Public recordings
Sort by
admin@i-0e2c9c64a6cc5b706:~$ ls agent webserver.py admin@i-0e2c9c64a6cc5b706:~$ ls agent/ check.sh sadagent sadagent.txt admin@i-0e2c9c64a6cc5b706:~$ ls agent/sadagent agent/sadagent admin@i-0e2c9c64a6cc5b706:~$ file agent/sadagent agent/sadagent: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, Go BuildID=H6A8cVluPFUvaNojVwMi/C5t-5rNiA5GJLWeSm5Qz/KXfivG_lDFnrqPGrWEJo/K_OQEFevUZEPr4lPEnoe, not stripped admin@i-0e2c9c64a6cc5b706:~$ ./agent/check.sh md5sum: /home/admin/mysolution: No such file or directory NOadmin@i-0e2c9c64a6cc5b706:~$ ./agent/
paris/i-0e2c9c64a6cc5b706 01:06
by SadServerswrite(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-05088a4f1fc43f619:~$ strace ./kihei 2>&1 | grep datafile newfstatat(AT_FDCWD, "/home/admin/data/newdatafile", 0xc00008e9f8, 0) = -1 ENOENunlinkat(AT_FDCWD, "/home/admin/data/newdatafile", 0) = 0 admin@i-05088a4f1fc43f619:~$ cd data admin@i-05088a4f1fc43f619:~/data$ ls -al total 8 drwxr-xr-x 2 admin root 4096 Dec 5 09:17 . drwxr-xr-x 7 admin admin 4096 Dec 5 09:12 .. admin@i-05088a4f1fc43f619:~/data$ touch newdatafile admin@i-05088a4f1fc43f619:~/data$ strace .../kihei 2>&1 | grep datafile
kihei/i-05088a4f1fc43f619 07:44
by SadServers/cpu.CacheLineSizeinternal/cpu.X86internal/cpu.optionsinternal/cpu.maxExtendedFunittaskpath.ErrBadPatterngo.itab.*flag.boolValue,flag.Valuego.itab.*os.File,io.WmError,errorgo.itab.*reflect.rtype,reflect.Typego.itab.*flag.durationValue,flag.64Value,flag.Valuego.itab.*flag.intValue,flag.Valuego.itab.*flag.int64Value,flagngValue,flag.Valuego.itab.*flag.uintValue,flag.Valuego.itab.*flag.uint64Value,fl.Builder,io.Writergo.itab.*errors.errorString,errorgo.itab.*fmt.wrapError,errorggo.itab.*os.File,io.Readergo.itab.syscall.Signal,os.Signalgo.itab.*io/fs.PathErrallError,errorgo.itab.syscall.Errno,errorgo.itab.os.onlyWriter,io.Writergo.itab.nfogo.itab.*io.LimitedReader,io.Readergo.itab.*os.File,io.Closergo.itab.*os/exec*os/exec.Error,errorgo.itab.*bufio.Reader,io.Readergo.itab.os/user.UnknownUserIdrnal/reflectlite.rtype,internal/reflectlite.Typego.itab.time.fileSizeError,errort.SortedMap,sort.Interfacego.itab.runtime.errorString,error_cgo_init_cgo_thread__init_done_cgo_callers_cgo_yield_cgo_mmap_cgo_munmap_cgo_sigactionruntime.mainPCeadlineExceededError,errorgo.itab.internal/poll.errNetClosing,errorruntime.defaudVersion.strruntime.modinfo.strtype.*runtime.textsectionmapadmin@i-062042b0fb20a
kihei/i-062042b0fb20a2893 02:05
by SadServersTotal PE 510 Alloc PE / Size 0 / 0 Free PE / Size 510 / 1.99 GiB VG UUID Iwu3cD-ZYLv-b7Nx-Ctd3-7xJg-JwLt-wR1ZVv admin@i-0b06f5a7c110614cf:~$ sudo lvcreate -n new -L 100%FREE vg00 Can't parse size argument. Invalid argument for --size: 100%FREE Error during parsing of command line. admin@i-0b06f5a7c110614cf:~$ sudo lvcreate -n new -l 100%FREE vg00 Logical volume "new" created. admin@i-0b06f5a7c110614cf:~$ lvs WARNING: Running as a non-root user. Functionality may be unavailable. /run/lock/lvm/P_global:aux: open failed: Permission denied admin@i-0b06f5a7c110614cf:~$
kihei/i-0b06f5a7c110614cf 04:44
by SadServerssudo:x:27:admin admin@i-07aabdeac228c0ec5:~$ su Password: admin@i-07aabdeac228c0ec5:~$ su - Password: admin@i-07aabdeac228c0ec5:~$ sudo ls We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin:
paris/i-07aabdeac228c0ec5 03:15
by SadServers<85>¯^B^@^@H<8d>^MüY ^@H9È^O<85><9f>^B^@^@ò^O^PC^Hò^O^QD$0ò^O^P^Kò^O^QL$ è^Y¢^B^@ò^O^PD$ ò^O^PL$0èh§^O^_^@é<89>^B^@^@<81>ù=èJÐ^O<87>^O^A^@^@<81>ù<92>×J½^O<87><83>^@^@^@^O^_^@<81>ù^B^@H9È^O<85>4^B^@^@Hc^CH<89>D$h軡^B^@H<8b>D$h豨^B^@è,¢^B^@é5^B^@^@^O^_<80>^@^@^½^O<85>^@^B^@^@H<8d>^MÍi ^@H9È^O<85>ð^A^@^@H<8b>^CH<89>D$@èw¡^B^@H<8b>D$@èm§^B^@èè¡^B^@éñ^A^@^@^O^_^@<81>MÑb ^@H9È^O<85>´^A^@^@H^O¾^CH<89>D$hè:¡^B^@H<8b>D$hè0¨^B^@è«¡^B^@é´^A^@^@f^O^_D^@^@<<80>^A^@^@H<8d>^M<8d>h ^@H9È^O<85>p^A^@^@<8b>^CH<89>D$pèø ^B^@H<8b>D$pèî¦^B^@èi¡^B^@ér^A^@^@^O^_@^@<81>>^@^@^@<81>ù^Rw¸Õu;H<8d>^MÅg ^@^O^_D^@^@H9È^O<85>#^A^@^@H<8b>^CH<89>D$Pèª ^B^@H<8b>D$P^O^_D^@^@è<9b>¦^B^@è^V¡81>ù´\ÿà^O<85>ñ^@^@^@H<8d>^M>g @@@ 64,1
kihei/i-08857ea34adc096aa 01:16
by SadServers_chrony 602 0.0 0.7 10856 3596 ? S 19:12 0:00 /usr/sbin/chrroot 609 0.0 3.7 26612 17272 ? Ss 19:12 0:00 /usr/bin/pyth-upgrades/unattended-upgrad _chrony 611 0.0 0.1 10724 552 ? S 19:12 0:00 /usr/sbin/chrroot 913 0.0 0.0 0 0 ? I 19:17 0:00 [kworker/1:1-admin 916 0.0 0.7 5920 3624 pts/0 S<s+ 19:18 0:00 bash -l admin 918 0.2 4.1 98188 19372 pts/0 R<l+ 19:18 0:00 /usr/bin/pythc -t kihei/i-058f99da3418f9 admin 921 0.0 3.2 24456 14984 pts/0 S<+ 19:18 0:00 /usr/bin/pythc -t kihei/i-058f99da3418f9 admin 922 0.0 0.1 2480 568 pts/1 S<s 19:18 0:00 sh -c /bin/baadmin 923 0.0 1.0 6952 4880 pts/1 S< 19:18 0:00 /bin/bash root 947 0.0 0.0 0 0 ? I 19:18 0:00 [kworker/0:0-admin 1046 0.0 0.7 8648 3268 pts/1 R<+ 19:19 0:00 ps waux admin@i-058f99da3418f95da:~$
kihei/i-058f99da3418f95da 06:55
by SadServersadmin@i-0a8bcc323c97885e6:~$ ls -l /etc/apache2/conf-available/javascript-common-rw-r--r-- 1 root root 127 Dec 18 2020 /etc/apache2/conf-available/javascript-cadmin@i-0a8bcc323c97885e6:~$ cat /etc/apache2/conf-available/javascript-common.cAlias /javascript /usr/share/javascript/ <Directory "/usr/share/javascript/"> Options FollowSymLinks MultiViews </Directory> admin@i-0a8bcc323c97885e6:~$ cd /usr/share/java admin@i-0a8bcc323c97885e6:/usr/share/java$ cd /usr/share/javascript/ admin@i-0a8bcc323c97885e6:/usr/share/javascript$ ls jquery sphinxdoc underscore admin@i-0a8bcc323c97885e6:/usr/share/javascript$ a2
paris/i-0a8bcc323c97885e6 04:24
by SadServersadmin@i-0b35f1e30982bea9a:~$ lsblk NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT nvme1n1 259:0 0 1G 0 disk nvme0n1 259:1 0 8G 0 disk ├─nvme0n1p1 259:2 0 7.9G 0 part / ├─nvme0n1p14 259:3 0 3M 0 part └─nvme0n1p15 259:4 0 124M 0 part /boot/efi nvme2n1 259:5 0 1G 0 disk admin@i-0b35f1e30982bea9a:~$
kihei/i-0b35f1e30982bea9a 00:06
by SadServersadmin@i-094407eb5173ca7f2:~$ telnet loaclhost 5000 telnet: could not resolve loaclhost/5000: Name or service not known admin@i-094407eb5173ca7f2:~$ telnet localhost 5000 Trying 127.0.0.1... Connected to localhost. Escape character is '^]'. GET / Welcome! Password is FDZPmh5AX3oiJtConnection closed by foreign host. admin@i-094407eb5173ca7f2:~$ curl --insecure --anyauth -u admin:passowrd -X GET Unauthorizedadmin@i-094407eb5173ca7f2:~$ curl --insecure --anyauth -u admin:pass admin@i-094407eb5173ca7f2:~$ admin@i-094407eb5173ca7f2:~$ admin@i-094407eb5173ca7f2:~$ curl --insecure --anyauth -u admin:FDZPmh5AX3oiJt -
paris/i-094407eb5173ca7f2 04:03
by SadServers23 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 netns 24 root 20 0 0 0 0 S 0.0 0.0 0:00.08 kauditd 25 root 20 0 0 0 0 S 0.0 0.0 0:00.00 khungtask 26 root 20 0 0 0 0 S 0.0 0.0 0:00.00 oom_reape 27 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 writeback 28 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kcompactd 29 root 25 5 0 0 0 S 0.0 0.0 0:00.00 ksmd 37 root 20 0 0 0 0 I 0.0 0.0 0:00.00 kworker/1 49 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kintegrit 50 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kblockd 51 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 blkcg_pun 52 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kworker/1 53 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kswapd0 54 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kthrotld admin@i-03873fbdcdbaf6f80:~$ top |