Anonymous FTP is not enabled. Ubbthreads 6.5 is installed on the same system. Is there a script in 6.5 that can be compromised to upload stuff. I've found four directories with these phishing pages - two in the 6.5 directory hierarchy, one under the 7.3 directory and one outside these directories but in another directory with 777 permissions. All are owned by user apache. The only scripts are in the 6.5 and 7.3 directories, everything else is static HTML files.