You can prevent files being stored in the media folder, check out the links here: Authentication for direct file access