paris/i-006f0e9a73bb6b96a
by SadServersMore by SadServers
drwxr-xr-x 7 admin admin 4096 Mar 4 20:45 . drwxr-xr-x 3 root root 4096 Sep 17 16:44 .. drwx------ 3 admin admin 4096 Sep 20 15:52 .ansible -rw------- 1 admin admin 576 Mar 4 20:45 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 15:56 .config drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py drwsr-sr-x 2 admin admin 4096 Mar 4 20:45 yolo admin@i-0914c01abdff80d82:~$ rmdir yolo admin@i-0914c01abdff80d82:~$ mkdir yolo admin@i-0914c01abdff80d82:~$ chmod +t yolo admin@i-0914c01abdff80d82:~$ mv
paris/i-0914c01abdff80d82 04:15
by SadServersadmin 681 0.0 0.9 6740 4532 pts/0 S<s+ 17:03 0:00 bash -l admin 685 0.0 4.1 98188 19252 pts/0 R<l+ 17:03 0:00 /usr/bin/pythadmin 688 0.0 3.0 24456 14384 pts/0 S<+ 17:03 0:00 /usr/bin/pythadmin 689 0.0 0.1 2480 572 pts/1 S<s 17:03 0:00 sh -c /bin/baadmin 690 0.0 1.0 6952 4716 pts/1 S< 17:03 0:00 /bin/bash admin 834 0.0 0.6 8648 3240 pts/1 R<+ 17:07 0:00 ps -aux admin@i-0855e77fc64d64a54:~$ cat /home/admin/webserver cat: /home/admin/webserver: No such file or directory admin@i-0855e77fc64d64a54:~$ ls /home/admin/ agent webserver.py admin@i-0855e77fc64d64a54:~$ cat /home/admin/webserver.py cat: /home/admin/webserver.py: Permission denied admin@i-0855e77fc64d64a54:~$ ls -l /home/admin/webserver.py -rwxrwx--- 1 root root 360 Sep 24 2023 /home/admin/webserver.py admin@i-0855e77fc64d64a54:~$
paris/i-0855e77fc64d64a54 02:42
by SadServersadmin@i-037723d04d1282399:~$ netstat -tulnp (Not all processes could be identified, non-owned process info will not be shown, you would have to be root to see it all.) Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN tcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN tcp6 0 0 :::22 :::* LISTEN tcp6 0 0 :::6767 :::* LISTEN tcp6 0 0 :::8080 :::* LISTEN udp 0 0 127.0.0.1:323 0.0.0.0:* udp 0 0 0.0.0.0:68 0.0.0.0:* udp6 0 0 fe80::8e1:d4ff:fe9b:546 :::* udp6 0 0 ::1:323 :::* admin@i-037723d04d1282399:~$
paris/i-037723d04d1282399 07:02
by SadServersadmin@i-0871758fae78c248d:~$ curl -A "Mozilla/5.0 (X11; Linux x86_64; rv:60.0) G.0" https://example.com/" > > > ^C admin@i-0871758fae78c248d:~$ ^C admin@i-0871758fae78c248d:~$ ^C admin@i-0871758fae78c248d:~$ curl -A "Mozilla/5.0 (X11; Linux x86_64; rv:60.0) G.0" localhost:5000" > ^C admin@i-0871758fae78c248d:~$ curl -v -A "Mozilla/5.0 (X11; Linux x86_64; rv:60.0/81.0" http:localhost:5000"