If you could see the email, look at the email headers. It should indicate what IP address and email program sent the email, as in, it may say SQLMail and it IP of the machine.
All-in-all, the fact that he mentions he exploited security hole in his company and then calls it "SQL thing" screams at me: FAKE
Why? That doesn't surprise me at all. As a (Computer Science) student, there were a lot of jokes (e.g. connecting to other computers, and doing... stuff) involving scripts that most people just blindly copied, without understanding them at all. And I have seen the same last year during an internship.