Live data from Hacker News

WordPress theme provider Pipdig using customer sites to DDoS competitors

jemjabella.co.uk

61–70 of 87 posts

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#61
post #41

> Another one from the @pipdig plugin. If you use one of their themes on @bluehost then they intentionally slow your website down by disabling the BlueHost cache plugin, then they can inject content with the title "Is your host slowing you down?" https://twitter.com/nickstadb/status/1112479746972151808 pipdig is a goldmine.

On a tangent, let's talk BlueHost.

While the call to host switch is malicious, almost every developer in WordPress world will agree BlueHost, and their parent company with all their 50+ hosting companies, are utter garbage. The only reason they exist is because they have hired an army of bloggers and pay them affiliate income of $65 / signup.

As far as disabling Endurance Cache goes, it is completely legitimate. It's a plugin forced upon BlueHost users, without being told so, and is a "must-use" plugin that most users will never check (and can't be completely disabled from WordPress admin).

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#62
post #47

Like always, a story has 2 sides. Do read the response on https://www.pipdig.co/blog/sad-times/ carefully too and draw your own conclusions. Having a bit of technical knowledge and understanding what everybody is actually talking about can help with your perspective, else it's hard to come to any well informed conclusion.

Their reply is an exercise in basic obfuscation and dissembling. Instead of explaining the specific 'features' of their code, their response is in a question-and-answer format. They chose the questions, and they are sufficiently broad and otherwise carefully chosen so that they can avoid being specific about what, exactly, they were up to. Some obvious follow-up questions to their initial answers are conspicuously absent.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#63
post #61
post #41

> Another one from the @pipdig plugin. If you use one of their themes on @bluehost then they intentionally slow your website down by disabling the BlueHost cache plugin, then they can inject content with the title "Is your host slowing you down?" https://twitter.com/nickstadb/status/1112479746972151808 pipdig is a goldmine.

On a tangent, let's talk BlueHost. While the call to host switch is malicious, almost every developer in WordPress world will agree BlueHost, and their parent company with all their 50+ hosting companies, are utter garbage. The only reason they exist is because they have hired an army of bloggers and pay them affiliate income of $65 / signup. As far as disabling Endurance Cache goes, it is completely legitimate. It's…

Wait... so if I write a WP plugin, I'm entitled to disable other plugins I don't like when people install mine? Of course not. That endurance cache is not the only one, there's a list of "plugins we disagree with" which are disabled:

https://www.wordfence.com/blog/2019/03/peculiar-php-present-...

As for hosting providers: GoDaddy, BlueHost, etc - yes, they're all bad. But that doesn't justify moves like these.

Serious question though, on the technical part: WP needs an advanced-cache.php file, which needs to be in wp-content in order for the cache to work; this will list as dropin. Are you sure the endurance cache is MU and not dropin? (Genuine question).

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#64
post #55
post #49

Earlier quoted context omitted.

Being able to drop someone else's full site contents is not something anyone should get away with under any circumstance. The want to prevent pirated theme - reset the theme to twentysexteen; block frontend access; overlay frontend with notification, etc - so many options. Deleting data? That is not one of them. I won't even get into the deliberate other plugins disabling with comments like "sorry not sorry", includi…

You clearly didn't read their response on it.

I did. It's factually inaccurate.

> There was function in an older version of the plugin which could be used to reset a site back to the default settings. This function had no risk of of malicious or unintentional use.

> The portrayal of this feature is not based on reality. There is a function in the plugin which can be used to clear database tables, much like a backup or standard reset plugin. To confirm, we do not have the ability to “kill” a site, nor would we ever, ever want to do that! The function is in place to reset a site back to defaults, however it is only activated after being in touch with the site owner.

It dropped all wordpress tables. This is not a reset. There's also no reason to only have PipDig able to do this via their server, vs. an option in the configuration.

They also don't address the password reset functionality.

At best, these people are incompetent and don't realize the power their code wields. At worst, they're just backpedaling and trying to mitigate damage. (I especially like their attempt to humanize themselves by saying they're just four people who like cat memes.)

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#65
post #35
post #6

Earlier quoted context omitted.

Pathetic. If I'm reading this correctly, they're essentially admitting to some of the malicious features described by the researcher, but claiming that they were included for support purposes, or as a way of sabotaging sites using pirated versions of their plugin. 1. Including features which can remotely grant unauthorized access or cause damage to a user's web site is inappropriate under any circumstances . Even if…

We're just a poor small company... that is acts maliciously against our competitors using our code we sell to clients who have no idea! we're sorry we got caught and it's hard to explain why this isn't bad. Oh and they deleted repos apparently, gotta hide the evidence

Didn't work: https://web.archive.org/web/20190331195338/bitbucket.org/pip...

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#66
post #58
post #10

Earlier quoted context omitted.

It sounds like they got a little overaggressive fighting with the company that had hijacked their themes and were selling them last year. They were probably obfuscating those functions to hide them from the people selling their themes. Sounds like they were also disabling this plugin as well. But they definitely went about things the wrong way, including functions like that and obfuscating them is definitely not the…

Saw this on Twitter: > Phil you need to stop with the lies. Not only do you outright lie about having the ability to kill sites with your plugin, you state that this was implemented in response to a security breach you experienced in July 2018. The code was implemented in November 2017. https://twitter.com/nickstadb/status/1112444919409446912 Unfortunately, pipdig wiped and recreated the repo an hour ago, so that his…

https://web.archive.org/web/20190331195338/bitbucket.org/pip...

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#67
post #63
post #61

Earlier quoted context omitted.

On a tangent, let's talk BlueHost. While the call to host switch is malicious, almost every developer in WordPress world will agree BlueHost, and their parent company with all their 50+ hosting companies, are utter garbage. The only reason they exist is because they have hired an army of bloggers and pay them affiliate income of $65 / signup. As far as disabling Endurance Cache goes, it is completely legitimate. It's…

Wait... so if I write a WP plugin, I'm entitled to disable other plugins I don't like when people install mine? Of course not. That endurance cache is not the only one, there's a list of "plugins we disagree with" which are disabled: https://www.wordfence.com/blog/2019/03/peculiar-php-present-... As for hosting providers: GoDaddy, BlueHost, etc - yes, they're all bad. But that doesn't justify moves like these. Seriou…

Which is why I stated it's a tangent about BlueHost and I definitely don't agree with disabling other plugins.

However, I believe it's perfectly valid to disable a forced plugin. If a host forced enabled an almost hidden plugin, without user consent [1], then it's no more evil to undo the evil for the good of users.

As for drop-in vs mu, every other cache plugin itself stays a normal plugin so it's not a technical limitation. That's beside the point though, the plugin is force enabled without user consent.

[1] https://github.com/bluehost/endurance-page-cache/issues/4#is...

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#68
post #55

Earlier quoted context omitted.

You clearly didn't read their response on it.

I did. It's factually inaccurate. > There was function in an older version of the plugin which could be used to reset a site back to the default settings. This function had no risk of of malicious or unintentional use. > The portrayal of this feature is not based on reality. There is a function in the plugin which can be used to clear database tables, much like a backup or standard reset plugin. To confirm, we do not…

Not just inaccurate, but heavily misleading as well.

"Older version", for example, is only true because they pushed a new version after getting caught that stripped out the nasty code.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#69

Here's a second writeup, which also contains a response from pipdig: https://www.wordfence.com/blog/2019/03/peculiar-php-present-...

I am just amazed, provided I am reading this right, that anyone can simply with a bit of code overwrite any user password on the site.

you would think there would different levels of user accounts and perhaps two level authentication for any change regardless of how it is invoked

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#70

Here's a second writeup, which also contains a response from pipdig: https://www.wordfence.com/blog/2019/03/peculiar-php-present-...

I am just amazed, provided I am reading this right, that anyone can simply with a bit of code overwrite any user password on the site. you would think there would different levels of user accounts and perhaps two level authentication for any change regardless of how it is invoked

There are user levels. But if you can execute code on the site ... any site, what difference does that make?
Post reply on HN