Users will often run unauthorized services. There are also some utilities which exist in the cracker crowd which they can run on alternate ports, once they gain root access. These programs will drop them directly into a root shell--bypassing normal login means.