points
What gets hacked all the time is the actual web app itself. Which has to be exposed to be useful.