Formatting cleanup

(cherry picked from commit 53ff916)
This commit is contained in:
Marcus Bointon
2017-02-27 17:20:12 +01:00
parent e73ed1be19
commit 04de7a90f8
15 changed files with 69 additions and 55 deletions

View File

@@ -1,21 +1,36 @@
<?xml version="1.0" encoding="UTF-8"?>
<section>
<title>Terms and Conditions</title>
<p><company_short/> will only perform the <company_svc_short/>
if it has obtained the permission from <generate_permission_parties/>
as set out in the penetration testing waiver, attached as <b>Annex 2</b>,
or provided in a separate document.</p>
<p><company_short/> performs this assignment on the basis of its general
terms and conditions, which are attached to this offer as Annex 1.
<company_short/> rejects any general terms and conditions used by
<client_short/>.</p>
<p>In order to agree to this offer, please sign this letter in duplicate
and return it to:</p>
<contact>
<name><company_legal_rep/></name>
<address><company_long/><br/><company_address/><br/><company_postalcode/> <company_city/></address>
<title>Terms and Conditions</title>
<p>
<company_short/> will only perform the
<company_svc_short/> if it has obtained the permission from
<generate_permission_parties/> as set out in the penetration testing waiver,
attached as <b>Annex 2</b>, or provided in a separate document.
</p>
<p>
<company_short/>
performs this assignment on the basis of its general terms and conditions,
which are attached to this offer as Annex 1.
<company_short/> rejects any general terms and conditions used by
<client_short/>.
</p>
<p>In order to agree to this offer, please sign this letter in duplicate and
return it to:
</p>
<contact>
<name>
<company_legal_rep/>
</name>
<address>
<company_long/>
<br/>
<company_address/>
<br/>
<company_postalcode/>
<company_city/>
</address>
<email><company_email/></email>
</contact>
<generate_offer_signature_box/>
</section>
</contact>
<generate_offer_signature_box/>
</section>

View File

@@ -1,4 +1,4 @@
<?xml version="1.0" encoding="UTF-8"?><!--snippet -->
<?xml version="1.0" encoding="UTF-8"?>
<section id="crystalboxing">
<title>The Crystal-Box Pentesting Method</title>
<p>
@@ -20,4 +20,4 @@
crystal-box pentesting fits naturally hand-in-hand with the "Peek Over Our
Shoulder" option that <company_short/> offers to <client_short/>.
</p>
</section><!-- end of template -->
</section>

View File

@@ -7,7 +7,6 @@
<company_short/>, instead, has an obligation to make reasonable efforts (in
Dutch: “<i>inspanningsverplichting</i>”) to perform the agreed services.
</p>
<p>
<company_short/> and <client_short/>
agree to take reasonable measures to maintain the confidentiality of

View File

@@ -8,11 +8,8 @@
<company_short/>, instead, has an obligation to make reasonable efforts (in
Dutch: “<i>inspanningsverplichting</i>”) to perform the agreed services.
</p>
<p>
<company_short/>
and
<client_short/>
<company_short/> and <client_short/>
agree to take reasonable measures to maintain the confidentiality of
information and any personal data they gain access to in the course of
performing the code audit. Both parties will use the information and data

View File

@@ -1,7 +1,6 @@
<?xml version="1.0" encoding="UTF-8"?>
<section id="waiver-example">
<title>ANNEX 2 Example Pentest Waiver</title>
<p>
<b><i>(Full Client Name)</i> (“<i>(Client)</i>”)</b>, with its registered
office at Somestreet, Somecity, Earth, Milkyway, and duly represented by

View File

@@ -2,13 +2,13 @@
<section id="greyboxing">
<title>The Grey-Box Pentesting Method</title>
<p>
<!--snippet -->Crystal-Box vs. Black-Box pentesting refers to the amount of
information regarding the target environment, architecture, and/or
applications that is initially shared by the customer with the pentesters.
With Black-Box testing, pentesters are given no information whatsoever about
the target(s). With Crystal-Box testing, pentesters are given all
information requested about the target(s), including source-code (when
relevant), access to developers or system management, etc..
Crystal-Box vs. Black-Box pentesting refers to the amount of information
regarding the target environment, architecture, and/or applications that is
initially shared by the customer with the pentesters. With Black-Box
testing, pentesters are given no information whatsoever about the target(s).
With Crystal-Box testing, pentesters are given all information requested
about the target(s), including source-code (when relevant), access to
developers or system management, etc..
</p>
<p>
<company_short/>

View File

@@ -1,12 +1,17 @@
<?xml version="1.0" encoding="UTF-8"?>
<section>
<title>Introduction</title>
<p><client_long/> (hereafter “<b><client_short/></b>”), with its registered office
at <client_street/>, <client_city/>, <client_country/>, has requested <company_long/>
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.
The motivation for this request is that <client_short/> wishes to get a better
insight into ...</p>
<p>
<client_long/> (hereafter “<b><client_short/></b>”), with its registered office at
<client_street/>, <client_city/>, <client_country/>, has requested <company_long/>
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.
</p>
<p>
The motivation for this request is that <client_short/> wishes to gain better
insight into ...
</p>
<p>This offer sets out the scope of the work and the terms and conditions under
which <company_short/> will perform these services.</p>
<p>This offer sets out the scope of the work and the terms and conditions
under which <company_short/> will perform these services.
</p>
</section>

View File

@@ -4,11 +4,12 @@
<p>
<client_long/> (hereafter “<b><client_short/></b>”), with its registered office at
<client_street/>, <client_city/>, <client_country/>, has requested <company_long/>
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.</p>
<p>The motivation for this request is that <client_short/> has had a recent penetration
test done by <company_short/> and wishes to check that the vulnerabilities found
have been mitigated.
</p>
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.
</p>
<p>The motivation for this request is that <client_short/> has had a recent penetration
test done by <company_short/> and wishes to check that the vulnerabilities found
have been mitigated.
</p>
<p>This offer sets out the scope of the work and the terms and conditions
under which <company_short/> will perform these services.

View File

@@ -10,8 +10,8 @@
impact on the Confidentiality, Integrity and Availability (CIA) of the
system. We will describe how an attacker would exploit the vulnerability and
suggest ways of fixing it.
<br/>
This requires an extensive knowledge of the platform the application is
</p>
<p>This requires an extensive knowledge of the platform the application is
running on, as well as the extensive knowledge of the language the
application in written in and patterns that have been used. Therefore a code
audit done by highly-trained specialists with a strong background in
@@ -21,7 +21,7 @@
During the code audit, we take the following approach:
</p>
<ol>
<li>Thorough comprehension of functionality
<li><b>Thorough comprehension of functionality</b>
<br/>
We try to get a thorough comprehension of how the application works and
how it interacts with the user and other systems. Having detailed
@@ -29,7 +29,7 @@
documentation) at this stage is very helpful, as they aid the
understanding of the application
</li>
<li>Static analysis
<li><b>Static analysis</b>
<br/>
Using the understanding we gained in the previous step, we will use static
code analysis to uncover any vulnerabilities. Static analysis means the
@@ -47,7 +47,7 @@
assessing the quality of the security measures.
</li>
<li>Dynamic analysis
<li><b>Dynamic analysis</b>
<br/>
Dynamic analysis can also be performed. In this case, the program is run
and actively exploited by the specialist. This is usually done to confirm

View File

@@ -8,6 +8,7 @@
<ul>
<li><company_short/> performs a <p_duration/>-day <company_svc_short/> starting <p_startdate/>.</li>
<li><company_short/> delivers the final report on <p_reportdue/>.</li>
</ul>
<p>
Our fixed-fee price quote for the above described <company_svc_short/> is <p_fee/>.-
excl. VAT and out-of-pocket expenses.

View File

@@ -2,7 +2,7 @@
<section>
<title>Prerequisites</title>
<p>In order to provide training, <company_short/> will need to:</p>
<!--Example of most common scenario, change if necessary!! :-->
<!-- Example of most common scenario, change if necessary -->
<ul>
<li>Develop training materials</li>
<li>Book an appropriate venue</li>

View File

@@ -1,6 +1,5 @@
<?xml version="1.0" encoding="UTF-8"?>
<section>
<!-- section with an overview of ROS activities -->
<title>Project Overview</title>
<p>
<company_short/> will perform <company_svc_long/> for <client_short/>

View File

@@ -1,6 +1,5 @@
<?xml version="1.0" encoding="UTF-8"?>
<section>
<!-- section with an overview of ROS activities -->
<title>Project Overview</title>
<p>
<company_short/> will perform <company_svc_long/> for <client_short/>

View File

@@ -1,7 +1,7 @@
<?xml version="1.0" encoding="UTF-8"?>
<section>
<title>Project Overview
</title><!-- section with an overview of ROS activities -->
</title>
<p>
<company_short/>
will provide xxx training sessions, for xxx different groups,

View File

@@ -20,7 +20,6 @@
<!-- remove this for non pentesting offers-->
<p>The workflow of our penetration testing team is modeled on that of a
Capture The Flag (CTF) team:
<!-- remove this for non pentesting offers-->
<company_long/> has a geographically distributed team and we use online
infrastructure (RocketChat, GitLabs, etc.) to coordinate our work. This