Live data from Hacker News

WordPress theme provider Pipdig using customer sites to DDoS competitors

jemjabella.co.uk

41–50 of 87 posts

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#41
> Another one from the @pipdig plugin. If you use one of their themes on @bluehost then they intentionally slow your website down by disabling the BlueHost cache plugin, then they can inject content with the title "Is your host slowing you down?"

https://twitter.com/nickstadb/status/1112479746972151808

pipdig is a goldmine.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#43
And this just illustrates the horror that is the proprietary market place of WordPress plugins. It is annoying because this results in incentives to take away freedom from users and require payment for proprietary code in the guise of a free software project. To expand Word Press functionality beyond the core functions you have to wade through a minefield of freemium plugins that have all been slightly broken to encourage you to shell out money to someone for code you won't have any freedom with and the worst of it possibly demonstrated by code like this. I have built some sites with WordPress but I have always felt stifled by the way the plugins and themes are distributed. On the other hand I understand people like being able to charge money and create businesses from the code they right which can be more challenging if you actually write free as in libre software vs. attempting to extract money from every potential user.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#44

And this just illustrates the horror that is the proprietary market place of WordPress plugins. It is annoying because this results in incentives to take away freedom from users and require payment for proprietary code in the guise of a free software project. To expand Word Press functionality beyond the core functions you have to wade through a minefield of freemium plugins that have all been slightly broken to enco…

For my personal site, I've left WP behind about 3 years ago. I had to go back last month, trying to build something instead of a Wix site for a school, and the experience was terrifying: after adding one of the events plugin, within 5 minutes I started getting spam registration. All plugins have ugly admin interface "extras" and are very pushy to buy them.

The WordPress of 2007, which I loved very much, has nothing to do with this monster of 2019.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#45

Earlier quoted context omitted.

It is not, you can check the post for the full context.

Or, better still, an Archive.org snapshot of the commit that added this very code: https://web.archive.org/web/20190331195338/bitbucket.org/pip... (As a resident geek, I was asked to look into this by a friend)

For good measure, the commit seems to be removed from the original repo.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#46
post #44

And this just illustrates the horror that is the proprietary market place of WordPress plugins. It is annoying because this results in incentives to take away freedom from users and require payment for proprietary code in the guise of a free software project. To expand Word Press functionality beyond the core functions you have to wade through a minefield of freemium plugins that have all been slightly broken to enco…

For my personal site, I've left WP behind about 3 years ago. I had to go back last month, trying to build something instead of a Wix site for a school, and the experience was terrifying: after adding one of the events plugin, within 5 minutes I started getting spam registration. All plugins have ugly admin interface "extras" and are very pushy to buy them. The WordPress of 2007, which I loved very much, has nothing t…

I share a similar sentiment. Since about 2-3 years ago, most WordPress plugins are marketed bloatware that messes up the entire dashboard UI. And don't get me started on plugins that don't let you close their notifications unless you do "some thing".

It really is a shame, because frankly speaking - most of these plugins are utter trash anyway.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#47
Like always, a story has 2 sides. Do read the response on https://www.pipdig.co/blog/sad-times/ carefully too and draw your own conclusions. Having a bit of technical knowledge and understanding what everybody is actually talking about can help with your perspective, else it's hard to come to any well informed conclusion.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#48
post #46
post #44

Earlier quoted context omitted.

For my personal site, I've left WP behind about 3 years ago. I had to go back last month, trying to build something instead of a Wix site for a school, and the experience was terrifying: after adding one of the events plugin, within 5 minutes I started getting spam registration. All plugins have ugly admin interface "extras" and are very pushy to buy them. The WordPress of 2007, which I loved very much, has nothing t…

I share a similar sentiment. Since about 2-3 years ago, most WordPress plugins are marketed bloatware that messes up the entire dashboard UI. And don't get me started on plugins that don't let you close their notifications unless you do "some thing". It really is a shame, because frankly speaking - most of these plugins are utter trash anyway.

I've tried out a massive amount of gutenberg block plugins; whichever added a new line in the admin menu instead of adding it into a submenu of settings, deserves immediate deletion.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#49
post #47

Like always, a story has 2 sides. Do read the response on https://www.pipdig.co/blog/sad-times/ carefully too and draw your own conclusions. Having a bit of technical knowledge and understanding what everybody is actually talking about can help with your perspective, else it's hard to come to any well informed conclusion.

Being able to drop someone else's full site contents is not something anyone should get away with under any circumstance.

The want to prevent pirated theme - reset the theme to twentysexteen; block frontend access; overlay frontend with notification, etc - so many options. Deleting data? That is not one of them.

I won't even get into the deliberate other plugins disabling with comments like "sorry not sorry", including cache plugins to advertise their own hosting.

Conclusion: nasty, lying bag of s*.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#50
post #11

These guys put all this evil into their code (PHP no less so easily readable by anyone) and it took this long for them to get caught? Further, they peddled this into who knows how many themes they sold and never thought they'd get caught?

https://wordpress.org/plugins/

"Extend your WordPress experience with 54,886 plugins."

And those are only the ones on wp.org itself; the "premium" themes are in the tens thousands as well. It's not simple to catch these.

Post reply on HN