10 ms·
From pipdig https://www.pipdig.co/blog/sad-times/ https://www.pipdig.co/blog/sad-times/
by tfaruq 8y ago
From pipdig https://www.pipdig.co/blog/sad-times/ https://www.pipdig.co/blog/sad-times/
- ceejayoz 8y agoA pretty sad attempt at turning themselves into the victims, by my reading.
- xvf22 8y agoAgreed, it's a pathetic response that avoids addrssing the obviously malicious behavior. At best it shows incredibly awful development practices.
- navs 8y agoThey seem to be getting some support on Twitter: https://twitter.com/pipdig/status/1112310062956064768 https://twitter.com/pipdig/status/1112310062956064768 It's easy enough these days to blame things on journalists and "fake news".
- duskwuff 8y agoPathetic. If I'm reading this correctly, they're essentially admitting to some of the malicious features described by the researcher, but claiming that they were included for support purposes, or as a way of sabotaging sites using pirated versions of their plugin. 1. Including features which can remotely grant unauthorized access or cause damage to a user's web site is inappropriate under any circumstances. Even if they're your customers, or if they aren't your customers, or whatever. You don't do that. 2. Pipdig hasn't come up with any sensible explanation for why their license checks were pointed at a competitor's web site. It's not even clear why the license check would be architected in a way that allowed for this. 3. Altering user's site content to change links from Blogerize to Pipdig is beyond the pale. Pipdig's explanation of this feature is incoherent; it isn't even consistent with the behavior of the code presented. 4. Obfuscating the code surrounding all of these questionable bits of functionality stinks of wrongdoing. It's understandable for a license check to be a little obfuscated, perhaps, but there's no reason why a remote administration feature should be (even if it had any reason for existing).
- hrrsn 8y agoRe #2, it's clear from reading the code that the function has absolutely nothing to do with a licensing check anyway.
- ohashi 8y agoWe're just a poor small company... that is acts maliciously against our competitors using our code we sell to clients who have no idea! we're sorry we got caught and it's hard to explain why this isn't bad. Oh and they deleted repos apparently, gotta hide the evidence
- pavel_lishin 8y agoDidn't work: https://web.archive.org/web/20190331195338/bitbucket.org/pipdig/p3/commits/edc47824200e15d64cab7270debc4a0526a8d323 https://web.archive.org/web/20190331195338/bitbucket.org/pip...
- jakejarvis 8y agoYikes. "But all my customers love and trust me!" == "I'm just an above-average con man." "But I was just doing this to support them without bothering them!" == "I'm clearly not ready to take responsibility and fess up to anything because I thought my deceptively named functions would fool everybody (and still do)." "But my girlfriend and I love cat memes!" == "Please, for the love of god, can we forget about all this and talk about cat memes instead?" [I honestly have no clue what he was trying to get at in the first six paragraphs...]
- saluki 8y agoIt sounds like they got a little overaggressive fighting with the company that had hijacked their themes and were selling them last year. They were probably obfuscating those functions to hide them from the people selling their themes. Sounds like they were also disabling this plugin as well. But they definitely went about things the wrong way, including functions like that and obfuscating them is definitely not the right way to do things. I think a simple, we're sorry we had included these functions in this manner to combat the company stealing our themes last year. We understand this was wrong and a fresh clean version of the plugin will be out this week. We will do things the right way from now on, you can trust us and we welcome audits of all our code.
- ceejayoz 8y ago> It sounds like they got a little overaggressive fighting with the company that had hijacked their themes and were selling them last year. Some of this might be explainable in this fashion, but not all. https://www.wordfence.com/blog/2019/03/peculiar-php-present-in-popular-pipdig-power-pack-plugin/ https://www.wordfence.com/blog/2019/03/peculiar-php-present-... > Firstly, the plugin includes a content filter that automatically replaces references to Blogerize, a service which claims to be a beginner’s blogging course, with references to Pipdig’s own services.
- cortesoft 8y agoIt sounds like that might have been the place that stole it?
- aiCeivi9 8y agoI am sorry, that we got caught.