I think a decent place to start is: given a small web app, give it a bug report and ask it what causes the bug.