I just heard about a potential ASP.NET security problem, one which lets others download files that are on your ASP.NET application root, which can include login info. Anyone know a good patch for this, or maybe some other solution?