http://www.flickr.com/photos/gregvdb/

SQL injection exploitation internals

How to exploit this web application injection point.

2009 Top 25 Programming Errors

25 most dangerous programming errors that lead to security bugs

w3af 2312 portable (and other useful stuff)

UPDATED w3af to build 2312 fixed SVN updater and added larger 1meg plkto (nikto ) DB file.

Interesting exploits:
Wordpress plugin WP-Forum 1.7.8 Remote SQL Injection
Simple Machines Forum – Destroyer

meh, not much else going on… here is a good read though:

Fail and You – Twitter hack edition

and finally:
hxxp://anonym.to/javascript%3Aalert(%27fail%27)//http%3A//