paris/i-05463a839cf549c2b
by SadServersMore by SadServers
_chrony 602 0.0 0.7 10856 3596 ? S 19:12 0:00 /usr/sbin/chrroot 609 0.0 3.7 26612 17272 ? Ss 19:12 0:00 /usr/bin/pyth-upgrades/unattended-upgrad _chrony 611 0.0 0.1 10724 552 ? S 19:12 0:00 /usr/sbin/chrroot 913 0.0 0.0 0 0 ? I 19:17 0:00 [kworker/1:1-admin 916 0.0 0.7 5920 3624 pts/0 S<s+ 19:18 0:00 bash -l admin 918 0.2 4.1 98188 19372 pts/0 R<l+ 19:18 0:00 /usr/bin/pythc -t kihei/i-058f99da3418f9 admin 921 0.0 3.2 24456 14984 pts/0 S<+ 19:18 0:00 /usr/bin/pythc -t kihei/i-058f99da3418f9 admin 922 0.0 0.1 2480 568 pts/1 S<s 19:18 0:00 sh -c /bin/baadmin 923 0.0 1.0 6952 4880 pts/1 S< 19:18 0:00 /bin/bash root 947 0.0 0.0 0 0 ? I 19:18 0:00 [kworker/0:0-admin 1046 0.0 0.7 8648 3268 pts/1 R<+ 19:19 0:00 ps waux admin@i-058f99da3418f95da:~$
kihei/i-058f99da3418f95da 06:55
by SadServersnt-Type: application/x-www-form-urlencoded' --data-urlencode 'password=" or 1=1'Access denied!admin@i-09f0e7c74e34fbdd9:~$ curl --location --request POST 'localnt-Type: application/x-www-form-urlencoded' --data-urlencode 'password=" or "1"=Access denied!admin@i-09f0e7c74e34fbdd9:~$ curl --location --request POST 'localnt-Type: application/x-www-form-urlencoded' --data-urlencode 'password=^Cor "1"=admin@i-09f0e7c74e34fbdd9:~$ curl --location --request POST 'localhost:5000' \ --header 'Content-Type: application/x-www-form-urlencoded' \ --data-urlencode 'password='\'' or '\''1'\''='\''1' admin@i-09f0e7c74e34fbdd9:~$ curl --location --request POST 'localhost:5000' \al--header 'Content-Type: application/x-www-form-urlencoded' \ --data-urlencode 'password=' admin@i-09f0e7c74e34fbdd9:~$ curl --location --request POST 'localhost:5000' \al--form 'password="admin"' Access denied!admin@i-09f0e7c74e34fbdd9:~$ curl --location --request POST 'locald="admin"'
monaco/i-09f0e7c74e34fbdd9 05:55
by SadServersadmin@i-06e417f4b5d603c82:~$ ls -l total 8 drwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-06e417f4b5d603c82:~$ chown admin webserver.py chown: changing ownership of 'webserver.py': Operation not permitted admin@i-06e417f4b5d603c82:~$ chmod 777 webserver.py chmod: changing permissions of 'webserver.py': Operation not permitted admin@i-06e417f4b5d603c82:~$ nc localhost 5000 GET / Welcome! Password is FDZPmh5AX3oiJt admin@i-06e417f4b5d603c82:~$ admin@i-06e417f4b5d603c82:~$ admin@i-06e417f4b5d603c82:~$ curl