There is a good book called application security, or web app security, which has a picture of a cowboy hat on the front...can`t remember what the bloody name is at the moment.
I think if you already have a couple of books then you can stick with those and just read the papers from SPI, NGS etc...
Also, have a look at WebGoat http://www.owasp.org/software/webgoat.html as you can learn alot form there.




Reply With Quote