You don't need to use a DSN connection.
If you had read the documentation that came with the forum you will have found that this issue is covered.
It is strongly suggestested that you rename the database and move it to a folder that is not accessible through a web browser. For this you don't need to use a DSN connection, a DSN-less connection can be used and all you have to do is change the path in the common.asp files to where the database is located.
If people where to read the documentation then these things wouldn't happen!!!!
Also as many of you don't, version 7 addresses this issue by one-way encrypting all passwords, so it doesn't matter if someone downloads the database, they can't get the passwords.