What gets hacked all the time is the actual web app itself. Which has to be exposed to be useful.
Password auth and the root username. Use one attackers are unlikely to guess and elevate with sudo if needed.
What gets hacked all the time is the actual web app itself. Which has to be exposed to be useful.