http://www.owasp.org/index.php/Category:OWASP_Testing_Projec...
Other than that, testing a web app is just like testing any other software. Look for edge cases, try different combination of things, etc. to say the least. But here are a few things to look out for off the top of my head:
* Don't be too restrictive on validation on fields like names, addresses/zip codes (if there are international customers), e-mails, etc. However, make sure people can't enter numbers in an SSN field or letters in a date field either.
* Make sure weird characters in different fields don't break anything. For example, entering O'Hara as the last name should be stored correctly in the DB and then rendered correctly to the user whenever you need to show it.
* Make sure your text box max lengths are not greater than the DB's column definitions. You don't want someone to enter a 50 letter name and have the field in the DB defined as varchar(20).
* Make sure the web app handles session time outs gracefully. You don't want a user filling out a registration form to get a phone call and then come back to complete the form, only to be redirected to the starting page when he clicks Submit.
There are also automated frameworks you can use to script automated tests, such as Watir/WatiN. (Please don't ever waste money on QTP.)
And as others have mentioned there's always load testing and stress testing you need to do at a certain point.