There’s a comprehensive article here which might help:
Also, a post here:
Resources on web application security - #31 by dklynn