Live data from Hacker News

Hamed Helped. Help Hamed.

hamedhelped.com

11–20 of 52 posts

Re: Hamed Helped. Help Hamed.

#11
post #10

While Hamed was honorable and didn't try to abuse his exploits, I think it is a stretch to say "Hamed helped". I doubt he tried to get into the data for the purpose of helping make it more secure, it is more likely that he just had the "hacker drive", where he just wanted the challenge of beating a system.

If I'm not mistaking, he discovered the vulnerability while developing an app for its university, then he sent it to the system administrators.

His troubles began when he checked later if the security hole was still opened.

Re: Hamed Helped. Help Hamed.

#12

Earlier quoted context omitted.

http://news.ycombinator.com/item?id=5090007 A few days after reporting the flaw, he got caught using http://www.acunetix.com/ (web vulnerability scanner) on their network. He says he was checking to see if they fixed the flaw. I don't think he was intentionally being malicious, but his explanation doesn't jive with his actions. I still think it sucks that they expelled him. But I am unable to logically see how he did…

I don't understand how using an external attack tool is grounds for anything. If Hamed could use it to search for exploits an attacker could have used it to search for exploits. Especially if a students' information had been previously exposed and the attacker had access to everyone's personal information / passwords! -- Edit : after reading his expulsion letter, it seems he supposedly injected SQL on both occasions.…

Either ways, the solution should be to fix the security system and reward the whistleblower. In a few years, we are going to have millions of teenagers with the competence and ability to pull of what Hamed did. What then?

Re: Hamed Helped. Help Hamed.

#14
post #11
post #10

While Hamed was honorable and didn't try to abuse his exploits, I think it is a stretch to say "Hamed helped". I doubt he tried to get into the data for the purpose of helping make it more secure, it is more likely that he just had the "hacker drive", where he just wanted the challenge of beating a system.

If I'm not mistaking, he discovered the vulnerability while developing an app for its university, then he sent it to the system administrators. His troubles began when he checked later if the security hole was still opened.

Ah, so that means he wasn't even really "hacking". But I still think it is weird that the site calls it him "helping".

Re: Hamed Helped. Help Hamed.

#15

Moral of the story: Sanitise your query params.

I think the moral of the story is - whatever you do anonymize your tracks and do not inform the authorities. There is substantial risk and no reward for acting otherwise.

I think there can be reward in some cases. From what petition website says, he's received several job offers.

Re: Hamed Helped. Help Hamed.

#16
I've read the claims from both sides, I think that although he might have handled it more carefully, it was an overreach to expel him this way, I feel we should stand behind him. I signed the petition. Anyone with counter evidence, please step forward.

Re: Hamed Helped. Help Hamed.

#17
post #8

Earlier quoted context omitted.

Here's his expulsion letter, stating why he was expelled according to the school. http://www.documentcloud.org/documents/560325-al-khabaz-expu...

Translation: On Sept 21st our site was vulnerable to a simple SQL injection attack. On Sept 22nd you documented this information for us. On Oct 26th our site was STILL vulnerable to a simple SQL injection attack. On Oct 29th you again documented this information for us. On Nov 12th we expelled you for our discovering our abysmal security.

I advice everyone to read the original expulsion letter. It is just one page, and the parent's post completely (and I must assume intentionally) twists the facts as mentioned in the letter to make the student look better.

In particular the letter claims that the student has in fact attempted to exploit the SQL injection to gain unauthorized access, and that both notifications to the IT department were made after they detected him and blocked his account.

Re: Hamed Helped. Help Hamed.

#18
post #14
post #11

Earlier quoted context omitted.

If I'm not mistaking, he discovered the vulnerability while developing an app for its university, then he sent it to the system administrators. His troubles began when he checked later if the security hole was still opened.

Ah, so that means he wasn't even really "hacking". But I still think it is weird that the site calls it him "helping".

Basically he did something he shouldn't have/ He Scanned them again after reporting the bug to "see if they had fixed it" (per his claims).

It seems like he had no malicious intent (At least I believe him) but his school and the vendor basically went nuclear on him.

Re: Hamed Helped. Help Hamed.

#19
post #11
post #10

While Hamed was honorable and didn't try to abuse his exploits, I think it is a stretch to say "Hamed helped". I doubt he tried to get into the data for the purpose of helping make it more secure, it is more likely that he just had the "hacker drive", where he just wanted the challenge of beating a system.

If I'm not mistaking, he discovered the vulnerability while developing an app for its university, then he sent it to the system administrators. His troubles began when he checked later if the security hole was still opened.

According to the expulsion letter (linked somewhere in his thread) he only reported the issue after he was detected and his access was blocked. That doesn't prove either sides version but shows why one should get authorization before attempting such a thing. After getting caught anyone can say that they were just trying to help.

Re: Hamed Helped. Help Hamed.

#20
post #8

Earlier quoted context omitted.

Translation: On Sept 21st our site was vulnerable to a simple SQL injection attack. On Sept 22nd you documented this information for us. On Oct 26th our site was STILL vulnerable to a simple SQL injection attack. On Oct 29th you again documented this information for us. On Nov 12th we expelled you for our discovering our abysmal security.

I advice everyone to read the original expulsion letter. It is just one page, and the parent's post completely (and I must assume intentionally) twists the facts as mentioned in the letter to make the student look better. In particular the letter claims that the student has in fact attempted to exploit the SQL injection to gain unauthorized access, and that both notifications to the IT department were made after they…

Actually the letter says nothing about detection and all other sources[1][2] about this matter agree that the 'detection' took the form of a voluntary disclosure, which was rewarded with an NDA demand under threat of arrest.

So it seems you are the one twisting the facts for reasons unknown.

---

[1] "Al-Khabaz immediately alerted the head of information technology for the school about the breach in the Omnivox software used by the college. At first he was thanked for the discovery." -- http://www.thestar.com/news/article/1318163--montreal-studen...

[2] "they discovered that by exchanging other student numbers in the encrypted links, they could easily obtain information such as the social insurance numbers, home addresses and phone numbers of more than 250,000 students. Al-Khabaz said he informed the school’s head of information technology immediately after discovering the vulnerability in the school’s Omnivox software and was congratulated for the discovery." -- http://www.cbc.ca/m/rich/canada/story/2013/01/21/montreal-da...

Post reply on HN