Disclaimer: This report reflects the submitter's account. It has not been independently verified unless marked Verified. The company may dispute this claim.
Scam Alert: notte.cc — Notte.cc Scammed on RCE Finding
Notte.cc is doing massive scams. They take the report and disappear like a flash once you ask for the justification. They claim that the RCE, AWS Secrets, etc/passwd file, everything is by design and intentional behavior.
But they will not answer your questions in any way. If everything is by design, there is no need to fix it, right? but they will not answer that.
I want to ask you guys, how many of have seen RCE by design? isn't it funny?
Like is it a test-lab where RCE type vulns are existing by design for the testers?
I have got other references from the fellow researchers thay, they love to reject your reports and fix that vulnerabilities without rewarding anything.
I also asked to publish a notice on their official website that this "RCE, AWS Secrets, Internal Server Files Read and Write, etc" vulnerability here is intentional and by design, so people should not spent time over it to test the design-flow.
I would highly recommend not to work and invest your time and money in Notte.cc
Their founders are
CEO Andrea Pinto and CTO Lucas Giordano, do not work with them in any way.
Thank you.
Report a Scam Use the Submit tab to file a detailed report with evidence.
🛡
Security Issues Found a vulnerability on our site? Email us directly.
🤝
Partnerships Interested in collaborating? We'd love to hear from you.
☠
Get Notified of New Scam Reports
Subscribe to get an email the moment a new scam report or blog post goes live on BugBountyScam. Double opt-in, no spam, unsubscribe anytime.
☠
New Scam Reports Instant alert when a bug bounty program gets reported.
✎
Blog Posts Get notified when we publish new investigations.
🔒
Privacy First We never share your email. One-click unsubscribe in every message.
⌕ Program Lookup
Check if a bug bounty program has scam reports
☠ Wall of Shame
Programs with the most scam reports from the community
◈ Scam Analytics
⧖ Track Report
Enter your tracking ID to check submission status
✎ Blog
☆ Weekly Digest
Valid Bug Bounty Programs
Researcher-reported programs and experiences. Explore programs that researchers have interacted with — and read what actually happened — before you start hunting.
⚠ Researcher-submitted information. Program details, bounty ranges, response times and experiences are based on user submissions and may not be independently verified. Verify important details yourself before relying on them.
⌕
No programs match your filters.
Stay Updated
Get notified when new valid programs are approved.
Submit a Program
⚠ User-submitted bounty/response information may not be independently verified. Submissions are reviewed before publishing.
Share Your Experience
Tags (select any that apply)
Preview
Submission Terms
This must be your own experience.
Do not knowingly submit false information.
Do not publish passwords, API keys, tokens or credentials.
Do not publish confidential vulnerability information.
BugBountyScam may review, reject or remove submissions.
Submitted experiences may be displayed publicly.
☻ Chat
Join Community Chat
Enter name & email to chat
☠
Get Notified of New Scam Reports
Drop your email. We'll ping you the moment a new scam report or blog post goes live. No spam, unsubscribe anytime.