(OWASP's webgoat test method, webgoat is a good platform for penetration testing, this document is the Chinese version of doc, which is very helpful for learning webgoat...
OWASP's webgoat test\1.WebGoat installation, access to use with Firebug.docx
OWASP's webgoat test\2.AcceS/SControlFlaws.docx
OWASP's webgoat test\3.AJAXSecurity.docx
OWASP's webgoat test\4.Cross-SiteScripting(XSS).docx
OWASP's webgoat test\5.InjectionFlaws.docx)