Live data from Hacker News

WordPress theme provider Pipdig using customer sites to DDoS competitors

jemjabella.co.uk

71–80 of 87 posts

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#71
post #59

Earlier quoted context omitted.

I would be interested to hear from CloudFlare as to whether there is any possibility of confirming that the URL " https://pipdigz.co.uk/p3/id39dqm3c0_license_h.txt" - fetched by the "license check" code - did at some point return the text " https://kotrynabassdesign.com/wp-admin/admin-ajax.php" . I suspect this will be difficult, or impossible, to verify (I'm not a security expert) and the "license check" code in and…

Hopefully not. Cloudflare has no business in law enforcement or legal investigations. If they are trustworthy, this will not know about the contents of sites in the past.

Agreed. Separation of concerns and all that.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#72
post #67
post #63

Earlier quoted context omitted.

Wait... so if I write a WP plugin, I'm entitled to disable other plugins I don't like when people install mine? Of course not. That endurance cache is not the only one, there's a list of "plugins we disagree with" which are disabled: https://www.wordfence.com/blog/2019/03/peculiar-php-present-... As for hosting providers: GoDaddy, BlueHost, etc - yes, they're all bad. But that doesn't justify moves like these. Seriou…

Which is why I stated it's a tangent about BlueHost and I definitely don't agree with disabling other plugins. However, I believe it's perfectly valid to disable a forced plugin. If a host forced enabled an almost hidden plugin, without user consent [1], then it's no more evil to undo the evil for the good of users. As for drop-in vs mu, every other cache plugin itself stays a normal plugin so it's not a technical li…

Well... the thing with a hosted service is the host needs to protect their arses as well, and WP resource abuse can get fascinating - a mandatory cache plugin is not _that_ bad. It's not The Right Way, but shipping WP without enabled cache or a full page cache isn't either.

I actually understand this perspective, having hosted wordpress sites and having written wordpress cache plugin myself.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#73
post #58
post #10

Earlier quoted context omitted.

It sounds like they got a little overaggressive fighting with the company that had hijacked their themes and were selling them last year. They were probably obfuscating those functions to hide them from the people selling their themes. Sounds like they were also disabling this plugin as well. But they definitely went about things the wrong way, including functions like that and obfuscating them is definitely not the…

Saw this on Twitter: > Phil you need to stop with the lies. Not only do you outright lie about having the ability to kill sites with your plugin, you state that this was implemented in response to a security breach you experienced in July 2018. The code was implemented in November 2017. https://twitter.com/nickstadb/status/1112444919409446912 Unfortunately, pipdig wiped and recreated the repo an hour ago, so that his…

y, even having this in their plugin wasn't the right way to do things. And if the timing isn't lining up that starts poking holes in their response.

I was just trying to give them the benefit of the doubt if this was done to try to combat piracy.

With GPL some piracy is expected though, and this isn't the right way to combat it.

WordPress plugins and development is still the Wild Wild West.

Most developers are good but they are some Black/Gray Hats out there for sure.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#74
post #16

Did they seriously have the audacity to deny all this after all those code examples were shown? Edit: Wow, peoples' responses on Twitter are even more delusional. Wtf?

A percentage of the population treats something like this as a personal attack. I have Atari/Sega/Chevy thus Commodore/Nintendo/Ford sucks. I use it, why are you saying those things about X, are you calling me stupid? etc.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#76

I'm a little late on the wagon here but someone seems to have made a recent backup of the code on Github: https://github.com/longwave/p3

That is me, I found a Dropbox link containing the repo on Twitter and thought it might be a good idea to preserve it.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#77

Earlier quoted context omitted.

I did. It's factually inaccurate. > There was function in an older version of the plugin which could be used to reset a site back to the default settings. This function had no risk of of malicious or unintentional use. > The portrayal of this feature is not based on reality. There is a function in the plugin which can be used to clear database tables, much like a backup or standard reset plugin. To confirm, we do not…

Not just inaccurate, but heavily misleading as well. "Older version", for example, is only true because they pushed a new version after getting caught that stripped out the nasty code.

Definitely. That they're trying to position this as an oversight is frankly disgusting. That code was intentional.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#78

What options are left if you need a simple website builder that's not a) Wordpress, which is a swamp filled with mines in the form of plugins b) Wix, which forces hosting and bad HTML on you Basically I want a Wordpress-like frontend + the rich template ecosystem and for it to spit out static HTML files.

Not a web developer, but Grav CMS is pretty neat.

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#79

Here's a second writeup, which also contains a response from pipdig: https://www.wordfence.com/blog/2019/03/peculiar-php-present-...

Jesus christ, that page is 50% ads for "Wordfence" with a static header and footer.

Yeah, it's pretty annoying. The Chrome extension "eKill" is a godsend. It makes websites like Medium readable.

https://github.com/rhardih/ekill

Re: WordPress theme provider Pipdig using customer sites to DDoS competitors

#80
post #61
post #41

> Another one from the @pipdig plugin. If you use one of their themes on @bluehost then they intentionally slow your website down by disabling the BlueHost cache plugin, then they can inject content with the title "Is your host slowing you down?" https://twitter.com/nickstadb/status/1112479746972151808 pipdig is a goldmine.

On a tangent, let's talk BlueHost. While the call to host switch is malicious, almost every developer in WordPress world will agree BlueHost, and their parent company with all their 50+ hosting companies, are utter garbage. The only reason they exist is because they have hired an army of bloggers and pay them affiliate income of $65 / signup. As far as disabling Endurance Cache goes, it is completely legitimate. It's…

I'm curious which host you'd recommend. I want a good host for making websites. Not sure if I need to be a reseller or just use their shared hosting. I'm hoping to create lots of static websites for different small businesses, and then cheaply host them. Considering Namecheap, DreamHost, and BlueHost, but I'm also hoping there's one that allows nudity (not porn, just artistic nudity). Or if there's a host that allows any content, that's a plus.

I've been trying to find non-Amazon or non-Google hosting options, wanting to spend my money elsewhere. Is this a waste of time or effort? I imagine that cloud hosting with Google would be less restrictive, though more complicated to setup.

Thanks for any ideas

Post reply on HN