From there, you could either go further into web, such as PHP or ASP which will give you a better understanding of how dynamic sites communicate and work with a backend database, or you could go into C which will allow you to understand most exploit code and also allow you to write your own (as many exploits are written in C).