Live data from Hacker News

Hamed Helped. Help Hamed.

hamedhelped.com

21–30 of 52 posts

Re: Hamed Helped. Help Hamed.

#21
post #3

What's the truth here? What did Hamed "do"? Exposing a security flaw doesn't get you expelled. He had to have taken it one or more steps too far. I'd like to see the facts.

http://news.ycombinator.com/item?id=5090007 A few days after reporting the flaw, he got caught using http://www.acunetix.com/ (web vulnerability scanner) on their network. He says he was checking to see if they fixed the flaw. I don't think he was intentionally being malicious, but his explanation doesn't jive with his actions. I still think it sucks that they expelled him. But I am unable to logically see how he did…

> but his explanation doesn't jive with his actions.

I think it's perfectly congruent. An entity has your data as well as information on many other people. You come across and report a vunerability. You check that something was done about it. I see no holes in this (aside from the ones in Montreal college's security).

Re: Hamed Helped. Help Hamed.

#22
post #11

Earlier quoted context omitted.

If I'm not mistaking, he discovered the vulnerability while developing an app for its university, then he sent it to the system administrators. His troubles began when he checked later if the security hole was still opened.

According to the expulsion letter (linked somewhere in his thread) he only reported the issue after he was detected and his access was blocked. That doesn't prove either sides version but shows why one should get authorization before attempting such a thing. After getting caught anyone can say that they were just trying to help.

The letter says no such thing. I don't know why you've taken the trouble to post this falsehood twice in a short thread.

http://news.ycombinator.com/item?id=5096170

Re: Hamed Helped. Help Hamed.

#23
post #20

Earlier quoted context omitted.

I advice everyone to read the original expulsion letter. It is just one page, and the parent's post completely (and I must assume intentionally) twists the facts as mentioned in the letter to make the student look better. In particular the letter claims that the student has in fact attempted to exploit the SQL injection to gain unauthorized access, and that both notifications to the IT department were made after they…

Actually the letter says nothing about detection and all other sources[1][2] about this matter agree that the 'detection' took the form of a voluntary disclosure, which was rewarded with an NDA demand under threat of arrest. So it seems you are the one twisting the facts for reasons unknown. --- [1] "Al-Khabaz immediately alerted the head of information technology for the school about the breach in the Omnivox softwa…

Read point 2: "On September 21, the IT Policy was applied and your network and portal accesses were suspended."

Read point 3: "On September 22, you admitted to these attacks in writing."

Compare the dates. According to the letter, his disclosure came after the account was suspended. Implying that they did detect the attack before he admitted to it.

Re: Hamed Helped. Help Hamed.

#24
Look, this is fairly simple.

The names of the top people at Dawson 'College'?

  Richard Filion, Director General, Dawson College
  Robert Kavanagh, Academic Dean, Dawson College
  Diane Gauvin, Dean, Social Science & Business Technology, Dawson College
  Ken Fogel, Chairperson, Department of Computer Science, Dawson College
  François Paradis, Director of Information Services and Technology, Dawson College
The name of the supposed 'perpetrator'?

  Hamed Al-Khabaz
I'd bet an insane amount of money that if the guy had been named something like Stéfane Latrimou, he'd have gotten off far more lightly.

Re: Hamed Helped. Help Hamed.

#25
post #3

What's the truth here? What did Hamed "do"? Exposing a security flaw doesn't get you expelled. He had to have taken it one or more steps too far. I'd like to see the facts.

http://news.ycombinator.com/item?id=5090007 A few days after reporting the flaw, he got caught using http://www.acunetix.com/ (web vulnerability scanner) on their network. He says he was checking to see if they fixed the flaw. I don't think he was intentionally being malicious, but his explanation doesn't jive with his actions. I still think it sucks that they expelled him. But I am unable to logically see how he did…

It sounds like he's being screwed over by the vendor, who forced him to sign an NDA.

To be honest anyone using Acunetix isn't looking to hack into anything. It's an enterprise scanner that looks for general web app issues rather than something that's typically used to conduct actual attacks. You'd expect an actual attack to be conducted with a tool like Havij, Sqlmap, Burp or Zap proxy.

Re: Hamed Helped. Help Hamed.

#26
post #20

Earlier quoted context omitted.

Actually the letter says nothing about detection and all other sources[1][2] about this matter agree that the 'detection' took the form of a voluntary disclosure, which was rewarded with an NDA demand under threat of arrest. So it seems you are the one twisting the facts for reasons unknown. --- [1] "Al-Khabaz immediately alerted the head of information technology for the school about the breach in the Omnivox softwa…

Read point 2: "On September 21, the IT Policy was applied and your network and portal accesses were suspended." Read point 3: "On September 22, you admitted to these attacks in writing." Compare the dates. According to the letter, his disclosure came after the account was suspended. Implying that they did detect the attack before he admitted to it.

An admission in writing is not the same thing as a disclosure.

You're using uncorroborated dates in a document that's clearly worded to paint the student in the worst light possible to infer a 'detection' which it doesn't mention and for which there is no evidence. You're then sharing your inference as documented fact. That's a smear.

Re: Hamed Helped. Help Hamed.

#27
post #15

Earlier quoted context omitted.

I think the moral of the story is - whatever you do anonymize your tracks and do not inform the authorities. There is substantial risk and no reward for acting otherwise.

I think there can be reward in some cases. From what petition website says, he's received several job offers.

This is a great comment for ShitHnSays.

Re: Hamed Helped. Help Hamed.

#28
post #26

Earlier quoted context omitted.

Read point 2: "On September 21, the IT Policy was applied and your network and portal accesses were suspended." Read point 3: "On September 22, you admitted to these attacks in writing." Compare the dates. According to the letter, his disclosure came after the account was suspended. Implying that they did detect the attack before he admitted to it.

An admission in writing is not the same thing as a disclosure. You're using uncorroborated dates in a document that's clearly worded to paint the student in the worst light possible to infer a 'detection' which it doesn't mention and for which there is no evidence. You're then sharing your inference as documented fact. That's a smear.

I was merely communicating the content of the letter. Whether its claim or the contradicting ones of the student are true, I don't know. What I do know is that mrtron's "translation" of the letter conveniently leaves out the actual exploitation of the SQL injection and the blocking of the account that are claimed to have happened in the letter, and is therefore completely unfit as a summary of the letter.

Re: Hamed Helped. Help Hamed.

#29
post #26

Earlier quoted context omitted.

An admission in writing is not the same thing as a disclosure. You're using uncorroborated dates in a document that's clearly worded to paint the student in the worst light possible to infer a 'detection' which it doesn't mention and for which there is no evidence. You're then sharing your inference as documented fact. That's a smear.

I was merely communicating the content of the letter. Whether its claim or the contradicting ones of the student are true, I don't know. What I do know is that mrtron's "translation" of the letter conveniently leaves out the actual exploitation of the SQL injection and the blocking of the account that are claimed to have happened in the letter, and is therefore completely unfit as a summary of the letter.

Sorry but that's bullshit. What you've said is that the guy simply got caught and therefore this was not a case of responsible disclosure.

The letter doesn't say that. No other sources say that. You're the only one saying that.

Re: Hamed Helped. Help Hamed.

#30
post #29

Earlier quoted context omitted.

I was merely communicating the content of the letter. Whether its claim or the contradicting ones of the student are true, I don't know. What I do know is that mrtron's "translation" of the letter conveniently leaves out the actual exploitation of the SQL injection and the blocking of the account that are claimed to have happened in the letter, and is therefore completely unfit as a summary of the letter.

Sorry but that's bullshit. What you've said is that the guy simply got caught and therefore this was not a case of responsible disclosure. The letter doesn't say that. No other sources say that. You're the only one saying that.

I did read the blocking of his account to mean that he was detected in some form. You may not agree with my reading of that letter, and I certainly don't agree with mrtron's reading of the letter, but that's why I asked people to read the original letter anyway.

I never said that it was not a case of responsible disclosure. I simply don't know, the evidence at this point seems insufficient to support either conclusion.

Post reply on HN