Unauthorized security testing == Malicious attack The actions of Mr. Al-Khabaz were unlawful and unethical. If he only accidentally found the flaw and reported it to the responsible person, things would be fine. But security testing without the permission of the system owner is the same as unauthorized access attempt! I work as a security professional for 7 years, and I recently did a guest lecture on the college dis…
You are overlooking the fact that Al-Khabaz informed the system owner 2 days prior of the problem. Thus, you can not claim the actions of Mr. Al-Khabaz were definitely unlawful and unethical, that remains to be seen. This is not a black and white issue.
Warning the system owner doesn't give you the ability to run pen tests if they do not wish you to do so.