Public recordings
Sort by
_chrony 594 0.0 0.1 10724 556 ? S 10:32 0:00 \_ /usr/sbinroot 602 0.0 3.7 26612 17524 ? Ss 10:32 0:00 /usr/bin/pythadmin@i-0f1eaa7d28ad4d0f3:~$ vim /home/admin/webserver.py admin@i-0f1eaa7d28ad4d0f3:~$ ls -l total 8 drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-0f1eaa7d28ad4d0f3:~$ chown admin:admin webserver.py chown: changing ownership of 'webserver.py': Operation not permitted admin@i-0f1eaa7d28ad4d0f3:~$ lsattr -i webserver.py lsattr: invalid option -- 'i' Usage: lsattr [-RVadlpv] [files...] admin@i-0f1eaa7d28ad4d0f3:~$ lsattr webserver.py lsattr: Permission denied While reading flags on webserver.py admin@i-0f1eaa7d28ad4d0f3:~$ h
paris/i-0f1eaa7d28ad4d0f3 04:44
by SadServersstemd: --nofork --nopidfile --systemd-activation --syslog-only root 573 0.2 5.9 33040 27900 ? Ss 21:18 0:00 /usr/bin/pythroot 575 0.0 0.9 220796 4340 ? Ssl 21:18 0:00 /usr/sbin/rsyroot 586 0.0 1.4 13492 6676 ? Ss 21:18 0:00 /lib/systemd/root 591 0.0 0.3 2872 1728 tty1 Ss+ 21:18 0:00 /sbin/agetty nux root 592 0.0 0.4 4396 2096 ttyS0 Ss+ 21:18 0:00 /sbin/agetty 0,57600,38400,9600 ttyS0 vt220 root 593 0.0 1.5 13352 7292 ? Ss 21:18 0:00 sshd: /usr/sb-100 startups _chrony 595 0.0 0.7 10852 3664 ? S 21:18 0:00 /usr/sbin/chr_chrony 596 0.0 0.1 10724 548 ? S 21:18 0:00 \_ /usr/sbinroot 610 0.0 3.7 26612 17412 ? Ss 21:18 0:00 /usr/bin/pythrades/unattended-upgrade-shutdown --wait-for-signal admin@i-0f11b62e125014253:~$ curl 127
paris/i-0f11b62e125014253 02:50
by SadServersadmin@i-0102423b4d32663a7:~$ curl 127.0.0.1:5000 Unauthorizedadmin@i-0102423b4d32663a7:~$ admin@i-0102423b4d32663a7:~$ admin@i-0102423b4d32663a7:~$ ls agent webserver.py admin@i-0102423b4d32663a7:~$ less webserver.py webserver.py: Permission denied admin@i-0102423b4d32663a7:~$ ll bash: ll: command not found admin@i-0102423b4d32663a7:~$ cat webserver.py cat: webserver.py: Permission denied admin@i-0102423b4d32663a7:~$ cd agent/ admin@i-0102423b4d32663a7:~/agent$ ls check.sh sadagent sadagent.txt admin@i-0102423b4d32663a7:~/agent$ ls
paris/i-0102423b4d32663a7 02:35
by SadServers24 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 netns 25 root 20 0 0 0 0 S 0.0 0.0 0:00.12 kauditd 26 root 20 0 0 0 0 S 0.0 0.0 0:00.00 khungtask 27 root 20 0 0 0 0 S 0.0 0.0 0:00.00 oom_reape 28 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 writeback 29 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kcompactd 30 root 25 5 0 0 0 S 0.0 0.0 0:00.00 ksmd 49 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kintegrit 50 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kblockd 51 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 blkcg_pun 52 root 20 0 0 0 0 I 0.0 0.0 0:00.03 kworker/1 53 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kworker/0 54 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kswapd0 55 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kthrotld admin@i-0bc8be230e1a6d230:~$ lso
paris/i-0bc8be230e1a6d230 01:07
by SadServersgoroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0b280c2a98b3cd4ee:~$ cd /home/admin/ admin@i-0b280c2a98b3cd4ee:~$ ls agent data datafile kihei admin@i-0b280c2a98b3cd4ee:~$ ./kihei panic: exit status 1 goroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0b280c2a98b3cd4ee:~$ kihei bash: kihei: command not found admin@i-0b280c2a98b3cd4ee:~$ kihei
kihei/i-0b280c2a98b3cd4ee 02:27
by SadServerslsof 881 admin mem REG 259,1 14952linux-gnu/libpthread-2.31.so lsof 881 admin mem REG 259,1 1868linux-gnu/libdl-2.31.so lsof 881 admin mem REG 259,1 61712linux-gnu/libpcre2-8.so.0.10.1 lsof 881 admin mem REG 259,1 190153linux-gnu/libc-2.31.so lsof 881 admin mem REG 259,1 16612linux-gnu/libselinux.so.1 lsof 881 admin mem REG 259,1 17792linux-gnu/ld-2.31.so lsof 881 admin 4r FIFO 0,11 0tlsof 881 admin 7w FIFO 0,11 0tadmin@i-004e377b1bc91ea0e:/proc/572$ ls
paris/i-004e377b1bc91ea0e 03:35
by SadServersFirst sector (2048-2097151, default 2048): Last sector, +/-sectors or +/-size{K,M,G,T,P} (2048-2097151, default 2097151): Created a new partition 1 of type 'Linux' and of size 1023 MiB. Command (m for help): w The partition table has been altered. Calling ioctl() to re-read partition table. Syncing disks. admin@i-09f66041f9028dba9:~$ sudo pvcreate /dev/nvme1n1p1 Physical volume "/dev/nvme1n1p1" successfully created. admin@i-09f66041f9028dba9:~$ sudo pvcreate /dev/nvme2n1p1 Physical volume "/dev/nvme2n1p1" successfully created. admin@i-09f66041f9028dba9:~$
kihei/i-09f66041f9028dba9 04:54
by SadServersudev 217M 0 217M 0% /dev tmpfs 46M 368K 46M 1% /run /dev/nvme0n1p1 7.7G 6.1G 1.2G 84% / tmpfs 228M 12K 228M 1% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock /dev/nvme0n1p15 124M 5.9M 118M 5% /boot/efi admin@i-00e339adeade5921e:~$ lsblk NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT nvme0n1 259:0 0 8G 0 disk ├─nvme0n1p1 259:3 0 7.9G 0 part / ├─nvme0n1p14 259:4 0 3M 0 part └─nvme0n1p15 259:5 0 124M 0 part /boot/efi nvme1n1 259:1 0 1G 0 disk nvme2n1 259:2 0 1G 0 disk admin@i-00e339adeade5921e:~$
kihei/i-00e339adeade5921e 00:26
by SadServersadmin@i-08cacd57dfb4eeb5e:~$ ls agent webserver.py admin@i-08cacd57dfb4eeb5e:~$ ls -l total 8 drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-08cacd57dfb4eeb5e:~$ admin@i-08cacd57dfb4eeb5e:~$ lsof
paris/i-08cacd57dfb4eeb5e 02:54
by SadServersWe trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: Sorry, try again. [sudo] password for admin: Sorry, try again. [sudo] password for admin: sudo: 3 incorrect password attempts admin@i-040ec55e8e002101c:~$ find / -name webserver
paris/i-040ec55e8e002101c 02:48
by SadServersWARNING: Running as a non-root user. Functionality may be unavailable. /run/lock/lvm/P_global:aux: open failed: Permission denied admin@i-0a1d4ad6b6fe16108:~$ ыгвщ ыг bash: ыгвщ: command not found admin@i-0a1d4ad6b6fe16108:~$ sudo su root@i-0a1d4ad6b6fe16108:/home/admin# pvcreate /dev/nvme1n1 /dev/nvme2n1 Physical volume "/dev/nvme1n1" successfully created. Physical volume "/dev/nvme2n1" successfully created. root@i-0a1d4ad6b6fe16108:/home/admin# lvcreate -n lv -L1600 vg Volume group "vg" not found Cannot process volume group vg root@i-0a1d4ad6b6fe16108:/home/admin# vgcreate vg ^C root@i-0a1d4ad6b6fe16108:/home/admin# vfcreate lvcreate -n lv -L1600 vg bash: vfcreate: command not found root@i-0a1d4ad6b6fe16108:/home/admin# vfcreate lvcreate -n lv -L1600 vg
kihei/i-0a1d4ad6b6fe16108 01:54
by SadServerstmpfs 228M 12K 228M 1% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock /dev/nvme0n1p15 124M 5.9M 118M 5% /boot/efi admin@i-032d3ffe9fedd91fa:~$ sudo df -h Filesystem Size Used Avail Use% Mounted on udev 217M 0 217M 0% /dev tmpfs 46M 368K 46M 1% /run /dev/nvme0n1p1 7.7G 6.1G 1.2G 84% / tmpfs 228M 12K 228M 1% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock /dev/nvme0n1p15 124M 5.9M 118M 5% /boot/efi admin@i-032d3ffe9fedd91fa:~$ cd /usr admin@i-032d3ffe9fedd91fa:/usr$ ls bin games include lib lib32 lib64 libexec libx32 local sbin share srcadmin@i-032d3ffe9fedd91fa:/usr$ c