@@ -1,21 +1,36 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<section>
|
||||
<title>Terms and Conditions</title>
|
||||
<p><company_short/> will only perform the <company_svc_short/>
|
||||
if it has obtained the permission from <generate_permission_parties/>
|
||||
as set out in the penetration testing waiver, attached as <b>Annex 2</b>,
|
||||
or provided in a separate document.</p>
|
||||
|
||||
<p><company_short/> performs this assignment on the basis of its general
|
||||
terms and conditions, which are attached to this offer as Annex 1.
|
||||
<company_short/> rejects any general terms and conditions used by
|
||||
<client_short/>.</p>
|
||||
<p>In order to agree to this offer, please sign this letter in duplicate
|
||||
and return it to:</p>
|
||||
<contact>
|
||||
<name><company_legal_rep/></name>
|
||||
<address><company_long/><br/><company_address/><br/><company_postalcode/> <company_city/></address>
|
||||
<title>Terms and Conditions</title>
|
||||
<p>
|
||||
<company_short/> will only perform the
|
||||
<company_svc_short/> if it has obtained the permission from
|
||||
<generate_permission_parties/> as set out in the penetration testing waiver,
|
||||
attached as <b>Annex 2</b>, or provided in a separate document.
|
||||
</p>
|
||||
|
||||
<p>
|
||||
<company_short/>
|
||||
performs this assignment on the basis of its general terms and conditions,
|
||||
which are attached to this offer as Annex 1.
|
||||
<company_short/> rejects any general terms and conditions used by
|
||||
<client_short/>.
|
||||
</p>
|
||||
<p>In order to agree to this offer, please sign this letter in duplicate and
|
||||
return it to:
|
||||
</p>
|
||||
<contact>
|
||||
<name>
|
||||
<company_legal_rep/>
|
||||
</name>
|
||||
<address>
|
||||
<company_long/>
|
||||
<br/>
|
||||
<company_address/>
|
||||
<br/>
|
||||
<company_postalcode/>
|
||||
<company_city/>
|
||||
</address>
|
||||
<email><company_email/></email>
|
||||
</contact>
|
||||
<generate_offer_signature_box/>
|
||||
</section>
|
||||
</contact>
|
||||
<generate_offer_signature_box/>
|
||||
</section>
|
||||
@@ -1,4 +1,4 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?><!--snippet -->
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<section id="crystalboxing">
|
||||
<title>The Crystal-Box Pentesting Method</title>
|
||||
<p>
|
||||
@@ -20,4 +20,4 @@
|
||||
crystal-box pentesting fits naturally hand-in-hand with the "Peek Over Our
|
||||
Shoulder" option that <company_short/> offers to <client_short/>.
|
||||
</p>
|
||||
</section><!-- end of template -->
|
||||
</section>
|
||||
|
||||
@@ -7,7 +7,6 @@
|
||||
<company_short/>, instead, has an obligation to make reasonable efforts (in
|
||||
Dutch: “<i>inspanningsverplichting</i>”) to perform the agreed services.
|
||||
</p>
|
||||
|
||||
<p>
|
||||
<company_short/> and <client_short/>
|
||||
agree to take reasonable measures to maintain the confidentiality of
|
||||
|
||||
@@ -8,11 +8,8 @@
|
||||
<company_short/>, instead, has an obligation to make reasonable efforts (in
|
||||
Dutch: “<i>inspanningsverplichting</i>”) to perform the agreed services.
|
||||
</p>
|
||||
|
||||
<p>
|
||||
<company_short/>
|
||||
and
|
||||
<client_short/>
|
||||
<company_short/> and <client_short/>
|
||||
agree to take reasonable measures to maintain the confidentiality of
|
||||
information and any personal data they gain access to in the course of
|
||||
performing the code audit. Both parties will use the information and data
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<section id="waiver-example">
|
||||
<title>ANNEX 2 Example Pentest Waiver</title>
|
||||
|
||||
<p>
|
||||
<b><i>(Full Client Name)</i> (“<i>(Client)</i>”)</b>, with its registered
|
||||
office at Somestreet, Somecity, Earth, Milkyway, and duly represented by
|
||||
|
||||
@@ -2,13 +2,13 @@
|
||||
<section id="greyboxing">
|
||||
<title>The Grey-Box Pentesting Method</title>
|
||||
<p>
|
||||
<!--snippet -->Crystal-Box vs. Black-Box pentesting refers to the amount of
|
||||
information regarding the target environment, architecture, and/or
|
||||
applications that is initially shared by the customer with the pentesters.
|
||||
With Black-Box testing, pentesters are given no information whatsoever about
|
||||
the target(s). With Crystal-Box testing, pentesters are given all
|
||||
information requested about the target(s), including source-code (when
|
||||
relevant), access to developers or system management, etc..
|
||||
Crystal-Box vs. Black-Box pentesting refers to the amount of information
|
||||
regarding the target environment, architecture, and/or applications that is
|
||||
initially shared by the customer with the pentesters. With Black-Box
|
||||
testing, pentesters are given no information whatsoever about the target(s).
|
||||
With Crystal-Box testing, pentesters are given all information requested
|
||||
about the target(s), including source-code (when relevant), access to
|
||||
developers or system management, etc..
|
||||
</p>
|
||||
<p>
|
||||
<company_short/>
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<section>
|
||||
<title>Introduction</title>
|
||||
<p><client_long/> (hereafter “<b><client_short/></b>”), with its registered office
|
||||
at <client_street/>, <client_city/>, <client_country/>, has requested <company_long/>
|
||||
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.
|
||||
The motivation for this request is that <client_short/> wishes to get a better
|
||||
insight into ...</p>
|
||||
<p>
|
||||
<client_long/> (hereafter “<b><client_short/></b>”), with its registered office at
|
||||
<client_street/>, <client_city/>, <client_country/>, has requested <company_long/>
|
||||
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.
|
||||
</p>
|
||||
<p>
|
||||
The motivation for this request is that <client_short/> wishes to gain better
|
||||
insight into ...
|
||||
</p>
|
||||
|
||||
<p>This offer sets out the scope of the work and the terms and conditions under
|
||||
which <company_short/> will perform these services.</p>
|
||||
<p>This offer sets out the scope of the work and the terms and conditions
|
||||
under which <company_short/> will perform these services.
|
||||
</p>
|
||||
</section>
|
||||
@@ -4,11 +4,12 @@
|
||||
<p>
|
||||
<client_long/> (hereafter “<b><client_short/></b>”), with its registered office at
|
||||
<client_street/>, <client_city/>, <client_country/>, has requested <company_long/>
|
||||
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.</p>
|
||||
<p>The motivation for this request is that <client_short/> has had a recent penetration
|
||||
test done by <company_short/> and wishes to check that the vulnerabilities found
|
||||
have been mitigated.
|
||||
</p>
|
||||
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.
|
||||
</p>
|
||||
<p>The motivation for this request is that <client_short/> has had a recent penetration
|
||||
test done by <company_short/> and wishes to check that the vulnerabilities found
|
||||
have been mitigated.
|
||||
</p>
|
||||
|
||||
<p>This offer sets out the scope of the work and the terms and conditions
|
||||
under which <company_short/> will perform these services.
|
||||
|
||||
@@ -10,8 +10,8 @@
|
||||
impact on the Confidentiality, Integrity and Availability (CIA) of the
|
||||
system. We will describe how an attacker would exploit the vulnerability and
|
||||
suggest ways of fixing it.
|
||||
<br/>
|
||||
This requires an extensive knowledge of the platform the application is
|
||||
</p>
|
||||
<p>This requires an extensive knowledge of the platform the application is
|
||||
running on, as well as the extensive knowledge of the language the
|
||||
application in written in and patterns that have been used. Therefore a code
|
||||
audit done by highly-trained specialists with a strong background in
|
||||
@@ -21,7 +21,7 @@
|
||||
During the code audit, we take the following approach:
|
||||
</p>
|
||||
<ol>
|
||||
<li>Thorough comprehension of functionality
|
||||
<li><b>Thorough comprehension of functionality</b>
|
||||
<br/>
|
||||
We try to get a thorough comprehension of how the application works and
|
||||
how it interacts with the user and other systems. Having detailed
|
||||
@@ -29,7 +29,7 @@
|
||||
documentation) at this stage is very helpful, as they aid the
|
||||
understanding of the application
|
||||
</li>
|
||||
<li>Static analysis
|
||||
<li><b>Static analysis</b>
|
||||
<br/>
|
||||
Using the understanding we gained in the previous step, we will use static
|
||||
code analysis to uncover any vulnerabilities. Static analysis means the
|
||||
@@ -47,7 +47,7 @@
|
||||
assessing the quality of the security measures.
|
||||
</li>
|
||||
|
||||
<li>Dynamic analysis
|
||||
<li><b>Dynamic analysis</b>
|
||||
<br/>
|
||||
Dynamic analysis can also be performed. In this case, the program is run
|
||||
and actively exploited by the specialist. This is usually done to confirm
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
<ul>
|
||||
<li><company_short/> performs a <p_duration/>-day <company_svc_short/> starting <p_startdate/>.</li>
|
||||
<li><company_short/> delivers the final report on <p_reportdue/>.</li>
|
||||
</ul>
|
||||
<p>
|
||||
Our fixed-fee price quote for the above described <company_svc_short/> is <p_fee/>.-
|
||||
excl. VAT and out-of-pocket expenses.
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
<section>
|
||||
<title>Prerequisites</title>
|
||||
<p>In order to provide training, <company_short/> will need to:</p>
|
||||
<!--Example of most common scenario, change if necessary!! :-->
|
||||
<!-- Example of most common scenario, change if necessary -->
|
||||
<ul>
|
||||
<li>Develop training materials</li>
|
||||
<li>Book an appropriate venue</li>
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<section>
|
||||
<!-- section with an overview of ROS activities -->
|
||||
<title>Project Overview</title>
|
||||
<p>
|
||||
<company_short/> will perform <company_svc_long/> for <client_short/>
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<section>
|
||||
<!-- section with an overview of ROS activities -->
|
||||
<title>Project Overview</title>
|
||||
<p>
|
||||
<company_short/> will perform <company_svc_long/> for <client_short/>
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<section>
|
||||
<title>Project Overview
|
||||
</title><!-- section with an overview of ROS activities -->
|
||||
</title>
|
||||
<p>
|
||||
<company_short/>
|
||||
will provide xxx training sessions, for xxx different groups,
|
||||
|
||||
@@ -20,7 +20,6 @@
|
||||
<!-- remove this for non pentesting offers-->
|
||||
<p>The workflow of our penetration testing team is modeled on that of a
|
||||
Capture The Flag (CTF) team:
|
||||
<!-- remove this for non pentesting offers-->
|
||||
|
||||
<company_long/> has a geographically distributed team and we use online
|
||||
infrastructure (RocketChat, GitLabs, etc.) to coordinate our work. This
|
||||
|
||||
Reference in New Issue
Block a user