maybe this will also contribute
http://www.insecure.org/stf/mudge_bu..._tutorial.html

it's an old article but covers most of the aspects and it's good reading