Hacker News new | ask | show | jobs
by thatusertwo 3921 days ago
My VPS had a default username/password called testuser, I never actually noticed it existed till my server got taken over by some chinese bruteforce attack. Every time I rebuilt the server that user account was created, apparently it is part of the image used by my ISP.

My point is that many people probably have their servers taken over in a similar way without even realizing it.