Preventing Web Application Access Control Abuse