Google's John Mueller explains the nine scenarios in which one URL is selected as the canonical instead of another.
A single unauthenticated connection gives attackers a full shell; credential theft observed in under three minutes on honeypot servers.