The game I'm in just got hit by a troll that issued a console command that deleted everything near spawn. The server used the default settings: public, no password, "allow commands" was set to true.
It shouldn't even be possible to have a public, unpassworded game that allows commands, nevermind as the default! It's a giant bait to trolls and I'm sure they're going through every server in the list.