How to stop forceful browsing?
Check authorization on each page
Name files with un-guessable names
Place all accessible files in the same directory
ACL's on the web root