http://www.documentcloud.org/documents/560325-al-khabaz-expu...
http://www.documentcloud.org/documents/560325-al-khabaz-expu...
On Sept 21st our site was vulnerable to a simple SQL injection attack. On Sept 22nd you documented this information for us.
On Oct 26th our site was STILL vulnerable to a simple SQL injection attack. On Oct 29th you again documented this information for us.
On Nov 12th we expelled you for our discovering our abysmal security.
In particular the letter claims that the student has in fact attempted to exploit the SQL injection to gain unauthorized access, and that both notifications to the IT department were made after they detected him and blocked his account.
So it seems you are the one twisting the facts for reasons unknown.
---
[1] "Al-Khabaz immediately alerted the head of information technology for the school about the breach in the Omnivox software used by the college. At first he was thanked for the discovery." -- http://www.thestar.com/news/article/1318163--montreal-studen...
[2] "they discovered that by exchanging other student numbers in the encrypted links, they could easily obtain information such as the social insurance numbers, home addresses and phone numbers of more than 250,000 students. Al-Khabaz said he informed the school’s head of information technology immediately after discovering the vulnerability in the school’s Omnivox software and was congratulated for the discovery." -- http://www.cbc.ca/m/rich/canada/story/2013/01/21/montreal-da...
Read point 3: "On September 22, you admitted to these attacks in writing."
Compare the dates. According to the letter, his disclosure came after the account was suspended. Implying that they did detect the attack before he admitted to it.
You're using uncorroborated dates in a document that's clearly worded to paint the student in the worst light possible to infer a 'detection' which it doesn't mention and for which there is no evidence. You're then sharing your inference as documented fact. That's a smear.
The letter doesn't say that. No other sources say that. You're the only one saying that.
I never said that it was not a case of responsible disclosure. I simply don't know, the evidence at this point seems insufficient to support either conclusion.
The first application of the IT Policy is the interesting one here, as it lays the foundation for - or undermines Hamed's case as a white hat.