Public recordings
Sort by
write(2, ":", 1:) = 1 write(2, "64", 264) = 2 write(2, " +", 2 +) = 2 write(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-04e9a940bea99a35d:~$ ls /home/admin/data/newdatafile ls: cannot access '/home/admin/data/newdatafile': No such file or directory admin@i-04e9a940bea99a35d:~$ cd /home/admin/data/ admin@i-04e9a940bea99a35d:~/data$ ls admin@i-04e9a940bea99a35d:~/data$ vi newdatafile admin@i-04e9a940bea99a35d:~/data$ chattr -i newdatafile admin@i-04e9a940bea99a35d:~/data$
kihei/i-04e9a940bea99a35d 06:04
by SadServers20K /var/log/debug 16K /var/log/dpkg.log 8.0K /var/log/faillog 33M /var/log/journal 176K /var/log/kern.log 8.0K /var/log/lastlog 180K /var/log/messages 4.0K /var/log/minio.log 4.0K /var/log/private 8.0K /var/log/runit 316K /var/log/syslog 8.0K /var/log/unattended-upgrades 20K /var/log/user.log 52K /var/log/wtmp admin@i-00c7c0914e0cfbd6f:~$
kihei/i-00c7c0914e0cfbd6f 00:57
by SadServers-rw-r----- 1 root adm 6951 Feb 18 15:31 syslog -rw-r----- 1 root adm 88453 Feb 18 15:26 syslog.1 -rw-r----- 1 root adm 46670 Sep 24 2023 syslog.2.gz drwxr-x--- 2 root adm 4096 Feb 18 15:26 unattended-upgrades -rw-r----- 1 root adm 928 Feb 18 15:26 user.log -rw-r----- 1 root adm 7751 Sep 24 2023 user.log.1 -rw-r----- 1 root adm 2927 Sep 20 2023 user.log.2.gz -rw-rw-r-- 1 root utmp 67968 Feb 18 15:26 wtmp admin@i-08d02c91e01791c90:/var/log$ ll bash: ll: command not found admin@i-08d02c91e01791c90:/var/log$ vi syslog. syslog.1 syslog.2.gz admin@i-08d02c91e01791c90:/var/log$ vi syslog. syslog.1 syslog.2.gz admin@i-08d02c91e01791c90:/var/log$ vi syslog.
paris/i-08d02c91e01791c90 06:30
by SadServersmain.main() ./main.go:64 +0x47d admin@i-04c6f947b4137d4bb:~$ ./kihei -h Usage: ./kihei [options] -h Display help -help Display help -v Verbose mode (print extra info) -verbose Verbose mode (print extra info) admin@i-04c6f947b4137d4bb:~$ free -m total used free shared buff/cache availableMem: 455 90 198 0 167 352Swap: 0 0 0 admin@i-04c6f947b4137d4bb:~$
kihei/i-04c6f947b4137d4bb 02:02
by SadServers_chrony 594 0.0 0.1 10724 556 ? S 10:32 0:00 \_ /usr/sbinroot 602 0.0 3.7 26612 17524 ? Ss 10:32 0:00 /usr/bin/pythadmin@i-0f1eaa7d28ad4d0f3:~$ vim /home/admin/webserver.py admin@i-0f1eaa7d28ad4d0f3:~$ ls -l total 8 drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-0f1eaa7d28ad4d0f3:~$ chown admin:admin webserver.py chown: changing ownership of 'webserver.py': Operation not permitted admin@i-0f1eaa7d28ad4d0f3:~$ lsattr -i webserver.py lsattr: invalid option -- 'i' Usage: lsattr [-RVadlpv] [files...] admin@i-0f1eaa7d28ad4d0f3:~$ lsattr webserver.py lsattr: Permission denied While reading flags on webserver.py admin@i-0f1eaa7d28ad4d0f3:~$ h
paris/i-0f1eaa7d28ad4d0f3 04:44
by SadServersstemd: --nofork --nopidfile --systemd-activation --syslog-only root 573 0.2 5.9 33040 27900 ? Ss 21:18 0:00 /usr/bin/pythroot 575 0.0 0.9 220796 4340 ? Ssl 21:18 0:00 /usr/sbin/rsyroot 586 0.0 1.4 13492 6676 ? Ss 21:18 0:00 /lib/systemd/root 591 0.0 0.3 2872 1728 tty1 Ss+ 21:18 0:00 /sbin/agetty nux root 592 0.0 0.4 4396 2096 ttyS0 Ss+ 21:18 0:00 /sbin/agetty 0,57600,38400,9600 ttyS0 vt220 root 593 0.0 1.5 13352 7292 ? Ss 21:18 0:00 sshd: /usr/sb-100 startups _chrony 595 0.0 0.7 10852 3664 ? S 21:18 0:00 /usr/sbin/chr_chrony 596 0.0 0.1 10724 548 ? S 21:18 0:00 \_ /usr/sbinroot 610 0.0 3.7 26612 17412 ? Ss 21:18 0:00 /usr/bin/pythrades/unattended-upgrade-shutdown --wait-for-signal admin@i-0f11b62e125014253:~$ curl 127
paris/i-0f11b62e125014253 02:50
by SadServersadmin@i-0102423b4d32663a7:~$ curl 127.0.0.1:5000 Unauthorizedadmin@i-0102423b4d32663a7:~$ admin@i-0102423b4d32663a7:~$ admin@i-0102423b4d32663a7:~$ ls agent webserver.py admin@i-0102423b4d32663a7:~$ less webserver.py webserver.py: Permission denied admin@i-0102423b4d32663a7:~$ ll bash: ll: command not found admin@i-0102423b4d32663a7:~$ cat webserver.py cat: webserver.py: Permission denied admin@i-0102423b4d32663a7:~$ cd agent/ admin@i-0102423b4d32663a7:~/agent$ ls check.sh sadagent sadagent.txt admin@i-0102423b4d32663a7:~/agent$ ls
paris/i-0102423b4d32663a7 02:35
by SadServers24 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 netns 25 root 20 0 0 0 0 S 0.0 0.0 0:00.12 kauditd 26 root 20 0 0 0 0 S 0.0 0.0 0:00.00 khungtask 27 root 20 0 0 0 0 S 0.0 0.0 0:00.00 oom_reape 28 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 writeback 29 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kcompactd 30 root 25 5 0 0 0 S 0.0 0.0 0:00.00 ksmd 49 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kintegrit 50 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kblockd 51 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 blkcg_pun 52 root 20 0 0 0 0 I 0.0 0.0 0:00.03 kworker/1 53 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kworker/0 54 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kswapd0 55 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kthrotld admin@i-0bc8be230e1a6d230:~$ lso
paris/i-0bc8be230e1a6d230 01:07
by SadServersgoroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0b280c2a98b3cd4ee:~$ cd /home/admin/ admin@i-0b280c2a98b3cd4ee:~$ ls agent data datafile kihei admin@i-0b280c2a98b3cd4ee:~$ ./kihei panic: exit status 1 goroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0b280c2a98b3cd4ee:~$ kihei bash: kihei: command not found admin@i-0b280c2a98b3cd4ee:~$ kihei
kihei/i-0b280c2a98b3cd4ee 02:27
by SadServerslsof 881 admin mem REG 259,1 14952linux-gnu/libpthread-2.31.so lsof 881 admin mem REG 259,1 1868linux-gnu/libdl-2.31.so lsof 881 admin mem REG 259,1 61712linux-gnu/libpcre2-8.so.0.10.1 lsof 881 admin mem REG 259,1 190153linux-gnu/libc-2.31.so lsof 881 admin mem REG 259,1 16612linux-gnu/libselinux.so.1 lsof 881 admin mem REG 259,1 17792linux-gnu/ld-2.31.so lsof 881 admin 4r FIFO 0,11 0tlsof 881 admin 7w FIFO 0,11 0tadmin@i-004e377b1bc91ea0e:/proc/572$ ls
paris/i-004e377b1bc91ea0e 03:35
by SadServersFirst sector (2048-2097151, default 2048): Last sector, +/-sectors or +/-size{K,M,G,T,P} (2048-2097151, default 2097151): Created a new partition 1 of type 'Linux' and of size 1023 MiB. Command (m for help): w The partition table has been altered. Calling ioctl() to re-read partition table. Syncing disks. admin@i-09f66041f9028dba9:~$ sudo pvcreate /dev/nvme1n1p1 Physical volume "/dev/nvme1n1p1" successfully created. admin@i-09f66041f9028dba9:~$ sudo pvcreate /dev/nvme2n1p1 Physical volume "/dev/nvme2n1p1" successfully created. admin@i-09f66041f9028dba9:~$