There are quite a few web security papers and seminar transcripts available which explain everything in detail, but unless you know/learn PHP, the mechanics of HTTP requests, DOM and SSL protocols you probably won't understand them. As Renmiri said though, it would be almost impossible to glean a full understanding of these things from here.

If you aren't that far along yet, chances are you don't need to elaborate that much, but if you are I definitely recommend reading a few papers.