling them last year. They were probably obfuscating those functions to hide them from the people selling their themes. Sounds like they were also disabling this plugin as well. But they definitely went about things the wrong way, including functions like that and obfuscating them is definitely not the…

> It sounds like they got a little overaggressive fighting with the company that had hijacked their themes and were selling them last year. Some of this might be explainable in this fashion, but not all. https://www.wordfence.com/blog/2019/03/peculiar-php-present-... > Firstly, the plugin includes a content filter that automatically replaces references to Blogerize, a service which claims to be a beginner’s blogging…

It sounds like that might have been the place that stole it?
Post reply on HN