Merge remote-tracking branch 'origin/master'
# Conflicts: # xml/RELEASE_NOTES.md # xml/source/client_info.xml # xml/source/snippets/company_info.xml # xml/source/snippets/offerte/en/conditions.xml # xml/source/snippets/offerte/en/crystal-box.xml # xml/source/snippets/offerte/en/disclaimer.xml # xml/source/snippets/offerte/en/disclaimer_code-audit.xml # xml/source/snippets/offerte/en/examplewaiver.xml # xml/source/snippets/offerte/en/grey-box.xml # xml/source/snippets/offerte/en/introandscope.xml # xml/source/snippets/offerte/en/introandscope_retest.xml # xml/source/snippets/offerte/en/methodology_code-audit.xml # xml/source/snippets/offerte/en/prerequisites_training.xml # xml/source/snippets/offerte/en/projectoverview.xml # xml/source/snippets/offerte/en/projectoverview_retest.xml # xml/source/snippets/offerte/en/projectoverview_training.xml # xml/source/snippets/offerte/en/teamandreporting.xml # xml/xslt/auto.xslt
This commit is contained in:
+35
-20
@@ -1,24 +1,39 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!-- This file contains all known information for this client. All elements are MANDATORY. If any piece of information is not available, leave the element empty --><!-- Example <invoice_rep></invoice_rep> -->
|
||||
<!-- This file contains all known information for this client.
|
||||
|
||||
All elements are MANDATORY. If any piece of information is not available, leave the element empty
|
||||
|
||||
Example <invoice_rep></invoice_rep> -->
|
||||
|
||||
<client xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
|
||||
xsi:noNamespaceSchemaLocation="../dtd/offerte.xsd" id="client">
|
||||
<full_name>Sitting Duck B.V.</full_name>
|
||||
<!-- long client name, e.g. Sitting Duck B.V. -->
|
||||
<short_name>Sitting Duck</short_name>
|
||||
<!-- short client name, e.g. Sitting Duck; if no short name: same as long name -->
|
||||
<legal_rep>I.M. Portant</legal_rep>
|
||||
<!-- customer legal representative (to sign offer) -->
|
||||
<waiver_rep>B.I.G. Wig</waiver_rep>
|
||||
<!-- customer legal representative (to sign waiver; can be same person as legal_rep) -->
|
||||
<poc1>Sir Knowsalot</poc1>
|
||||
<!-- first point of contact for customer (during pentest); can be same person as above -->
|
||||
<address>Reed Street 42</address>
|
||||
<postal_code>0000</postal_code>
|
||||
<city>Pond City</city>
|
||||
<country>Amazonia</country>
|
||||
<coc nationality="Dutch">9999999</coc>
|
||||
<!-- chamber of commerce number; if no chamber of commerce number, please delete the whole element -->
|
||||
<invoice_rep>D. Ollars</invoice_rep>
|
||||
<invoice_mail>freemoney@sittingduck.com</invoice_mail>
|
||||
<vat_no>0000000000B01</vat_no>
|
||||
<full_name>Sitting Duck B.V.</full_name>
|
||||
<!-- long client name, e.g. Sitting Duck B.V. -->
|
||||
<short_name>Sitting Duck</short_name>
|
||||
<!-- short client name, e.g. Sitting Duck; if no short name: same as long name -->
|
||||
<legal_rep>I.M. Portant</legal_rep>
|
||||
<!-- customer legal representative (to sign offer) -->
|
||||
<waiver_rep>B.I.G. Wig</waiver_rep>
|
||||
<!-- customer legal representative (to sign waiver; can be same person as legal_rep) -->
|
||||
<poc1>Sir Knowsalot</poc1>
|
||||
<!-- first point of contact for customer (during pentest); can be same person as above -->
|
||||
<address>Reed Street 42</address>
|
||||
<postal_code>0000</postal_code>
|
||||
<city>Pond City</city>
|
||||
<country>Amazonia</country>
|
||||
<coc nationality="Dutch">9999999</coc>
|
||||
<!-- chamber of commerce number; if no chamber of commerce number, please delete the whole element -->
|
||||
<invoice_rep></invoice_rep>
|
||||
<invoice_mail>freemoney@sittingduck.com</invoice_mail>
|
||||
<!-- Use the extra field to enter a line requested by the client, such as PO or creditor number, cost centre, internal account number or whatever info they need for their internal administration -->
|
||||
<invoice_extra_field></invoice_extra_field>
|
||||
<vat_no>0000000000B01</vat_no>
|
||||
<rates denomination="eur" lastrevisiondate="2017-03-01">
|
||||
<rate title="juniorpentester">100</rate>
|
||||
<rate title="mediorpentester">125</rate>
|
||||
<rate title="seniorpentester">150</rate>
|
||||
<rate title="expertpentester">1000</rate>
|
||||
<rate title="juniormanager">100</rate>
|
||||
<rate title="seniormanager">125</rate>
|
||||
</rates>
|
||||
</client>
|
||||
|
||||
@@ -5,9 +5,9 @@
|
||||
<legal_rep>Melanie Rieback
|
||||
</legal_rep><!-- ROS legal representative (to sign offerte) -->
|
||||
<poc1>Melanie Rieback</poc1><!-- first point of contact for ROS -->
|
||||
<address>Overdiemerweg 28</address>
|
||||
<postal_code>1111 PP</postal_code>
|
||||
<city>Diemen</city>
|
||||
<address>Zieseniskade 21</address>
|
||||
<postal_code>1017 RT</postal_code>
|
||||
<city>Amsterdam</city>
|
||||
<country>The Netherlands</country>
|
||||
<phone>+31 6 10 21 32 40</phone>
|
||||
<email>info@radicallyopensecurity.com</email>
|
||||
|
||||
@@ -1,32 +1,21 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<section>
|
||||
<title>Terms and Conditions</title>
|
||||
<p>
|
||||
<company_short/> will only perform the
|
||||
<company_svc_short/> if it has obtained the permission from
|
||||
<generate_permission_parties/> as set out in the penetration testing waiver,
|
||||
attached as <b>Annex 2</b>, or provided in a separate document.
|
||||
</p>
|
||||
|
||||
<p>
|
||||
<company_short/>
|
||||
performs this assignment on the basis of its general terms and conditions,
|
||||
which are attached to this offer as Annex 1.
|
||||
<company_short/> rejects any general terms and conditions used by
|
||||
<client_short/>.
|
||||
</p>
|
||||
<p>In order to agree to this offer, please sign this letter in duplicate and
|
||||
return it to:
|
||||
</p>
|
||||
<contact>
|
||||
<name>
|
||||
<company_legal_rep/>
|
||||
</name>
|
||||
<address>
|
||||
<company_long/>
|
||||
<br/>Overdiemerweg 28<br/>1111 PP Diemen
|
||||
</address>
|
||||
<title>Terms and Conditions</title>
|
||||
<p><company_short/> will only perform the <company_svc_short/>
|
||||
if it has obtained the permission from <generate_permission_parties/>
|
||||
as set out in the penetration testing waiver, attached as <b>Annex 2</b>,
|
||||
or provided in a separate document.</p>
|
||||
|
||||
<p><company_short/> performs this assignment on the basis of its general
|
||||
terms and conditions, which are attached to this offer as Annex 1.
|
||||
<company_short/> rejects any general terms and conditions used by
|
||||
<client_short/>.</p>
|
||||
<p>In order to agree to this offer, please sign this letter in duplicate
|
||||
and return it to:</p>
|
||||
<contact>
|
||||
<name><company_legal_rep/></name>
|
||||
<address><company_long/><br/>Overdiemerweg 28<br/>1111 PP Diemen</address>
|
||||
<email>melanie@radicallyopensecurity.com</email>
|
||||
</contact>
|
||||
<generate_offer_signature_box/>
|
||||
</section>
|
||||
</contact>
|
||||
<generate_offer_signature_box/>
|
||||
</section>
|
||||
@@ -1,4 +1,4 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<?xml version="1.0" encoding="UTF-8"?><!--snippet -->
|
||||
<section id="crystalboxing">
|
||||
<title>The Crystal-Box Pentesting Method</title>
|
||||
<p>
|
||||
@@ -20,4 +20,4 @@
|
||||
crystal-box pentesting fits naturally hand-in-hand with the "Peek Over Our
|
||||
Shoulder" option that <company_short/> offers to <client_short/>.
|
||||
</p>
|
||||
</section>
|
||||
</section><!-- end of template -->
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
<company_short/>, instead, has an obligation to make reasonable efforts (in
|
||||
Dutch: “<i>inspanningsverplichting</i>”) to perform the agreed services.
|
||||
</p>
|
||||
|
||||
<p>
|
||||
<company_short/> and <client_short/>
|
||||
agree to take reasonable measures to maintain the confidentiality of
|
||||
|
||||
@@ -8,8 +8,11 @@
|
||||
<company_short/>, instead, has an obligation to make reasonable efforts (in
|
||||
Dutch: “<i>inspanningsverplichting</i>”) to perform the agreed services.
|
||||
</p>
|
||||
|
||||
<p>
|
||||
<company_short/> and <client_short/>
|
||||
<company_short/>
|
||||
and
|
||||
<client_short/>
|
||||
agree to take reasonable measures to maintain the confidentiality of
|
||||
information and any personal data they gain access to in the course of
|
||||
performing the code audit. Both parties will use the information and data
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<section id="waiver-example">
|
||||
<title>ANNEX 2 Example Pentest Waiver</title>
|
||||
|
||||
<p>
|
||||
<b><i>(Full Client Name)</i> (“<i>(Client)</i>”)</b>, with its registered
|
||||
office at Somestreet, Somecity, Earth, Milkyway, and duly represented by
|
||||
|
||||
@@ -2,13 +2,13 @@
|
||||
<section id="greyboxing">
|
||||
<title>The Grey-Box Pentesting Method</title>
|
||||
<p>
|
||||
Crystal-Box vs. Black-Box pentesting refers to the amount of information
|
||||
regarding the target environment, architecture, and/or applications that is
|
||||
initially shared by the customer with the pentesters. With Black-Box
|
||||
testing, pentesters are given no information whatsoever about the target(s).
|
||||
With Crystal-Box testing, pentesters are given all information requested
|
||||
about the target(s), including source-code (when relevant), access to
|
||||
developers or system management, etc..
|
||||
<!--snippet -->Crystal-Box vs. Black-Box pentesting refers to the amount of
|
||||
information regarding the target environment, architecture, and/or
|
||||
applications that is initially shared by the customer with the pentesters.
|
||||
With Black-Box testing, pentesters are given no information whatsoever about
|
||||
the target(s). With Crystal-Box testing, pentesters are given all
|
||||
information requested about the target(s), including source-code (when
|
||||
relevant), access to developers or system management, etc..
|
||||
</p>
|
||||
<p>
|
||||
<company_short/>
|
||||
|
||||
@@ -1,17 +1,12 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<section>
|
||||
<title>Introduction</title>
|
||||
<p>
|
||||
<client_long/> (hereafter “<b><client_short/></b>”), with its registered office at
|
||||
<client_street/>, <client_city/>, <client_country/>, has requested <company_long/>
|
||||
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.
|
||||
</p>
|
||||
<p>
|
||||
The motivation for this request is that <client_short/> wishes to gain better
|
||||
insight into ...
|
||||
</p>
|
||||
<p><client_long/> (hereafter “<b><client_short/></b>”), with its registered office
|
||||
at <client_street/>, <client_city/>, <client_country/>, has requested <company_long/>
|
||||
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.
|
||||
The motivation for this request is that <client_short/> wishes to get a better
|
||||
insight into ...</p>
|
||||
|
||||
<p>This offer sets out the scope of the work and the terms and conditions
|
||||
under which <company_short/> will perform these services.
|
||||
</p>
|
||||
<p>This offer sets out the scope of the work and the terms and conditions under
|
||||
which <company_short/> will perform these services.</p>
|
||||
</section>
|
||||
@@ -4,12 +4,11 @@
|
||||
<p>
|
||||
<client_long/> (hereafter “<b><client_short/></b>”), with its registered office at
|
||||
<client_street/>, <client_city/>, <client_country/>, has requested <company_long/>
|
||||
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.
|
||||
</p>
|
||||
<p>The motivation for this request is that <client_short/> has had a recent penetration
|
||||
test done by <company_short/> and wishes to check that the vulnerabilities found
|
||||
have been mitigated.
|
||||
</p>
|
||||
(hereafter “<b><company_short/></b>”) to perform <company_svc_long/>.</p>
|
||||
<p>The motivation for this request is that <client_short/> has had a recent penetration
|
||||
test done by <company_short/> and wishes to check that the vulnerabilities found
|
||||
have been mitigated.
|
||||
</p>
|
||||
|
||||
<p>This offer sets out the scope of the work and the terms and conditions
|
||||
under which <company_short/> will perform these services.
|
||||
|
||||
@@ -10,8 +10,8 @@
|
||||
impact on the Confidentiality, Integrity and Availability (CIA) of the
|
||||
system. We will describe how an attacker would exploit the vulnerability and
|
||||
suggest ways of fixing it.
|
||||
</p>
|
||||
<p>This requires an extensive knowledge of the platform the application is
|
||||
<br/>
|
||||
This requires an extensive knowledge of the platform the application is
|
||||
running on, as well as the extensive knowledge of the language the
|
||||
application in written in and patterns that have been used. Therefore a code
|
||||
audit done by highly-trained specialists with a strong background in
|
||||
@@ -21,7 +21,7 @@
|
||||
During the code audit, we take the following approach:
|
||||
</p>
|
||||
<ol>
|
||||
<li><b>Thorough comprehension of functionality</b>
|
||||
<li>Thorough comprehension of functionality
|
||||
<br/>
|
||||
We try to get a thorough comprehension of how the application works and
|
||||
how it interacts with the user and other systems. Having detailed
|
||||
@@ -29,7 +29,7 @@
|
||||
documentation) at this stage is very helpful, as they aid the
|
||||
understanding of the application
|
||||
</li>
|
||||
<li><b>Static analysis</b>
|
||||
<li>Static analysis
|
||||
<br/>
|
||||
Using the understanding we gained in the previous step, we will use static
|
||||
code analysis to uncover any vulnerabilities. Static analysis means the
|
||||
@@ -47,7 +47,7 @@
|
||||
assessing the quality of the security measures.
|
||||
</li>
|
||||
|
||||
<li><b>Dynamic analysis</b>
|
||||
<li>Dynamic analysis
|
||||
<br/>
|
||||
Dynamic analysis can also be performed. In this case, the program is run
|
||||
and actively exploited by the specialist. This is usually done to confirm
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
<section>
|
||||
<title>Prerequisites</title>
|
||||
<p>In order to provide training, <company_short/> will need to:</p>
|
||||
<!-- Example of most common scenario, change if necessary -->
|
||||
<!--Example of most common scenario, change if necessary!! :-->
|
||||
<ul>
|
||||
<li>Develop training materials</li>
|
||||
<li>Book an appropriate venue</li>
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<section>
|
||||
<!-- section with an overview of ROS activities -->
|
||||
<title>Project Overview</title>
|
||||
<p>
|
||||
<company_short/> will perform <company_svc_long/> for <client_short/>
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<section>
|
||||
<!-- section with an overview of ROS activities -->
|
||||
<title>Project Overview</title>
|
||||
<p>
|
||||
<company_short/> will perform <company_svc_long/> for <client_short/>
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<section>
|
||||
<title>Project Overview
|
||||
</title>
|
||||
</title><!-- section with an overview of ROS activities -->
|
||||
<p>
|
||||
<company_short/>
|
||||
will provide xxx training sessions, for xxx different groups,
|
||||
|
||||
@@ -20,6 +20,7 @@
|
||||
<!-- remove this for non pentesting offers-->
|
||||
<p>The workflow of our penetration testing team is modeled on that of a
|
||||
Capture The Flag (CTF) team:
|
||||
<!-- remove this for non pentesting offers-->
|
||||
|
||||
<company_long/> has a geographically distributed team and we use online
|
||||
infrastructure (RocketChat, GitLabs, etc.) to coordinate our work. This
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
|
||||
<ratecard xml:lang="en" xmlns:xi="http://www.w3.org/2001/XInclude" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="../../../dtd/ratecard.xsd">
|
||||
<meta>
|
||||
<xi:include href="../company_info.xml"/>
|
||||
<xi:include href="../../client_info.xml"/>
|
||||
</meta>
|
||||
<title><company_long/><br/> <br/>SERVICES RATE CARD FOR <client_long/></title>
|
||||
<div class="important"><generate_raterevisiondate/></div>
|
||||
<p>For <client_long/> we have the following hourly rates:</p>
|
||||
<table cols="10mm 80mm 30mm">
|
||||
<tr><td>•</td><td>Junior pentester:</td><td><client_rate title="juniorpentester"/></td></tr>
|
||||
<tr><td>•</td><td>Medior pentester:</td><td><client_rate title="mediorpentester"/></td></tr>
|
||||
<tr><td>•</td><td>Senior pentester:</td><td><client_rate title="seniorpentester"/></td></tr>
|
||||
<tr><td>•</td><td>Expert pentester<fnref>Only on special requests by, and after discussion with and
|
||||
approval of, <client_short/></fnref>:</td><td><client_rate title="expertpentester"/></td></tr>
|
||||
<tr><td>•</td><td>Junior project and account manager<fnref>Tasks of a project and account manager include
|
||||
support in client contact, writing pentest reports, presenting findings and
|
||||
conclusions, communication with team, etc.</fnref>:</td><td><client_rate title="juniormanager"/></td></tr>
|
||||
<tr><td>•</td><td>Senior project and account manager:</td><td><client_rate title="seniormanager"/></td></tr>
|
||||
</table>
|
||||
|
||||
|
||||
<p><company_long/>'s hourly rates are excluding VAT and out-of-pocket expenses and depend upon
|
||||
the exact service or area of expertise.</p>
|
||||
<p>Typically, a pentesting team is composed of two pentesters and one project/account manager. The actual team composition and price naturally depends on the length of the pentest and the complexity of the tasks, and will be determined in close consultation with <client_short/> on a per-assignment basis.</p>
|
||||
<p>
|
||||
<company_long/>
|
||||
<br/>
|
||||
<company_poc1/> - Director</p>
|
||||
</ratecard>
|
||||
Reference in New Issue
Block a user