Okay I will actually give you an useful answer instead of @"FZEROX" raging upon W3schools..
First of all I'm happy to hear that you have read my thread. I expect you to be fairly familiar with Javascript, HTML, SQL and PHP. The next thing to do would be to focus on one website application attack method. My favorite method is XSS, you could also choose SQL injection etc.
I practiced a lot of "live sites" like Ask.com, Utorrent.com, thedailyshow etc. (I listed some of the sites where I was able to find vulnerabilities) and that gave me a lot of experience. To keep you self clear of all charges you could setup some kind of lab at home. If you don't have another computer you could use as server you could always fire up a VM and use that instead. Learn how to exploit your own server and learn about how to setup a secure server. That will also give you the ability to see where people forget to secure their servers. For testing things like XSS you can either use some of the test sites (I know 1llusion has made some XSS tests you could practive on legally) or you could install some intentionally vulnerable web applications on your server to practice on like,
http://www.dvwa.co.uk/ etc.
When you know that basics move on to more advanced techniques and topics, this is where the PHP knowledge will benefit you A LOT! I don't know if you have heard about the Ubuntu forums got hacked? I know the guy who discovered and invented the method the attackers (idiots) used to gain access to the fourms. 1llusion has some great tutorials on his blog on some advanced XSS methods too. Other than that research, practive and research!
I can't say it enough, it's the practical experience you learn from. The concept learn by doing is the most important way of learning everything computer related.
I know that I focused a lot of XSS in my reply, I simply choose one attack method to focus on to give you a better view on my points.