I have a few sensitive files on my web server, they hold the passwords to the db etc.

they have the file extension .data which I have blocked for http access in the .htaccess file

there is no directory browsing on my server.

I was looking through my http error log and someone tried to download the .data files. but the thing that kicked me was that someone knew the names of all the files, how the hell did they get the names of the files!!!!