command-line-murders/i-07566a41e4b74086c
by SadServersMore by SadServers
unattended-upgrades alternatives.log.1 btmp cloud-init.log debug.1 journal user.log apt btmp.1 daemon.log debug.2.gz kern.log user.log.1 auth.log cast daemon.log.1 dpkg.log kern.log.11 user.log.2.gz auth.log.1 chrony daemon.log.2.gz dpkg.log.1 kern.log.22.gz wtmp admin@i-06683be665f75c9a6:/var/log$ cd ./cast/ admin@i-06683be665f75c9a6:/var/log/cast$ ls i-06683be665f75c9a6 admin@i-06683be665f75c9a6:/var/log/cast$ ls- la bash: ls-: command not found admin@i-06683be665f75c9a6:/var/log/cast$
paris/i-06683be665f75c9a6 02:28
by SadServersadmin@i-016fc9e6460102905:~$ curl localhost 5000 curl: (7) Failed to connect to localhost port 80: Connection refused ^C admin@i-016fc9e6460102905:~$ curl localhost:5000 Unauthorizedadmin@i-016fc9e6460102905:~$ vim /usr/bin/as as asciinema admin@i-016fc9e6460102905:~$ vim /usr/bin/asciinema admin@i-016fc9e6460102905:~$ /usr/bin/python3 /usr/bin/asciinema rec -t paris asciinema: recording asciicast to /tmp/tmpf1dsbhc8-ascii.cast asciinema: press <ctrl-d> or type "exit" when you're done admin@i-016fc9e6460102905:~$ vim /usr/bin/asciinema admin@i-016fc9e6460102905:~$ vim /tmp/tmpf1dsbhc8-ascii.cast admin@i-016fc9e6460102905:~$ vim /usr/bin/asciinema admin@i-016fc9e6460102905:~$ vim /home/admin/.bash_history admin@i-016fc9e6460102905:~$
paris/i-016fc9e6460102905 03:47
by SadServers2 2023-09-20T15:58:02 exit 3 2023-12-18T23:23:28 ls 4 2023-12-18T23:23:32 vim webserver.py 5 2023-12-18T23:23:35 ls -l 6 2023-12-18T23:23:37 sudo -l 7 2023-12-18T23:23:44 sudo view webserver.py 8 2023-12-18T23:24:00 ls 9 2023-12-18T23:24:02 ls agent 10 2023-12-18T23:24:08 view agent/check.sh 11 2023-12-18T23:24:22 netstat -nl4 12 2023-12-18T23:24:29 curl 127.0.0.1:5000 13 2023-12-18T23:24:40 curl -v 127.0.0.1:5000 14 2023-12-18T23:25:09 history admin@i-091ee8f6864cabf76:~$ view .bash_history admin@i-091ee8f6864cabf76:~$