Thanks Simon, makes sense...

And ya, can see how leaving the default will make it easier for hackers to find.
Some what similar to leaving the WP default passwords, for reasons I am not going to say (least with 2.3.x), it's pretty easy to at least narrow it down by quite a bit.
One thing also for any one getting rid of this exploit, or reading this, kinda got me stuck for a second. Step 5 is kind of vague. You need to remove that entry completely from the DB, which will deactivate all your plugin's. Then go back in and activate your plugin's and WP will add the right entry for that field. At first, I wasn't totally sure if I needed to completely remove it and if I did, if it would mess up my plugins.
As I mentioned the image add on one of my blogs was not working, I did the steps above and now works like a charm.