So the guys was either running unknown binaries as root, compiling unknown source as root or running some daemon as root, so what? Every newbie knows that doing so is simply asking for trouble, even though most do it. A production server shouldn't anyway be running unknown software.
Do you have any idea how know-it-all this sounds?
I know the guy, and he's not some pimply faced geek teenager who knows just enough to be dangerous. He knows his stuff.
Cheers, Carl.
