Mischief after patch

I found a user l*** and a nice password for him and he is running a service on port ***6 and managed to connect. A bit confused that there are two kind of credentials for the same user. Am I on the good track? where to use the second pair of cred?