If you’re thinking of ATM skimming as clunky hardware that’s easy to detect, think again. Taped on hardware and bulky card swipe gadgets are a thing of the past. Good thieves use expensive equipment that works and they don’t get caught. They’re like ninja’s in that no one really knows if they exist.
The default out-of-the-box installation should delete any additional anonymous users after installation and disallow remote logins completely, but it doesn’t. At least all you have to do is run the mysql_secure_installation script to do so.
So I just wrote this in 2 minutes so I could kill some things in /etc and /home and be done with it. Short and simple, don’t you think?