Kinda heartless sounding...
Most people don't think to put their database outside of their site root folder or even to change the name of it. Which makes it very easy for a person to download their access database. A search on google/yahoo, etc for a web wiz forum will show up many ppl using it. If the administrator doesn't think to at least rename the database, they almost deserve what happens to them.
It's stressed repeatedly in the readme file, setup docs, etc that you should do this. Another option you can do is Password protect the database and then just configure the common.asp file to login whenever it accesses teh database. (i believe that's the only file that needs updated).