command-line-murders/i-0b170140fb08c77f8
by SadServersMore by SadServers
-upgrades/unattended-upgrade-shutdown -- root 685 0.0 0.0 0 0 ? I 04:20 0:00 [kworker/1:4-admin 687 0.0 0.9 6740 4512 pts/0 S<s+ 04:20 0:00 bash -l admin 691 0.5 4.1 98188 19348 pts/0 S<l+ 04:20 0:00 /usr/bin/pythc -t paris/i-0cea73f15d68f034f -q -i 2 / admin 694 0.0 3.0 24456 14436 pts/0 S<+ 04:20 0:00 /usr/bin/pythc -t paris/i-0cea73f15d68f034f -q -i 2 / admin 695 0.0 0.1 2480 572 pts/1 S<s 04:20 0:00 sh -c /bin/baadmin 696 0.0 1.0 6952 4724 pts/1 S< 04:20 0:00 /bin/bash admin 709 0.0 0.6 8648 3240 pts/1 R<+ 04:20 0:00 ps aux admin@i-0cea73f15d68f034f:~$ ps aux|grep -i web root 574 0.5 6.0 107132 28320 ? Ss 04:20 0:00 /usr/bin/pyth.py admin 712 0.0 0.1 5132 640 pts/1 S<+ 04:20 0:00 grep -i web admin@i-0cea73f15d68f034f:~$
paris/i-0cea73f15d68f034f 00:54
by SadServers> GET / HTTP/1.1 > Host: localhost:5000 > User-Agent: curl/7.74.0 > Accept: */* > * Mark bundle as not supporting multiuse < HTTP/1.1 200 OK < Server: Werkzeug/2.3.7 Python/3.9.2 < Date: Tue, 06 Feb 2024 07:30:57 GMT < Content-Type: text/html; charset=utf-8 < Content-Length: 12 < Connection: close < * Closing connection 0 Unauthorizedadmin@i-03d5c3bada9b64230:~$
paris/i-03d5c3bada9b64230 03:12
by SadServerscrw------- 1 root root 10, 241 Oct 30 21:24 vhost-vsock lrwxrwxrwx 1 root root 7 Oct 30 21:24 xvda -> nvme0n1 lrwxrwxrwx 1 root root 9 Oct 30 21:25 xvda1 -> nvme0n1p1 lrwxrwxrwx 1 root root 10 Oct 30 21:24 xvda14 -> nvme0n1p14 lrwxrwxrwx 1 root root 10 Oct 30 21:24 xvda15 -> nvme0n1p15 crw-rw-rw- 1 root root 1, 5 Oct 30 21:24 zero admin@i-03eef21126bfed599:~$ lsblk NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT nvme1n1 259:0 0 1G 0 disk nvme0n1 259:1 0 8G 0 disk ├─nvme0n1p1 259:3 0 7.9G 0 part / ├─nvme0n1p14 259:4 0 3M 0 part └─nvme0n1p15 259:5 0 124M 0 part /boot/efi nvme2n1 259:2 0 1G 0 disk admin@i-03eef21126bfed599:~$ pvcreate
kihei/i-03eef21126bfed599 05:24
by SadServers1 134 2 26 4 54 573 594 63 729 bus driver 10 14 20 27 462 55 574 596 64 73 cgroups dynamic_debug11 15 212 28 49 557 579 597 680 762 cmdline execdomains 114 16 22 29 5 558 58 6 684 78 consoles fb 115 17 23 3 50 56 582 60 687 8 cpuinfo filesystems 12 18 235 30 51 561 583 61 688 9 crypto fs 13 19 24 347 52 563 584 618 689 acpi devices interrupts 133 195 25 389 53 57 59 62 7 buddyinfo diskstats iomem admin@i-0c5c0bccbc8341a7b:~$ ls /proc/^C admin@i-0c5c0bccbc8341a7b:~$ ^C admin@i-0c5c0bccbc8341a7b:~$ ^C admin@i-0c5c0bccbc8341a7b:~$ ^C admin@i-0c5c0bccbc8341a7b:~$ ^C admin@i-0c5c0bccbc8341a7b:~$ ^C admin@i-0c5c0bccbc8341a7b:~$ ps -aux | grep p