diff --git a/xml/source/snippets/offerte/en/conditions.xml b/xml/source/snippets/offerte/en/conditions.xml index ac345c6..1f8f503 100644 --- a/xml/source/snippets/offerte/en/conditions.xml +++ b/xml/source/snippets/offerte/en/conditions.xml @@ -1,21 +1,36 @@
- Terms and Conditions -

will only perform the - if it has obtained the permission from - as set out in the penetration testing waiver, attached as Annex 2, - or provided in a separate document.

- -

performs this assignment on the basis of its general - terms and conditions, which are attached to this offer as Annex 1. - rejects any general terms and conditions used by - .

-

In order to agree to this offer, please sign this letter in duplicate - and return it to:

- - -


+ Terms and Conditions +

+ will only perform the + if it has obtained the permission from + as set out in the penetration testing waiver, + attached as Annex 2, or provided in a separate document. +

+ +

+ + performs this assignment on the basis of its general terms and conditions, + which are attached to this offer as Annex 1. + rejects any general terms and conditions used by + . +

+

In order to agree to this offer, please sign this letter in duplicate and + return it to: +

+ + + + +
+ +
+ +
+ + +
-
- -
\ No newline at end of file + + + \ No newline at end of file diff --git a/xml/source/snippets/offerte/en/crystal-box.xml b/xml/source/snippets/offerte/en/crystal-box.xml index b468c51..6bccbd4 100644 --- a/xml/source/snippets/offerte/en/crystal-box.xml +++ b/xml/source/snippets/offerte/en/crystal-box.xml @@ -1,4 +1,4 @@ - +
The Crystal-Box Pentesting Method

@@ -20,4 +20,4 @@ crystal-box pentesting fits naturally hand-in-hand with the "Peek Over Our Shoulder" option that offers to .

-
+ diff --git a/xml/source/snippets/offerte/en/disclaimer.xml b/xml/source/snippets/offerte/en/disclaimer.xml index 0215784..6297971 100644 --- a/xml/source/snippets/offerte/en/disclaimer.xml +++ b/xml/source/snippets/offerte/en/disclaimer.xml @@ -7,7 +7,6 @@ , instead, has an obligation to make reasonable efforts (in Dutch: “inspanningsverplichting”) to perform the agreed services.

-

and agree to take reasonable measures to maintain the confidentiality of diff --git a/xml/source/snippets/offerte/en/disclaimer_code-audit.xml b/xml/source/snippets/offerte/en/disclaimer_code-audit.xml index 8168427..a274bb5 100644 --- a/xml/source/snippets/offerte/en/disclaimer_code-audit.xml +++ b/xml/source/snippets/offerte/en/disclaimer_code-audit.xml @@ -8,11 +8,8 @@ , instead, has an obligation to make reasonable efforts (in Dutch: “inspanningsverplichting”) to perform the agreed services.

-

- - and - + and agree to take reasonable measures to maintain the confidentiality of information and any personal data they gain access to in the course of performing the code audit. Both parties will use the information and data diff --git a/xml/source/snippets/offerte/en/examplewaiver.xml b/xml/source/snippets/offerte/en/examplewaiver.xml index f86b794..215aef8 100644 --- a/xml/source/snippets/offerte/en/examplewaiver.xml +++ b/xml/source/snippets/offerte/en/examplewaiver.xml @@ -1,7 +1,6 @@

ANNEX 2 Example Pentest Waiver -

(Full Client Name) (“(Client)”), with its registered office at Somestreet, Somecity, Earth, Milkyway, and duly represented by diff --git a/xml/source/snippets/offerte/en/grey-box.xml b/xml/source/snippets/offerte/en/grey-box.xml index a73f17f..42722a9 100644 --- a/xml/source/snippets/offerte/en/grey-box.xml +++ b/xml/source/snippets/offerte/en/grey-box.xml @@ -2,13 +2,13 @@

The Grey-Box Pentesting Method

- Crystal-Box vs. Black-Box pentesting refers to the amount of - information regarding the target environment, architecture, and/or - applications that is initially shared by the customer with the pentesters. - With Black-Box testing, pentesters are given no information whatsoever about - the target(s). With Crystal-Box testing, pentesters are given all - information requested about the target(s), including source-code (when - relevant), access to developers or system management, etc.. + Crystal-Box vs. Black-Box pentesting refers to the amount of information + regarding the target environment, architecture, and/or applications that is + initially shared by the customer with the pentesters. With Black-Box + testing, pentesters are given no information whatsoever about the target(s). + With Crystal-Box testing, pentesters are given all information requested + about the target(s), including source-code (when relevant), access to + developers or system management, etc..

diff --git a/xml/source/snippets/offerte/en/introandscope.xml b/xml/source/snippets/offerte/en/introandscope.xml index bb8c684..d4f1a64 100644 --- a/xml/source/snippets/offerte/en/introandscope.xml +++ b/xml/source/snippets/offerte/en/introandscope.xml @@ -1,12 +1,17 @@

Introduction -

(hereafter “”), with its registered office - at , , , has requested - (hereafter “”) to perform . - The motivation for this request is that wishes to get a better - insight into ...

+

+ (hereafter “”), with its registered office at + , , , has requested + (hereafter “”) to perform . +

+

+ The motivation for this request is that wishes to gain better + insight into ... +

-

This offer sets out the scope of the work and the terms and conditions under - which will perform these services.

+

This offer sets out the scope of the work and the terms and conditions + under which will perform these services. +

\ No newline at end of file diff --git a/xml/source/snippets/offerte/en/introandscope_retest.xml b/xml/source/snippets/offerte/en/introandscope_retest.xml index ccc5971..143569d 100644 --- a/xml/source/snippets/offerte/en/introandscope_retest.xml +++ b/xml/source/snippets/offerte/en/introandscope_retest.xml @@ -4,11 +4,12 @@

(hereafter “”), with its registered office at , , , has requested - (hereafter “”) to perform .

-

The motivation for this request is that has had a recent penetration - test done by and wishes to check that the vulnerabilities found - have been mitigated. -

+ (hereafter “”) to perform . +

+

The motivation for this request is that has had a recent penetration + test done by and wishes to check that the vulnerabilities found + have been mitigated. +

This offer sets out the scope of the work and the terms and conditions under which will perform these services. diff --git a/xml/source/snippets/offerte/en/methodology_code-audit.xml b/xml/source/snippets/offerte/en/methodology_code-audit.xml index 02b24cf..5530cf7 100644 --- a/xml/source/snippets/offerte/en/methodology_code-audit.xml +++ b/xml/source/snippets/offerte/en/methodology_code-audit.xml @@ -10,8 +10,8 @@ impact on the Confidentiality, Integrity and Availability (CIA) of the system. We will describe how an attacker would exploit the vulnerability and suggest ways of fixing it. -
- This requires an extensive knowledge of the platform the application is +

+

This requires an extensive knowledge of the platform the application is running on, as well as the extensive knowledge of the language the application in written in and patterns that have been used. Therefore a code audit done by highly-trained specialists with a strong background in @@ -21,7 +21,7 @@ During the code audit, we take the following approach:

    -
  1. Thorough comprehension of functionality +
  2. Thorough comprehension of functionality
    We try to get a thorough comprehension of how the application works and how it interacts with the user and other systems. Having detailed @@ -29,7 +29,7 @@ documentation) at this stage is very helpful, as they aid the understanding of the application
  3. -
  4. Static analysis +
  5. Static analysis
    Using the understanding we gained in the previous step, we will use static code analysis to uncover any vulnerabilities. Static analysis means the @@ -47,7 +47,7 @@ assessing the quality of the security measures.
  6. -
  7. Dynamic analysis +
  8. Dynamic analysis
    Dynamic analysis can also be performed. In this case, the program is run and actively exploited by the specialist. This is usually done to confirm diff --git a/xml/source/snippets/offerte/en/planningandpayment.xml b/xml/source/snippets/offerte/en/planningandpayment.xml index 9d3d0e7..03bc540 100644 --- a/xml/source/snippets/offerte/en/planningandpayment.xml +++ b/xml/source/snippets/offerte/en/planningandpayment.xml @@ -8,6 +8,7 @@
    • performs a -day starting .
    • delivers the final report on .
    • +

    Our fixed-fee price quote for the above described is .- excl. VAT and out-of-pocket expenses. diff --git a/xml/source/snippets/offerte/en/prerequisites_training.xml b/xml/source/snippets/offerte/en/prerequisites_training.xml index 4d13029..8ff8527 100644 --- a/xml/source/snippets/offerte/en/prerequisites_training.xml +++ b/xml/source/snippets/offerte/en/prerequisites_training.xml @@ -2,7 +2,7 @@

    Prerequisites

    In order to provide training, will need to:

    - +
    • Develop training materials
    • Book an appropriate venue
    • diff --git a/xml/source/snippets/offerte/en/projectoverview.xml b/xml/source/snippets/offerte/en/projectoverview.xml index 6ba4a56..6c21fd1 100644 --- a/xml/source/snippets/offerte/en/projectoverview.xml +++ b/xml/source/snippets/offerte/en/projectoverview.xml @@ -1,6 +1,5 @@
      - Project Overview

      will perform for diff --git a/xml/source/snippets/offerte/en/projectoverview_retest.xml b/xml/source/snippets/offerte/en/projectoverview_retest.xml index 948b027..082103e 100644 --- a/xml/source/snippets/offerte/en/projectoverview_retest.xml +++ b/xml/source/snippets/offerte/en/projectoverview_retest.xml @@ -1,6 +1,5 @@

      - Project Overview

      will perform for diff --git a/xml/source/snippets/offerte/en/projectoverview_training.xml b/xml/source/snippets/offerte/en/projectoverview_training.xml index 7d26efc..33f9f37 100644 --- a/xml/source/snippets/offerte/en/projectoverview_training.xml +++ b/xml/source/snippets/offerte/en/projectoverview_training.xml @@ -1,7 +1,7 @@

      Project Overview - +

      will provide xxx training sessions, for xxx different groups, diff --git a/xml/source/snippets/offerte/en/teamandreporting.xml b/xml/source/snippets/offerte/en/teamandreporting.xml index 17dad5b..841fc5b 100644 --- a/xml/source/snippets/offerte/en/teamandreporting.xml +++ b/xml/source/snippets/offerte/en/teamandreporting.xml @@ -20,7 +20,6 @@

      The workflow of our penetration testing team is modeled on that of a Capture The Flag (CTF) team: - has a geographically distributed team and we use online infrastructure (RocketChat, GitLabs, etc.) to coordinate our work. This