As mentioned by Michael Howard:
Kevin Lam, David LeBlanc, & Ben Smith have released a new book, “Assessing Network Security” from MSPress. To quote Ben in an email he sent, “The book is primarily aimed at security professionals new to penetration testing and IT professionals and IT managers new to security, although all security professionals will likely benefit from the book.”
That's great that new resources are coming out on pen testing.
If you are new to the subject, here are a few links to get you started:
Penetration Testing for Web Applications (Parts One and Two)