TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

WordPress theme provider Pipdig using customer sites to DDoS competitors

325 pointsby JamieF1about 6 years ago

13 comments

pmlnrabout 6 years ago
&gt; Another one from the @pipdig plugin. If you use one of their themes on @bluehost then they intentionally slow your website down by disabling the BlueHost cache plugin, then they can inject content with the title &quot;Is your host slowing you down?&quot;<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;nickstadb&#x2F;status&#x2F;1112479746972151808" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;nickstadb&#x2F;status&#x2F;1112479746972151808</a><p>pipdig is a goldmine.
评论 #19542828 未加载
reustleabout 6 years ago
A developer at Pipdig wrote these lines of code and shipped it, I wonder how they felt.<p><pre><code> foreach ($tables as $table) { $wpdb-&gt;query(&quot;DROP TABLE $table&quot;); }</code></pre>
评论 #19541428 未加载
评论 #19540835 未加载
robotbikesabout 6 years ago
And this just illustrates the horror that is the proprietary market place of WordPress plugins. It is annoying because this results in incentives to take away freedom from users and require payment for proprietary code in the guise of a free software project. To expand Word Press functionality beyond the core functions you have to wade through a minefield of freemium plugins that have all been slightly broken to encourage you to shell out money to someone for code you won&#x27;t have any freedom with and the worst of it possibly demonstrated by code like this. I have built some sites with WordPress but I have always felt stifled by the way the plugins and themes are distributed. On the other hand I understand people like being able to charge money and create businesses from the code they right which can be more challenging if you actually write free as in libre software vs. attempting to extract money from every potential user.
评论 #19542301 未加载
评论 #19542547 未加载
评论 #19542506 未加载
nickodellabout 6 years ago
Here&#x27;s a second writeup, which also contains a response from pipdig: <a href="https:&#x2F;&#x2F;www.wordfence.com&#x2F;blog&#x2F;2019&#x2F;03&#x2F;peculiar-php-present-in-popular-pipdig-power-pack-plugin&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.wordfence.com&#x2F;blog&#x2F;2019&#x2F;03&#x2F;peculiar-php-present-...</a>
评论 #19539651 未加载
评论 #19541257 未加载
评论 #19543081 未加载
skilledabout 6 years ago
Did they seriously have the audacity to deny all this after all those code examples were shown?<p>Edit: Wow, peoples&#x27; responses on Twitter are even more delusional. Wtf?
评论 #19539953 未加载
评论 #19544335 未加载
tfaruqabout 6 years ago
From pipdig <a href="https:&#x2F;&#x2F;www.pipdig.co&#x2F;blog&#x2F;sad-times&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.pipdig.co&#x2F;blog&#x2F;sad-times&#x2F;</a>
评论 #19539421 未加载
评论 #19539506 未加载
评论 #19539632 未加载
评论 #19539365 未加载
评论 #19541698 未加载
nixgeekabout 6 years ago
It looks like the company involved is based in the U.K. and also seems likely this software and their usage of it is a violation of the Computer Misuse Act.<p>One of their competitors should consider filing a complaint with the relevant authorities, so this gets formally investigated.
评论 #19542513 未加载
评论 #19541054 未加载
duskwuffabout 6 years ago
Followup at:<p><a href="https:&#x2F;&#x2F;www.jemjabella.co.uk&#x2F;2019&#x2F;pipdig-your-questions-answered&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.jemjabella.co.uk&#x2F;2019&#x2F;pipdig-your-questions-answ...</a>
评论 #19539561 未加载
huxfluxabout 6 years ago
&quot;Sad times - <a href="https:&#x2F;&#x2F;www.pipdig.co&#x2F;blog&#x2F;sad-times&#x2F;&quot;" rel="nofollow">https:&#x2F;&#x2F;www.pipdig.co&#x2F;blog&#x2F;sad-times&#x2F;&quot;</a> No shit.
jarymabout 6 years ago
These guys put all this evil into their code (PHP no less so easily readable by anyone) and it took this long for them to get caught?<p>Further, they peddled this into who knows how many themes they sold and never thought they&#x27;d get caught?
评论 #19540990 未加载
评论 #19542433 未加载
fastbeefabout 6 years ago
What options are left if you need a simple website builder that&#x27;s not<p>a) Wordpress, which is a swamp filled with mines in the form of plugins b) Wix, which forces hosting and bad HTML on you<p>Basically I want a Wordpress-like frontend + the rich template ecosystem and for it to spit out static HTML files.
评论 #19547478 未加载
评论 #19545260 未加载
EKSolutionsabout 6 years ago
I&#x27;m a little late on the wagon here but someone seems to have made a recent backup of the code on Github: <a href="https:&#x2F;&#x2F;github.com&#x2F;longwave&#x2F;p3" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;longwave&#x2F;p3</a>
评论 #19544835 未加载
cy6erlionabout 6 years ago
The more I read the more it sounds like an April fools joke.