Not free but a great resource, 'Apache Security' from O'Reilly. http://www.oreilly.com/catalog/apachesc/toc.html Has a chapter on PHP, general web app security & explains chrooting web apps. Won't make you a web app security expert but will get you started. Ivo