diff --git a/xml/source/conclusion.xml b/xml/source/conclusion.xml
index 4af30fe..a5621a7 100644
--- a/xml/source/conclusion.xml
+++ b/xml/source/conclusion.xml
@@ -1,4 +1,18 @@
Conclusion
+ We discovered -severity issues during this penetration test.
+
+
+
+ We recommend fixing all of the issues found and then performing a retest in order to ensure
+ that mitigations are effective and that no new vulnerabilities have been introduced.
+ Finally, we want to emphasize that security is a process – this penetration test is just a
+ one-time snapshot. Security posture must be continuously evaluated and improved. Regular audits
+ and ongoing improvements are essential in order to maintain control of your corporate
+ information security. We hope that this pentest report (and the detailed explanations of our
+ findings) will contribute meaningfully towards that end.
+ Please don't hesitate to let us know if you have any further questions, or need further
+ clarification on anything in this report.
+
diff --git a/xml/source/futurework.xml b/xml/source/futurework.xml
index 3b4ef36..fb88f86 100644
--- a/xml/source/futurework.xml
+++ b/xml/source/futurework.xml
@@ -3,9 +3,17 @@
Future Work
-
- Title
-
- Description
+ Retest of findings
+
When mitigations for the vulnerabilities described in this report have been deployed, a
+ repeat test should be performed to ensure that they are effective and have not introduced
+ other security problems.
+ -
+ Regular security assessments
+
Security is an ongoing process and not a product, so we advise undertaking regular
+ security assessments and penetration tests, ideally prior to every major release or every
+ quarter.
+ -
+
diff --git a/xml/source/resultsinanutshell.xml b/xml/source/resultsinanutshell.xml
index 0bc667a..ac38e55 100644
--- a/xml/source/resultsinanutshell.xml
+++ b/xml/source/resultsinanutshell.xml
@@ -1,6 +1,9 @@
Results In A Nutshell
- During this pentest we found findings.
- ...
+ During this penetration test we found -severity
+ issues.
+
+
+ By exploiting these issues, an attacker might be able to .
diff --git a/xml/xslt/off2rep.xsl b/xml/xslt/off2rep.xsl
index 8728687..7e619f9 100644
--- a/xml/xslt/off2rep.xsl
+++ b/xml/xslt/off2rep.xsl
@@ -91,7 +91,8 @@
-
+
@@ -172,7 +173,13 @@
Project objectives
-
+
+ will perform a penetration test with of the
+ . The test is intended to gain insight into the security of
+ . To do so, will access this
+ . and will guide in attempting to find
+ vulnerabilities, and gain further access and elevated privileges by
+ exploiting any vulnerabilities found.
Timeline
@@ -207,9 +214,8 @@
Reconnaissance and Fingerprinting
- We were able to gain information about the
- software and infrastructure through automated scans. Detailed scan output can be found in the sections
- below.
+ We were able to gain information about the software and infrastructure through
+ automated scans. Detailed scan output can be found in the sections below.