Public recordings
Sort by
/home/admin admin@i-04d9fdf17ef2b370a:~$ ls -la total 44 drwxr-xr-x 6 admin admin 4096 Sep 24 23:20 . drwxr-xr-x 3 root root 4096 Sep 17 16:44 .. drwx------ 3 admin admin 4096 Sep 20 15:52 .ansible -rw------- 1 admin admin 93 Jan 31 18:51 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 15:56 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-04d9fdf17ef2b370a:~$ nano webserver.py
paris/i-04d9fdf17ef2b370a 01:05
by SadServersadmin@i-094407eb5173ca7f2:~$ telnet loaclhost 5000 telnet: could not resolve loaclhost/5000: Name or service not known admin@i-094407eb5173ca7f2:~$ telnet localhost 5000 Trying 127.0.0.1... Connected to localhost. Escape character is '^]'. GET / Welcome! Password is FDZPmh5AX3oiJtConnection closed by foreign host. admin@i-094407eb5173ca7f2:~$ curl --insecure --anyauth -u admin:passowrd -X GET Unauthorizedadmin@i-094407eb5173ca7f2:~$ curl --insecure --anyauth -u admin:pass admin@i-094407eb5173ca7f2:~$ admin@i-094407eb5173ca7f2:~$ admin@i-094407eb5173ca7f2:~$ curl --insecure --anyauth -u admin:FDZPmh5AX3oiJt -
paris/i-094407eb5173ca7f2 04:03
by SadServers-rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-093333d0150041494:~$ cd .. admin@i-093333d0150041494:/home$ find / -perm -4000 -type f 2>/dev/null /usr/lib/openssh/ssh-keysign /usr/lib/dbus-1.0/dbus-daemon-launch-helper /usr/bin/chsh /usr/bin/umount /usr/bin/mount /usr/bin/passwd /usr/bin/newgrp /usr/bin/sudo /usr/bin/chfn /usr/bin/su /usr/bin/gpasswd admin@i-093333d0150041494:/home$
paris/i-093333d0150041494 03:18
by SadServersadmin@i-0ce4088ffc36025b0:~$ sudo netstat -ntlup We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: Sorry, try again. [sudo] password for admin: sudo: 1 incorrect password attempt admin@i-0ce4088ffc36025b0:~$ ^C admin@i-0ce4088ffc36025b0:~$
paris/i-0ce4088ffc36025b0 01:09
by SadServersgoroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-07ceb80639215b899:~$ vim kihei admin@i-07ceb80639215b899:~$ admin@i-07ceb80639215b899:~$ admin@i-07ceb80639215b899:~$ admin@i-07ceb80639215b899:~$ admin@i-07ceb80639215b899:~$ ls -l total 5245048 drwxr-xr-x 2 admin root 4096 Sep 17 17:28 agent drwxr-xr-x 2 admin root 4096 Dec 5 20:45 data -rw-r--r-- 1 root root 5368709120 Sep 17 17:28 datafile -rwxr-xr-x 1 admin root 2207109 Sep 17 17:28 kihei admin@i-07ceb80639215b899:~$
kihei/i-07ceb80639215b899 01:05
by SadServersmv: cannot create directory '/boot/efi/usr/include': No space left on device mv: cannot create directory '/boot/efi/usr/src': No space left on device mv: cannot create directory '/boot/efi/usr/libexec': No space left on device mv: cannot create directory '/boot/efi/usr/local': No space left on device root@i-0309acbdfa892c707:/home/admin# ^C root@i-0309acbdfa892c707:/home/admin# df Filesystem 1K-blocks Used Available Use% Mounted on udev 221828 221828 0 100% /dev tmpfs 46636 384 46252 1% /run /dev/nvme0n1p1 8026128 6354688 1242184 84% / tmpfs 233168 12 233156 1% /dev/shm tmpfs 5120 0 5120 0% /run/lock /dev/nvme0n1p15 126678 126678 0 100% /boot/efi tmpfs 46632 0 46632 0% /run/user/0 root@i-0309acbdfa892c707:/home/admin# df
kihei/i-0309acbdfa892c707 01:14
by SadServerswrite(2, "\t", 1 ) = 1 write(2, "./main.go", 9./main.go) = 9 write(2, ":", 1:) = 1 write(2, "64", 264) = 2 write(2, " +", 2 +) = 2 write(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-0cf4052df7f7472c2:~$ strace -v /home/admin/kihei > strace.txt^C admin@i-0cf4052df7f7472c2:~$ cat strace.txt admin@i-0cf4052df7f7472c2:~$ strace^C admin@i-0cf4052df7f7472c2:~$ ^C admin@i-0cf4052df7f7472c2:~$
kihei/i-0cf4052df7f7472c2 06:53
by SadServersE: Invalid operation remove root@i-0a4d53e26d778df49:/usr/lib# apt apt apt-config apt-get apt-mark apt-cache apt-extracttemplates apt-key apt-sortpkgs apt-cdrom apt-ftparchive apt-listchanges root@i-0a4d53e26d778df49:/usr/lib# apt apt apt-config apt-get apt-mark apt-cache apt-extracttemplates apt-key apt-sortpkgs apt-cdrom apt-ftparchive apt-listchanges root@i-0a4d53e26d778df49:/usr/lib# apt re ove^C root@i-0a4d53e26d778df49:/usr/lib# apt remove Reading package lists... Done Building dependency tree... Done Reading state information... Done
kihei/i-0a4d53e26d778df49 04:11
by SadServersadmin@i-08be9ae6ca86822e0:~$ curl localhost:5000 Unauthorizedadmin@i-08be9ae6ca86822e0:~$ id uid=1000(admin) gid=1000(admin) groups=1000(admin),4(adm),20(dialout),24(cdrom),),30(dip),44(video),46(plugdev),109(netdev) admin@i-08be9ae6ca86822e0:~$ nc nc nc.openbsd admin@i-08be9ae6ca86822e0:~$ man nc admin@i-08be9ae6ca86822e0:~$ nc localhost 5000
paris/i-08be9ae6ca86822e0 00:50
by SadServersudev 217M 0 217M 0% /dev tmpfs 46M 368K 46M 1% /run /dev/nvme0n1p1 7.7G 6.1G 1.2G 84% / tmpfs 228M 12K 228M 1% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock /dev/nvme0n1p15 124M 5.9M 118M 5% /boot/efi admin@i-06f14f1acdd48bc0a:~$ df -ih Filesystem Inodes IUsed IFree IUse% Mounted on udev 55K 307 54K 1% /dev tmpfs 57K 442 57K 1% /run /dev/nvme0n1p1 504K 33K 472K 7% / tmpfs 57K 4 57K 1% /dev/shm tmpfs 57K 3 57K 1% /run/lock /dev/nvme0n1p15 0 0 0 - /boot/efi admin@i-06f14f1acdd48bc0a:~$
kihei/i-06f14f1acdd48bc0a 03:49
by SadServers/run/lock/lvm/P_global:aux: open failed: Permission denied admin@i-05ae3ce6cf2760c95:~$ sudo vgdisplay admin@i-05ae3ce6cf2760c95:~$ sudo pvdisplay admin@i-05ae3ce6cf2760c95:~$ sudo lvdisplay admin@i-05ae3ce6cf2760c95:~$ ls /dev/nv nvme0 nvme0n1p1 nvme0n1p15 nvme1n1 nvme2n1 nvme0n1 nvme0n1p14 nvme1 nvme2 nvram admin@i-05ae3ce6cf2760c95:~$ cfdisk /dev/nvme1 cfdisk: cannot open /dev/nvme1: Permission denied admin@i-05ae3ce6cf2760c95:~$ sudocfdisk /dev/nvme1 admin@i-05ae3ce6cf2760c95:~$ cfdisk /dev/nvme /dev/nvme0n1 /dev/nvme0n1p1 /dev/nvme0n1p14 /dev/nvme0n1p15 /dev/nvme1n1admin@i-05ae3ce6cf2760c95:~$ cfdisk /dev/nvme2n1 cfdisk: cannot open /dev/nvme2n1: Permission denied admin@i-05ae3ce6cf2760c95:~$ sudo cfdisk /dev/nvme2n1