I had a site hosted a xxxwebhosting a few years ago, it was on a virtual server. I was pulling password files from all the other sites on the server like mad. They gave Telnet access, and I could cruise around the server unabated. If a virtual host customer had wrong permissions on their scripts, password files, I could add users, delete users etc. etc.
The uptime was great, but beyond that I got the hell out of there for security reasons. I don't know shit about Unix and was accessing things I shouldn't be able to, I could only imagine what someone with experience could have done to me.
