Its certainly a grey area and covering all your bases legally before embarking on a penetration test would be good idea. Even with all the legal formalities, there needs to be a good level of trust between the client and the auditor for things to go smoothly.
Two days later, Mr. Al-Khabaz decided to run a software program called Acunetix, designed to test for vulnerabilities in websites, to ensure that the issues he and Mija had identified had been corrected.
If you find a security flaw in a system and report it, receiving positive feedback doesn't automatically imply that you have permission to conduct further tests. A web application vulnerability scanner can cause damage to production systems.
Almost anyone can just download a scanner and run a wild test using default settings. But its illegal to do it without prior authorization.
While his intentions were good, I think it was a bit naive of him to take upon himself the responsibility to make sure the flaws were fixed and conduct a test. Even when you have permission to conduct a test you stick to the scope and limits of the agreement. You cant just keep leapfrogging networks as you find holes.
Manually finding holes/bugs accidentally and reporting them is different from running a vulnerability scanner.
I dont think he should have been expelled without giving a chance to explain his story and the way they did it was not ethical. The management over reacted, especially considering there was no damages mentioned in this case.
http://testlab.sit.fraunhofer.de/downloads/Publications/tuer...
http://www.coresecurity.com/content/under-attack
https://en.wikipedia.org/wiki/Randal_L._Schwartz#Intel_case