I recently attended a Web Application Security workshop run by SANS in London.

Dominic Hiles has made extensive notes on this at: