Someone who is not usually a Ubuntu user sent me an excerpt from the auth.log file on a machine he has inherited. It contained a line similar to (I've removed the IP address for various reasons)
Accepted password for root from xx.yyy.zzz.abc port 44953 ssh2
Our question is 'Are we right in assuming that one of our users has re-enabled root on this machine or is their another way this could have happened?'
Cheers, Mike