I recently attended a Web Application Security workshop run by SANS in London. Dominic Hiles has made extensive notes on this at: Day 1 Day 2