The Property Jungle: I'm a security researcher, get me out of here
paul.reviews
paul.reviews
Maybe someone will learn something from this, or maybe not.
Finding sql injection requires active testing of the site which, without authority to test, may fall into a gray area of uk law about whether its in breach of the computer misuse act.
Now you'd hope the company will take this as intended, but some organisations will take being embarassed like this poorly.
Also using public tweets doesn't seem particularly professional to me, to start a discussion on vulnerabilities.
With email, it can be hard to find on a website that isn't just a generic email address that will go to someone who has no clue.
Paul made the effort - TPJ attacked.
His explanation of it veing to find a more accurate email adress is understood, although i would have probably just emailed the default on the site and asked via there.
There's something here about treating someone, even an ignorant idiot (whose only fault is being ignorantly and aggressively presumptuous), with a basic level of professional courtesy. You either foster that basic level of respect or you act like a child in need of attention. I would never hire this security researcher if I read this blog post. Communication is one of our most important skills.
As a consequence of TPJ's attitude - Paul is doing the next best thing of letting TPJ customers know that they are at risk.
Had the company done the right thing and taken him seriously, it would have led to a faster escalation on that basis. He could have immediately emailed the issue and the company would know to expect it and who they're dealing with.
It was probably the easy way to contact them. Paul is right to not want to talk over the phone: Large amount of time + hard to clear explain exact vulnerability to non-technical types.