I just have read a post from Anil John blog who referees to four articles from Msdn Patterns and Practices about techniques to avoid common attacks to web applications:
Very interesting information for every body who deals with .NET web application development.