hi
I am working in the same domain. :-)
U can try this site called..
www.foundstone.com.
U have dummy applications here. free download. try to crack them.
u'll learn how to do cross site scripting, sql injection and many more
flaws that one can come across.
Try using tools like ethereal, nmap and paros on ur own.
at first it will be a bit confusing but always google and when in doubt..
google even more :-)
u even have step by step manuals how to use the tools so u shud be ok.
i think i can send some read ups for ya just pm me ur email id. okie.