Christian Heinrich christian.heinrich at cmlh.id.au
Mon May 19 16:10:06 UTC 2014

Sarah and Michael,

I would like to remind the OWASP Board of the recent "review" of
and Josh Sokol's own thoughts are documented at
that indicate that I was a productive and contributing member of OWASP
prior to this action of Dinis Cruz.

I would like to bring to the attention of the OWASP Board Dinis'
admissions that the OWASP Google Hacking Inquiry, that lacked
supporting evidence or witnesses for that matter, was solely an
unprovoked, deliberate and personal attack inflicted upon me by Dinis
Cruz  within http://lists.owasp.org/pipermail/owasp-board/2011-January/009590.html
and http://lists.owasp.org/pipermail/owasp-board/2010-December/009363.html

As far as the e-mail to Josh Sokol, our matter was resolved last week
and I simply believe Josh may not have forgotten to remove this auto
response.  I was not inferring anything more with this e-mail to him.

I would like to thank you for your time.

On Tue, May 20, 2014 at 1:20 AM, Dinis Cruz <dinis.cruz at owasp.org> wrote:
> Sarah,Michael
> Can you please deal with this ASAP. I thought that Christian was not
> supposed to be involved in any OWASP activities and it is not fair to expose
> Josh to the abuses received in the last days/weeks/months.
> Yes, its easier to be quiet and hope Christian gives up, but that doesn't
> seem to be possible, so can we make OWASP (again) a nice place to contribute
> and collaborate
> Me and Josh might have different points of views on a couple things, but I
> never questioned or had doubts about his integrity, motivations or actions.
> Owasp needs to protect its leaders (and board members) from abuse, and
> specially from having to respond (alone) to accusations on their character,
> actions or intentions
> Josh, I'm sorry that you found yourself on the receiving end of Christian's
> accusations, and you have shown a lot of patience, respect and integrity in
> replying to them.
> But enough is enough and its time to wrap this up and send a clear message
> that this (ie Christian's) type of behaviour must not be acceptable in an
> open and collaborative organisation/community like OWASP
> I also would like (if possible) not to be on the receiving end of more
> abuse, since I want to use the time that I can make available to OWASP on
> productive actions (like helping out the OWASP projects)

Christian Heinrich


