How can one reduce the risk of session fixation attacks?
A) Regenerate session IDs after login
B) By disabling JavaScript
C) Use of CAPTCHAs
D) Shortening session expiration times