Live data from Hacker News

WordPress theme provider Pipdig using customer sites to DDoS competitors

jemjabella.co.uk

51–60 of 87 posts

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#51

And this just illustrates the horror that is the proprietary market place of WordPress plugins. It is annoying because this results in incentives to take away freedom from users and require payment for proprietary code in the guise of a free software project. To expand Word Press functionality beyond the core functions you have to wade through a minefield of freemium plugins that have all been slightly broken to enco…

> And this just illustrates the horror that is the proprietary market place of WordPress plugins.

Same stories emanate from the Google Play marketplace, and to a lesser extent the highly curated Apple app store marketplace. How is WordPress any different?

> you have to wade through a minefield of freemium plugins

Just like every other app store.

> for code you won't have any freedom with

Unlike smartphone apps, or apps for my PC I can and do inspect the source code of any WordPress plugin or theme.

> I have built some sites with WordPress but I have always felt stifled by the way the plugins and themes are distributed

I'd feel the same way about platforms I've only been exposed to a few times as well.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#52
post #29

It looks like the company involved is based in the U.K. and also seems likely this software and their usage of it is a violation of the Computer Misuse Act. One of their competitors should consider filing a complaint with the relevant authorities, so this gets formally investigated.

Yes, absolutely. The responses so far have been too tepid; DDOSing competitors, adding a database-dropping kill switch, disabling other software, and adding an admin login backdoor are all separate criminal offenses. The developer responsible should not just be blacklisted, he should be in prison.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#53

And this just illustrates the horror that is the proprietary market place of WordPress plugins. It is annoying because this results in incentives to take away freedom from users and require payment for proprietary code in the guise of a free software project. To expand Word Press functionality beyond the core functions you have to wade through a minefield of freemium plugins that have all been slightly broken to enco…

You get what you pay for with Wordpress plugins. There are some great free ones that are mainained.

Then you get ones that can't survive minor wordpress upgrades, or are full of security holes.

The worst is when you have a highly motivated person who throws a ton of them together to buid a website, and then it languishes and becomes out of date, and any upgrading you do will start culling plugins from their baby.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#54
post #44

And this just illustrates the horror that is the proprietary market place of WordPress plugins. It is annoying because this results in incentives to take away freedom from users and require payment for proprietary code in the guise of a free software project. To expand Word Press functionality beyond the core functions you have to wade through a minefield of freemium plugins that have all been slightly broken to enco…

For my personal site, I've left WP behind about 3 years ago. I had to go back last month, trying to build something instead of a Wix site for a school, and the experience was terrifying: after adding one of the events plugin, within 5 minutes I started getting spam registration. All plugins have ugly admin interface "extras" and are very pushy to buy them. The WordPress of 2007, which I loved very much, has nothing t…

On the plus side, you can see the code and turn those off. So if you think of the plugins as a starting point it's not so bad.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#55
post #49
post #47

Like always, a story has 2 sides. Do read the response on https://www.pipdig.co/blog/sad-times/ carefully too and draw your own conclusions. Having a bit of technical knowledge and understanding what everybody is actually talking about can help with your perspective, else it's hard to come to any well informed conclusion.

Being able to drop someone else's full site contents is not something anyone should get away with under any circumstance. The want to prevent pirated theme - reset the theme to twentysexteen; block frontend access; overlay frontend with notification, etc - so many options. Deleting data? That is not one of them. I won't even get into the deliberate other plugins disabling with comments like "sorry not sorry", includi…

You clearly didn't read their response on it.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#56
post #47

Like always, a story has 2 sides. Do read the response on https://www.pipdig.co/blog/sad-times/ carefully too and draw your own conclusions. Having a bit of technical knowledge and understanding what everybody is actually talking about can help with your perspective, else it's hard to come to any well informed conclusion.

I've got enough technical knowledge (I was a co-creator of the Tarski WP theme available on WordPress.com for several years) to know that this doesn't have two sides: https://twitter.com/nickstadb/status/1112479746972151808

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#57
What options are left if you need a simple website builder that's not

a) Wordpress, which is a swamp filled with mines in the form of plugins b) Wix, which forces hosting and bad HTML on you

Basically I want a Wordpress-like frontend + the rich template ecosystem and for it to spit out static HTML files.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#58
post #10
post #2

From pipdig https://www.pipdig.co/blog/sad-times/

It sounds like they got a little overaggressive fighting with the company that had hijacked their themes and were selling them last year. They were probably obfuscating those functions to hide them from the people selling their themes. Sounds like they were also disabling this plugin as well. But they definitely went about things the wrong way, including functions like that and obfuscating them is definitely not the…

Saw this on Twitter:

> Phil you need to stop with the lies. Not only do you outright lie about having the ability to kill sites with your plugin, you state that this was implemented in response to a security breach you experienced in July 2018. The code was implemented in November 2017.

https://twitter.com/nickstadb/status/1112444919409446912

Unfortunately, pipdig wiped and recreated the repo an hour ago, so that history is no longer available there at least.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#59
post #29

It looks like the company involved is based in the U.K. and also seems likely this software and their usage of it is a violation of the Computer Misuse Act. One of their competitors should consider filing a complaint with the relevant authorities, so this gets formally investigated.

I would be interested to hear from CloudFlare as to whether there is any possibility of confirming that the URL " https://pipdigz.co.uk/p3/id39dqm3c0_license_h.txt" - fetched by the "license check" code - did at some point return the text " https://kotrynabassdesign.com/wp-admin/admin-ajax.php" . I suspect this will be difficult, or impossible, to verify (I'm not a security expert) and the "license check" code in and…

Hopefully not. Cloudflare has no business in law enforcement or legal investigations. If they are trustworthy, this will not know about the contents of sites in the past.
Post reply on HN