Hi all. I wrote a book introducing the fundamentals of web application penetration testing, expressed in language I hope is friendly to coding hobbyists and beginners. I've written a few walkthroughs for basic vulnerabilities and plan to build it out with more vulnerabilities, tools, and extra resources (scripts, payload lists, etc).
I'd also like to offer all HNers half off. If you're curious and would like to get a taste of some of the content, visit http://bughunting.guide