I am going to guess that these files may be being accessed by FTP, I do not rule out the possibility of a script being used.

We have had no problems with our site (no defacements), so I more inclined to believe that the person responsible must be limited to the UBB or CGI-BIN directories.

This would rule out FTP and limit it to PERL scripting to modify our content.

In case this info is relevant we are running NT 4 servers.

Any more Help would be greatly appreciated.

Will