I am a relatively experienced hobbyist web developer, but am concerned about my lack of knowledge covering potential security holes in web sites/services. I am looking for documentation covering best practices regarding security, especially when dealing with SQL databases.
Attempts at searching are being thwarted by the fact that Google seems to equate "SQL" with "Microsoft SQL Server". I'm using PostgreSQL here.
Free resources are better right now, but dead tree is interesting too.