I've discovered something a bit odd - created a user, started with them in the staff group. I noticed that after I ssh'd in as this user I was able to su to root - so I removed them from staff and put them in guest - same behaviour.
I checked /etc/pam.d/su and compared against another system and it seems fine.
I checked /etc/pam.d/su and compared against another system and it seems fine.
Code:
FreeBSD xxxxxxxx 7.2-RELEASE-p8 FreeBSD 7.2-RELEASE-p8 #0: Wed May 26 03:08:50 UTC 2010 root@i386-builder.daemonology.net:/usr/obj/usr/src/sys/GENERIC i386