2.5 I'm using stored procedures for authentication, am I vulnerable? 2.6 I'm using client side JavaScript code for checking user input.
Although SSL provides a lot of security, SSL alone is not enough to prevent variable manipulation attacks.
http://owasp.com/index.php/OWASP_Application_Security_FAQ