Are there any good tutorials for writing web based exploits for beginners?
Saying you want to learn to write exploits is way too generic, even for web based ones. What do you want to focus on? SQLi, XSS, CSRF, RFI/LFI, auth bypass...? You should start by taking a look at OWASP.