From 04de7a90f8a811cf056c9e96509582c9a0f151cf Mon Sep 17 00:00:00 2001
From: Marcus Bointon
Date: Mon, 27 Feb 2017 17:20:12 +0100
Subject: [PATCH] Formatting cleanup
(cherry picked from commit 53ff916)
---
xml/source/snippets/offerte/en/conditions.xml | 51 ++++++++++++-------
.../snippets/offerte/en/crystal-box.xml | 4 +-
xml/source/snippets/offerte/en/disclaimer.xml | 1 -
.../offerte/en/disclaimer_code-audit.xml | 5 +-
.../snippets/offerte/en/examplewaiver.xml | 1 -
xml/source/snippets/offerte/en/grey-box.xml | 14 ++---
.../snippets/offerte/en/introandscope.xml | 19 ++++---
.../offerte/en/introandscope_retest.xml | 11 ++--
.../offerte/en/methodology_code-audit.xml | 10 ++--
.../offerte/en/planningandpayment.xml | 1 +
.../offerte/en/prerequisites_training.xml | 2 +-
.../snippets/offerte/en/projectoverview.xml | 1 -
.../offerte/en/projectoverview_retest.xml | 1 -
.../offerte/en/projectoverview_training.xml | 2 +-
.../snippets/offerte/en/teamandreporting.xml | 1 -
15 files changed, 69 insertions(+), 55 deletions(-)
diff --git a/xml/source/snippets/offerte/en/conditions.xml b/xml/source/snippets/offerte/en/conditions.xml
index ac345c6..1f8f503 100644
--- a/xml/source/snippets/offerte/en/conditions.xml
+++ b/xml/source/snippets/offerte/en/conditions.xml
@@ -1,21 +1,36 @@
- Terms and Conditions
- will only perform the
- if it has obtained the permission from
- as set out in the penetration testing waiver, attached as Annex 2,
- or provided in a separate document.
-
- performs this assignment on the basis of its general
- terms and conditions, which are attached to this offer as Annex 1.
- rejects any general terms and conditions used by
- .
- In order to agree to this offer, please sign this letter in duplicate
- and return it to:
-
-
-
+ Terms and Conditions
+
+ will only perform the
+ if it has obtained the permission from
+ as set out in the penetration testing waiver,
+ attached as Annex 2, or provided in a separate document.
+
+
+
+
+ performs this assignment on the basis of its general terms and conditions,
+ which are attached to this offer as Annex 1.
+ rejects any general terms and conditions used by
+ .
+
+ In order to agree to this offer, please sign this letter in duplicate and
+ return it to:
+
+
+
+
+
+
+
+
+
+
+
+
+
-
-
-
\ No newline at end of file
+
+
+
\ No newline at end of file
diff --git a/xml/source/snippets/offerte/en/crystal-box.xml b/xml/source/snippets/offerte/en/crystal-box.xml
index b468c51..6bccbd4 100644
--- a/xml/source/snippets/offerte/en/crystal-box.xml
+++ b/xml/source/snippets/offerte/en/crystal-box.xml
@@ -1,4 +1,4 @@
-
+
The Crystal-Box Pentesting Method
@@ -20,4 +20,4 @@
crystal-box pentesting fits naturally hand-in-hand with the "Peek Over Our
Shoulder" option that offers to .
-
+
diff --git a/xml/source/snippets/offerte/en/disclaimer.xml b/xml/source/snippets/offerte/en/disclaimer.xml
index 0215784..6297971 100644
--- a/xml/source/snippets/offerte/en/disclaimer.xml
+++ b/xml/source/snippets/offerte/en/disclaimer.xml
@@ -7,7 +7,6 @@
, instead, has an obligation to make reasonable efforts (in
Dutch: “inspanningsverplichting”) to perform the agreed services.
-
and
agree to take reasonable measures to maintain the confidentiality of
diff --git a/xml/source/snippets/offerte/en/disclaimer_code-audit.xml b/xml/source/snippets/offerte/en/disclaimer_code-audit.xml
index 8168427..a274bb5 100644
--- a/xml/source/snippets/offerte/en/disclaimer_code-audit.xml
+++ b/xml/source/snippets/offerte/en/disclaimer_code-audit.xml
@@ -8,11 +8,8 @@
, instead, has an obligation to make reasonable efforts (in
Dutch: “inspanningsverplichting”) to perform the agreed services.
-
-
- and
-
+ and
agree to take reasonable measures to maintain the confidentiality of
information and any personal data they gain access to in the course of
performing the code audit. Both parties will use the information and data
diff --git a/xml/source/snippets/offerte/en/examplewaiver.xml b/xml/source/snippets/offerte/en/examplewaiver.xml
index f86b794..215aef8 100644
--- a/xml/source/snippets/offerte/en/examplewaiver.xml
+++ b/xml/source/snippets/offerte/en/examplewaiver.xml
@@ -1,7 +1,6 @@
ANNEX 2 Example Pentest Waiver
-
(Full Client Name) (“(Client)”), with its registered
office at Somestreet, Somecity, Earth, Milkyway, and duly represented by
diff --git a/xml/source/snippets/offerte/en/grey-box.xml b/xml/source/snippets/offerte/en/grey-box.xml
index a73f17f..42722a9 100644
--- a/xml/source/snippets/offerte/en/grey-box.xml
+++ b/xml/source/snippets/offerte/en/grey-box.xml
@@ -2,13 +2,13 @@
The Grey-Box Pentesting Method
- Crystal-Box vs. Black-Box pentesting refers to the amount of
- information regarding the target environment, architecture, and/or
- applications that is initially shared by the customer with the pentesters.
- With Black-Box testing, pentesters are given no information whatsoever about
- the target(s). With Crystal-Box testing, pentesters are given all
- information requested about the target(s), including source-code (when
- relevant), access to developers or system management, etc..
+ Crystal-Box vs. Black-Box pentesting refers to the amount of information
+ regarding the target environment, architecture, and/or applications that is
+ initially shared by the customer with the pentesters. With Black-Box
+ testing, pentesters are given no information whatsoever about the target(s).
+ With Crystal-Box testing, pentesters are given all information requested
+ about the target(s), including source-code (when relevant), access to
+ developers or system management, etc..
diff --git a/xml/source/snippets/offerte/en/introandscope.xml b/xml/source/snippets/offerte/en/introandscope.xml
index bb8c684..d4f1a64 100644
--- a/xml/source/snippets/offerte/en/introandscope.xml
+++ b/xml/source/snippets/offerte/en/introandscope.xml
@@ -1,12 +1,17 @@
Introduction
- (hereafter “”), with its registered office
- at , , , has requested
- (hereafter “”) to perform .
- The motivation for this request is that wishes to get a better
- insight into ...
+
+ (hereafter “”), with its registered office at
+ , , , has requested
+ (hereafter “”) to perform .
+
+
+ The motivation for this request is that wishes to gain better
+ insight into ...
+
- This offer sets out the scope of the work and the terms and conditions under
- which will perform these services.
+ This offer sets out the scope of the work and the terms and conditions
+ under which will perform these services.
+
\ No newline at end of file
diff --git a/xml/source/snippets/offerte/en/introandscope_retest.xml b/xml/source/snippets/offerte/en/introandscope_retest.xml
index ccc5971..143569d 100644
--- a/xml/source/snippets/offerte/en/introandscope_retest.xml
+++ b/xml/source/snippets/offerte/en/introandscope_retest.xml
@@ -4,11 +4,12 @@
(hereafter “”), with its registered office at
, , , has requested
- (hereafter “”) to perform .
- The motivation for this request is that has had a recent penetration
- test done by and wishes to check that the vulnerabilities found
- have been mitigated.
-
+ (hereafter “”) to perform .
+
+ The motivation for this request is that has had a recent penetration
+ test done by and wishes to check that the vulnerabilities found
+ have been mitigated.
+
This offer sets out the scope of the work and the terms and conditions
under which will perform these services.
diff --git a/xml/source/snippets/offerte/en/methodology_code-audit.xml b/xml/source/snippets/offerte/en/methodology_code-audit.xml
index 02b24cf..5530cf7 100644
--- a/xml/source/snippets/offerte/en/methodology_code-audit.xml
+++ b/xml/source/snippets/offerte/en/methodology_code-audit.xml
@@ -10,8 +10,8 @@
impact on the Confidentiality, Integrity and Availability (CIA) of the
system. We will describe how an attacker would exploit the vulnerability and
suggest ways of fixing it.
-
- This requires an extensive knowledge of the platform the application is
+
+ This requires an extensive knowledge of the platform the application is
running on, as well as the extensive knowledge of the language the
application in written in and patterns that have been used. Therefore a code
audit done by highly-trained specialists with a strong background in
@@ -21,7 +21,7 @@
During the code audit, we take the following approach:
- - Thorough comprehension of functionality
+
- Thorough comprehension of functionality
We try to get a thorough comprehension of how the application works and
how it interacts with the user and other systems. Having detailed
@@ -29,7 +29,7 @@
documentation) at this stage is very helpful, as they aid the
understanding of the application
- - Static analysis
+
- Static analysis
Using the understanding we gained in the previous step, we will use static
code analysis to uncover any vulnerabilities. Static analysis means the
@@ -47,7 +47,7 @@
assessing the quality of the security measures.
- - Dynamic analysis
+
- Dynamic analysis
Dynamic analysis can also be performed. In this case, the program is run
and actively exploited by the specialist. This is usually done to confirm
diff --git a/xml/source/snippets/offerte/en/planningandpayment.xml b/xml/source/snippets/offerte/en/planningandpayment.xml
index 9d3d0e7..03bc540 100644
--- a/xml/source/snippets/offerte/en/planningandpayment.xml
+++ b/xml/source/snippets/offerte/en/planningandpayment.xml
@@ -8,6 +8,7 @@
- performs a -day starting .
- delivers the final report on .
+
Our fixed-fee price quote for the above described is .-
excl. VAT and out-of-pocket expenses.
diff --git a/xml/source/snippets/offerte/en/prerequisites_training.xml b/xml/source/snippets/offerte/en/prerequisites_training.xml
index 4d13029..8ff8527 100644
--- a/xml/source/snippets/offerte/en/prerequisites_training.xml
+++ b/xml/source/snippets/offerte/en/prerequisites_training.xml
@@ -2,7 +2,7 @@
Prerequisites
In order to provide training, will need to:
-
+
- Develop training materials
- Book an appropriate venue
diff --git a/xml/source/snippets/offerte/en/projectoverview.xml b/xml/source/snippets/offerte/en/projectoverview.xml
index 6ba4a56..6c21fd1 100644
--- a/xml/source/snippets/offerte/en/projectoverview.xml
+++ b/xml/source/snippets/offerte/en/projectoverview.xml
@@ -1,6 +1,5 @@
-
Project Overview
will perform for
diff --git a/xml/source/snippets/offerte/en/projectoverview_retest.xml b/xml/source/snippets/offerte/en/projectoverview_retest.xml
index 948b027..082103e 100644
--- a/xml/source/snippets/offerte/en/projectoverview_retest.xml
+++ b/xml/source/snippets/offerte/en/projectoverview_retest.xml
@@ -1,6 +1,5 @@
-
Project Overview
will perform for
diff --git a/xml/source/snippets/offerte/en/projectoverview_training.xml b/xml/source/snippets/offerte/en/projectoverview_training.xml
index 7d26efc..33f9f37 100644
--- a/xml/source/snippets/offerte/en/projectoverview_training.xml
+++ b/xml/source/snippets/offerte/en/projectoverview_training.xml
@@ -1,7 +1,7 @@
Project Overview
-
+
will provide xxx training sessions, for xxx different groups,
diff --git a/xml/source/snippets/offerte/en/teamandreporting.xml b/xml/source/snippets/offerte/en/teamandreporting.xml
index 17dad5b..841fc5b 100644
--- a/xml/source/snippets/offerte/en/teamandreporting.xml
+++ b/xml/source/snippets/offerte/en/teamandreporting.xml
@@ -20,7 +20,6 @@
The workflow of our penetration testing team is modeled on that of a
Capture The Flag (CTF) team:
-
has a geographically distributed team and we use online
infrastructure (RocketChat, GitLabs, etc.) to coordinate our work. This