I recently noticed that I had a big hole in my application because I had done something like:
\" />
Watch this video from Scott Hanselman and Phil Haack. They cover XSS, CSRF, JSON Hijacking specifically with ASP.Net MVC.