command-line-murders/i-06d49fb711db9521d
by SadServersMore by SadServers
local-fs-pre.target static - local-fs.target static - multi-user.target static - network-online.target static - admin@i-046eb98bd90d24c4a:~$ sudo -l Matching Defaults entries for admin on i-046eb98bd90d24c4a: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bi User admin may run the following commands on i-046eb98bd90d24c4a: (ALL : ALL) ALL (ALL) NOPASSWD: /sbin/shutdown admin@i-046eb98bd90d24c4a:~$ sudo /sbin/shutdown Shutdown scheduled for Fri 2024-02-23 19:06:27 UTC, use 'shutdown -c' to cancel.admin@i-046eb98bd90d24c4a:~$
paris/i-046eb98bd90d24c4a 05:02
by SadServerswrite(2, "main.main", 9main.main) = 9 write(2, "(", 1() = 1 write(2, ")\n", 2) ) = 2 write(2, "\t", 1 ) = 1 write(2, "./main.go", 9./main.go) = 9 write(2, ":", 1:) = 1 write(2, "64", 264) = 2 write(2, " +", 2 +) = 2 write(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-035d976ba3c56dd73:~$
kihei/i-035d976ba3c56dd73 00:05
by SadServers[sudo] password for admin: ^Csudo: 1 incorrect password attempt admin@i-09b7dc79be18d538a:~$ ^C admin@i-09b7dc79be18d538a:~$ netstat -an --tcp --program (Not all processes could be identified, non-owned process info will not be shown, you would have to be root to see it all.) Active Internet connections (servers and established) Proto Recv-Q Send-Q Local Address Foreign Address State tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN tcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN tcp6 0 0 :::6767 :::* LISTEN tcp6 0 0 :::8080 :::* LISTEN tcp6 0 0 :::22 :::* LISTEN tcp6 0 249 172.31.37.243:8080 172.31.16.109:41784 ESTABLISHED admin@i-09b7dc79be18d538a:~$
paris/i-09b7dc79be18d538a 01:13
by SadServerswrite(2, "main.main", 9main.main) = 9 write(2, "(", 1() = 1 write(2, ")\n", 2) ) = 2 write(2, "\t", 1 ) = 1 write(2, "./main.go", 9./main.go) = 9 write(2, ":", 1:) = 1 write(2, "64", 264) = 2 write(2, " +", 2 +) = 2 write(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-0a15686ccdc37dbde:~$ strace ./kihei | grep /home/admin