Merge remote-tracking branch 'origin/master'

# Conflicts:
#	xml/RELEASE_NOTES.md
#	xml/source/client_info.xml
#	xml/source/snippets/company_info.xml
#	xml/source/snippets/offerte/en/conditions.xml
#	xml/source/snippets/offerte/en/crystal-box.xml
#	xml/source/snippets/offerte/en/disclaimer.xml
#	xml/source/snippets/offerte/en/disclaimer_code-audit.xml
#	xml/source/snippets/offerte/en/examplewaiver.xml
#	xml/source/snippets/offerte/en/grey-box.xml
#	xml/source/snippets/offerte/en/introandscope.xml
#	xml/source/snippets/offerte/en/introandscope_retest.xml
#	xml/source/snippets/offerte/en/methodology_code-audit.xml
#	xml/source/snippets/offerte/en/prerequisites_training.xml
#	xml/source/snippets/offerte/en/projectoverview.xml
#	xml/source/snippets/offerte/en/projectoverview_retest.xml
#	xml/source/snippets/offerte/en/projectoverview_training.xml
#	xml/source/snippets/offerte/en/teamandreporting.xml
#	xml/xslt/auto.xslt
This commit is contained in:
Marcus Bointon
2017-04-13 11:26:29 +02:00
380 changed files with 62926 additions and 607 deletions
+35 -20
View File
@@ -1,24 +1,39 @@
<?xml version="1.0" encoding="UTF-8"?>
<!-- This file contains all known information for this client. All elements are MANDATORY. If any piece of information is not available, leave the element empty --><!-- Example <invoice_rep></invoice_rep> -->
<!-- This file contains all known information for this client.
All elements are MANDATORY. If any piece of information is not available, leave the element empty
Example <invoice_rep></invoice_rep> -->
<client xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:noNamespaceSchemaLocation="../dtd/offerte.xsd" id="client">
<full_name>Sitting Duck B.V.</full_name>
<!-- long client name, e.g. Sitting Duck B.V. -->
<short_name>Sitting Duck</short_name>
<!-- short client name, e.g. Sitting Duck; if no short name: same as long name -->
<legal_rep>I.M. Portant</legal_rep>
<!-- customer legal representative (to sign offer) -->
<waiver_rep>B.I.G. Wig</waiver_rep>
<!-- customer legal representative (to sign waiver; can be same person as legal_rep) -->
<poc1>Sir Knowsalot</poc1>
<!-- first point of contact for customer (during pentest); can be same person as above -->
<address>Reed Street 42</address>
<postal_code>0000</postal_code>
<city>Pond City</city>
<country>Amazonia</country>
<coc nationality="Dutch">9999999</coc>
<!-- chamber of commerce number; if no chamber of commerce number, please delete the whole element -->
<invoice_rep>D. Ollars</invoice_rep>
<invoice_mail>freemoney@sittingduck.com</invoice_mail>
<vat_no>0000000000B01</vat_no>
<full_name>Sitting Duck B.V.</full_name>
<!-- long client name, e.g. Sitting Duck B.V. -->
<short_name>Sitting Duck</short_name>
<!-- short client name, e.g. Sitting Duck; if no short name: same as long name -->
<legal_rep>I.M. Portant</legal_rep>
<!-- customer legal representative (to sign offer) -->
<waiver_rep>B.I.G. Wig</waiver_rep>
<!-- customer legal representative (to sign waiver; can be same person as legal_rep) -->
<poc1>Sir Knowsalot</poc1>
<!-- first point of contact for customer (during pentest); can be same person as above -->
<address>Reed Street 42</address>
<postal_code>0000</postal_code>
<city>Pond City</city>
<country>Amazonia</country>
<coc nationality="Dutch">9999999</coc>
<!-- chamber of commerce number; if no chamber of commerce number, please delete the whole element -->
<invoice_rep></invoice_rep>
<invoice_mail>freemoney@sittingduck.com</invoice_mail>
<!-- Use the extra field to enter a line requested by the client, such as PO or creditor number, cost centre, internal account number or whatever info they need for their internal administration -->
<invoice_extra_field></invoice_extra_field>
<vat_no>0000000000B01</vat_no>
<rates denomination="eur" lastrevisiondate="2017-03-01">
<rate title="juniorpentester">100</rate>
<rate title="mediorpentester">125</rate>
<rate title="seniorpentester">150</rate>
<rate title="expertpentester">1000</rate>
<rate title="juniormanager">100</rate>
<rate title="seniormanager">125</rate>
</rates>
</client>
+3 -3
View File
@@ -5,9 +5,9 @@
<legal_rep>Melanie Rieback
</legal_rep><!-- ROS legal representative (to sign offerte) -->
<poc1>Melanie Rieback</poc1><!-- first point of contact for ROS -->
<address>Overdiemerweg 28</address>
<postal_code>1111 PP</postal_code>
<city>Diemen</city>
<address>Zieseniskade 21</address>
<postal_code>1017 RT</postal_code>
<city>Amsterdam</city>
<country>The Netherlands</country>
<phone>+31 6 10 21 32 40</phone>
<email>info@radicallyopensecurity.com</email>
+18 -29
View File
@@ -1,32 +1,21 @@
<?xml version="1.0" encoding="UTF-8"?>
<section>
<title>Terms and Conditions</title>
<p>
<company_short/> will only perform the
<company_svc_short/> if it has obtained the permission from
<generate_permission_parties/> as set out in the penetration testing waiver,
attached as <b>Annex 2</b>, or provided in a separate document.
</p>
<p>
<company_short/>
performs this assignment on the basis of its general terms and conditions,
which are attached to this offer as Annex 1.
<company_short/> rejects any general terms and conditions used by
<client_short/>.
</p>
<p>In order to agree to this offer, please sign this letter in duplicate and
return it to:
</p>
<contact>
<name>
<company_legal_rep/>
</name>
<address>
<company_long/>
<br/>Overdiemerweg 28<br/>1111 PP Diemen
</address>
<title>Terms and Conditions</title>
<p><company_short/> will only perform the <company_svc_short/>
if it has obtained the permission from <generate_permission_parties/>
as set out in the penetration testing waiver, attached as <b>Annex 2</b>,
or provided in a separate document.</p>
<p><company_short/> performs this assignment on the basis of its general
terms and conditions, which are attached to this offer as Annex 1.
<company_short/> rejects any general terms and conditions used by
<client_short/>.</p>
<p>In order to agree to this offer, please sign this letter in duplicate
and return it to:</p>
<contact>
<name><company_legal_rep/></name>
<address><company_long/><br/>Overdiemerweg 28<br/>1111 PP Diemen</address>
<email>melanie@radicallyopensecurity.com</email>
</contact>
<generate_offer_signature_box/>
</section>
</contact>
<generate_offer_signature_box/>
</section>
@@ -1,4 +1,4 @@
<?xml version="1.0" encoding="UTF-8"?>
<?xml version="1.0" encoding="UTF-8"?><!--snippet -->
<section id="crystalboxing">
<title>The Crystal-Box Pentesting Method</title>
<p>
@@ -20,4 +20,4 @@
crystal-box pentesting fits naturally hand-in-hand with the "Peek Over Our
Shoulder" option that <company_short/> offers to <client_short/>.
</p>
</section>
</section><!-- end of template -->
@@ -7,6 +7,7 @@
<company_short/>, instead, has an obligation to make reasonable efforts (in
Dutch: “<i>inspanningsverplichting</i>”) to perform the agreed services.
</p>
<p>
<company_short/> and <client_short/>
agree to take reasonable measures to maintain the confidentiality of
@@ -8,8 +8,11 @@
<company_short/>, instead, has an obligation to make reasonable efforts (in
Dutch: “<i>inspanningsverplichting</i>”) to perform the agreed services.
</p>
<p>
<company_short/> and <client_short/>
<company_short/>
and
<client_short/>
agree to take reasonable measures to maintain the confidentiality of
information and any personal data they gain access to in the course of
performing the code audit. Both parties will use the information and data
@@ -1,6 +1,7 @@
<?xml version="1.0" encoding="UTF-8"?>
<section id="waiver-example">
<title>ANNEX 2 Example Pentest Waiver</title>
<p>
<b><i>(Full Client Name)</i> (“<i>(Client)</i>”)</b>, with its registered
office at Somestreet, Somecity, Earth, Milkyway, and duly represented by
+7 -7
View File
@@ -2,13 +2,13 @@
<section id="greyboxing">
<title>The Grey-Box Pentesting Method</title>
<p>
Crystal-Box vs. Black-Box pentesting refers to the amount of information
regarding the target environment, architecture, and/or applications that is
initially shared by the customer with the pentesters. With Black-Box
testing, pentesters are given no information whatsoever about the target(s).
With Crystal-Box testing, pentesters are given all information requested
about the target(s), including source-code (when relevant), access to
developers or system management, etc..
<!--snippet -->Crystal-Box vs. Black-Box pentesting refers to the amount of
information regarding the target environment, architecture, and/or
applications that is initially shared by the customer with the pentesters.
With Black-Box testing, pentesters are given no information whatsoever about
the target(s). With Crystal-Box testing, pentesters are given all
information requested about the target(s), including source-code (when
relevant), access to developers or system management, etc..
</p>
<p>
<company_short/>
@@ -1,17 +1,12 @@
<?xml version="1.0" encoding="UTF-8"?>
<section>
<title>Introduction</title>
<p>
<client_long/> (hereafter “<b><client_short/></b>”), with its registered office at
<client_street/>, <client_city/>, <client_country/>, has requested <company_long/>
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.
</p>
<p>
The motivation for this request is that <client_short/> wishes to gain better
insight into ...
</p>
<p><client_long/> (hereafter “<b><client_short/></b>”), with its registered office
at <client_street/>, <client_city/>, <client_country/>, has requested <company_long/>
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.
The motivation for this request is that <client_short/> wishes to get a better
insight into ...</p>
<p>This offer sets out the scope of the work and the terms and conditions
under which <company_short/> will perform these services.
</p>
<p>This offer sets out the scope of the work and the terms and conditions under
which <company_short/> will perform these services.</p>
</section>
@@ -4,12 +4,11 @@
<p>
<client_long/> (hereafter “<b><client_short/></b>”), with its registered office at
<client_street/>, <client_city/>, <client_country/>, has requested <company_long/>
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.
</p>
<p>The motivation for this request is that <client_short/> has had a recent penetration
test done by <company_short/> and wishes to check that the vulnerabilities found
have been mitigated.
</p>
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.</p>
<p>The motivation for this request is that <client_short/> has had a recent penetration
test done by <company_short/> and wishes to check that the vulnerabilities found
have been mitigated.
</p>
<p>This offer sets out the scope of the work and the terms and conditions
under which <company_short/> will perform these services.
@@ -10,8 +10,8 @@
impact on the Confidentiality, Integrity and Availability (CIA) of the
system. We will describe how an attacker would exploit the vulnerability and
suggest ways of fixing it.
</p>
<p>This requires an extensive knowledge of the platform the application is
<br/>
This requires an extensive knowledge of the platform the application is
running on, as well as the extensive knowledge of the language the
application in written in and patterns that have been used. Therefore a code
audit done by highly-trained specialists with a strong background in
@@ -21,7 +21,7 @@
During the code audit, we take the following approach:
</p>
<ol>
<li><b>Thorough comprehension of functionality</b>
<li>Thorough comprehension of functionality
<br/>
We try to get a thorough comprehension of how the application works and
how it interacts with the user and other systems. Having detailed
@@ -29,7 +29,7 @@
documentation) at this stage is very helpful, as they aid the
understanding of the application
</li>
<li><b>Static analysis</b>
<li>Static analysis
<br/>
Using the understanding we gained in the previous step, we will use static
code analysis to uncover any vulnerabilities. Static analysis means the
@@ -47,7 +47,7 @@
assessing the quality of the security measures.
</li>
<li><b>Dynamic analysis</b>
<li>Dynamic analysis
<br/>
Dynamic analysis can also be performed. In this case, the program is run
and actively exploited by the specialist. This is usually done to confirm
@@ -2,7 +2,7 @@
<section>
<title>Prerequisites</title>
<p>In order to provide training, <company_short/> will need to:</p>
<!-- Example of most common scenario, change if necessary -->
<!--Example of most common scenario, change if necessary!! :-->
<ul>
<li>Develop training materials</li>
<li>Book an appropriate venue</li>
@@ -1,5 +1,6 @@
<?xml version="1.0" encoding="UTF-8"?>
<section>
<!-- section with an overview of ROS activities -->
<title>Project Overview</title>
<p>
<company_short/> will perform <company_svc_long/> for <client_short/>
@@ -1,5 +1,6 @@
<?xml version="1.0" encoding="UTF-8"?>
<section>
<!-- section with an overview of ROS activities -->
<title>Project Overview</title>
<p>
<company_short/> will perform <company_svc_long/> for <client_short/>
@@ -1,7 +1,7 @@
<?xml version="1.0" encoding="UTF-8"?>
<section>
<title>Project Overview
</title>
</title><!-- section with an overview of ROS activities -->
<p>
<company_short/>
will provide xxx training sessions, for xxx different groups,
@@ -20,6 +20,7 @@
<!-- remove this for non pentesting offers-->
<p>The workflow of our penetration testing team is modeled on that of a
Capture The Flag (CTF) team:
<!-- remove this for non pentesting offers-->
<company_long/> has a geographically distributed team and we use online
infrastructure (RocketChat, GitLabs, etc.) to coordinate our work. This
+31
View File
@@ -0,0 +1,31 @@
<?xml version="1.0" encoding="UTF-8"?>
<ratecard xml:lang="en" xmlns:xi="http://www.w3.org/2001/XInclude" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="../../../dtd/ratecard.xsd">
<meta>
<xi:include href="../company_info.xml"/>
<xi:include href="../../client_info.xml"/>
</meta>
<title><company_long/><br/>&#160;<br/>SERVICES RATE CARD FOR <client_long/></title>
<div class="important"><generate_raterevisiondate/></div>
<p>For <client_long/> we have the following hourly rates:</p>
<table cols="10mm 80mm 30mm">
<tr><td></td><td>Junior pentester:</td><td><client_rate title="juniorpentester"/></td></tr>
<tr><td></td><td>Medior pentester:</td><td><client_rate title="mediorpentester"/></td></tr>
<tr><td></td><td>Senior pentester:</td><td><client_rate title="seniorpentester"/></td></tr>
<tr><td></td><td>Expert pentester<fnref>Only on special requests by, and after discussion with and
approval of, <client_short/></fnref>:</td><td><client_rate title="expertpentester"/></td></tr>
<tr><td></td><td>Junior project and account manager<fnref>Tasks of a project and account manager include
support in client contact, writing pentest reports, presenting findings and
conclusions, communication with team, etc.</fnref>:</td><td><client_rate title="juniormanager"/></td></tr>
<tr><td></td><td>Senior project and account manager:</td><td><client_rate title="seniormanager"/></td></tr>
</table>
<p><company_long/>'s hourly rates are excluding VAT and out-of-pocket expenses and depend upon
the exact service or area of expertise.</p>
<p>Typically, a pentesting team is composed of two pentesters and one project/account manager. The actual team composition and price naturally depends on the length of the pentest and the complexity of the tasks, and will be determined in close consultation with <client_short/> on a per-assignment basis.</p>
<p>
<company_long/>
<br/>
<company_poc1/> - Director</p>
</ratecard>