Is it possible to be a "white hat" hacker if you weren't actually contracted by the target for penetration testing?
There is obviously a spectrum to this sort of thing, but I know of many people that will just habitually enter javascript alerts into a web services's forms to see what happens. Mostly this is just to evaluate the product and to see if it is trustworthy, but they'll often send along a polite FYI to the site owners letting them know if they have security issues that need addressing. Actions like that: finding vulnerab…
It sucks, but if your goal is to avoid legal drama, don't test without permission.