It appears that Google can be used to find Citrix gateways, which are often unsecured - allowing a hacker to get a command prompt on the servers. This article explains how, and includes a video showing how to get a command prompt from the calculator application - it’s scarily easy…
Update: The video has been removed by YouTube.