Live data from Hacker News

WordPress theme provider Pipdig using customer sites to DDoS competitors

jemjabella.co.uk

31–40 of 87 posts

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#31

Earlier quoted context omitted.

It sounds like that might have been the place that stole it?

Doesn't matter. A WordPress plugin/theme developer has no business altering the content of sites using their software.

I don't know anything about WordPress, but isn't a plugin supposed to alter the content of the site using their software? If it didn't, why use it?

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#32
post #29

It looks like the company involved is based in the U.K. and also seems likely this software and their usage of it is a violation of the Computer Misuse Act. One of their competitors should consider filing a complaint with the relevant authorities, so this gets formally investigated.

I would be interested to hear from CloudFlare as to whether there is any possibility of confirming that the URL "https://pipdigz.co.uk/p3/id39dqm3c0_license_h.txt" - fetched by the "license check" code - did at some point return the text "https://kotrynabassdesign.com/wp-admin/admin-ajax.php". I suspect this will be difficult, or impossible, to verify (I'm not a security expert) and the "license check" code in and of itself (while extremely fishy) only betrays the potential of a DDoS and is not a smoking gun.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#33

Earlier quoted context omitted.

I'd also like to add that the DDoS functionality isn't what really jumped out at me. It was the ability to reset your site's admin password remotely using a hard-coded password that anyone can read. And then there is also the ability to drop all your tables. When we contacted them before publishing via email, they explained that someone had been pirating their software so this was a countermeasure. (quote is in the W…

> I guess the idea was that they would destroy sites using pirated licenses. Isn't it GPL?

Depends who you ask. Also some sites use a SaaS model with API key for back-end access. They claimed license keys were stolen. “Last year we had some serious problems after someone obtained a huge list of license keys and downloaded all of our products. The keys and files were then distributed on their file sharing site, which has since been taken down (not by us, ironically!). The drop tables function was put in place to try to stop this at the time.”

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#34
post #24

Earlier quoted context omitted.

While I don't disagree that this is horrible, perhaps the $tables array is hardcoded array.

It is not, you can check the post for the full context.

It's pretty much the same as if it was hardcoded, it drops all tables that have a name starting with the WP prefix. It's extremely ugly, but it's not unsafe (if your plan is removing all WP related tables from the DB).

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#35
post #6
post #2

From pipdig https://www.pipdig.co/blog/sad-times/

Pathetic. If I'm reading this correctly, they're essentially admitting to some of the malicious features described by the researcher, but claiming that they were included for support purposes, or as a way of sabotaging sites using pirated versions of their plugin. 1. Including features which can remotely grant unauthorized access or cause damage to a user's web site is inappropriate under any circumstances . Even if…

We're just a poor small company... that is acts maliciously against our competitors using our code we sell to clients who have no idea! we're sorry we got caught and it's hard to explain why this isn't bad.

Oh and they deleted repos apparently, gotta hide the evidence

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#36

Here's a second writeup, which also contains a response from pipdig: https://www.wordfence.com/blog/2019/03/peculiar-php-present-...

Jesus christ, that page is 50% ads for "Wordfence" with a static header and footer.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#40

Earlier quoted context omitted.

Doesn't matter. A WordPress plugin/theme developer has no business altering the content of sites using their software.

I don't know anything about WordPress, but isn't a plugin supposed to alter the content of the site using their software? If it didn't, why use it?

Not changing content linking to a competitor's services into one linking to author of the plugin's without the user's knowledge.
Post reply on HN