Scam Alert: notte.cc — Notte.cc Scammed on RCE Finding
Company / Program: notte.cc
Platform: Self-Hosted · Severity: critical · Scam type: ignored
Published:
Reported by: Anonymous
Notte.cc is doing massive scams. They take the report and disappear like a flash once you ask for the justification. They claim that the RCE, AWS Secrets, etc/passwd file, everything is by design and intentional behavior.
But they will not answer your questions in any way. If everything is by design, there is no need to fix it, right? but they will not answer that.
I want to ask you guys, how many of have seen RCE by design? isn't it funny?
Like is it a test-lab where RCE type vulns are existing by design for the testers?
I have got other references from the fellow researchers thay, they love to reject your reports and fix that vulnerabilities without rewarding anything.
I also asked to publish a notice on their official website that this "RCE, AWS Secrets, Internal Server Files Read and Write, etc" vulnerability here is intentional and by design, so people should not spent time over it to test the design-flow.
I would highly recommend not to work and invest your time and money in Notte.cc
Their founders are
CEO Andrea Pinto and CTO Lucas Giordano, do not work with them in any way.
Thank you.