paris/i-0b0edb32d26a5502b
by SadServersMore by SadServers
admin@i-0e3126c91f22b8e7e:~$ cd /home/admin/ admin@i-0e3126c91f22b8e7e:~$ ls agent data datafile kihei admin@i-0e3126c91f22b8e7e:~$ ps aux | grep kihei admin 733 0.4 4.1 98188 19420 pts/0 S<l+ 21:13 0:00 /usr/bin/pyth-t kihei/i-0e3126c91f22b8e7e -q -i 2 /var/log/cast/i-0e3126c91f22b8e7e admin 736 0.0 3.0 24456 14364 pts/0 S<+ 21:13 0:00 /usr/bin/pyth-t kihei/i-0e3126c91f22b8e7e -q -i 2 /var/log/cast/i-0e3126c91f22b8e7e admin 747 0.0 0.1 5264 696 pts/1 S<+ 21:14 0:00 grep kihei admin@i-0e3126c91f22b8e7e:~$ chmod -R a-w /var/log/cast/ admin@i-0e3126c91f22b8e7e:~$
kihei/i-0e3126c91f22b8e7e 00:44
by SadServerspipe2([5, 6], O_NONBLOCK|O_CLOEXEC) = 0 epoll_ctl(4, EPOLL_CTL_ADD, 5, {EPOLLIN, {u32=5871088, u64=5871088}}) = 0 epoll_ctl(4, EPOLL_CTL_ADD, 3, {EPOLLIN|EPOLLOUT|EPOLLRDHUP|EPOLLET, {u32=157228read(3, "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 1540 close(3) = 0 write(1, "Error: This program cannot be ru"..., 59Error: This program cannot be ) = 59 exit_group(1) = ? +++ exited with 1 +++ root@i-0a33e9937e66b67a2:/var/log# exit exit admin@i-0a33e9937e66b67a2:~$ cd admin@i-0a33e9937e66b67a2:~$ bash kihei kihei: kihei: cannot execute binary file admin@i-0a33e9937e66b67a2:~$ stra
kihei/i-0a33e9937e66b67a2 05:11
by SadServersadmin@i-08a1941667a15b5b6:/home$ cd /var/log/ admin@i-08a1941667a15b5b6:/var/log$ ls alternatives.log auth.log.2.gz cloud-init-output.log debug faillog te unattended-upgrades alternatives.log.1 btmp cloud-init.log debug.1 journal user.log apt btmp.1 daemon.log debug.2.gz kern.log g user.log.1 auth.log cast daemon.log.1 dpkg.log kern.log.1g.1 user.log.2.gz auth.log.1 chrony daemon.log.2.gz dpkg.log.1 kern.log.2g.2.gz wtmp admin@i-08a1941667a15b5b6:/var/log$ less messages admin@i-08a1941667a15b5b6:/var/log$ less syslog admin@i-08a1941667a15b5b6:/var/log$ c