• A Allow the use of HIDDEN form fields
  • B Clean and validate all user input
  • C Use GET instead of POST
  • D Trust user-supplied data