command-line-murders/i-0a86419b57a044464
by SadServersMore by SadServers
admin@i-0bb664b967d26d93a:~$ curl 127.0.0.1:80 curl: (7) Failed to connect to 127.0.0.1 port 80: Connection refused admin@i-0bb664b967d26d93a:~$ curl 127.0.0.1:443 curl: (7) Failed to connect to 127.0.0.1 port 443: Connection refused admin@i-0bb664b967d26d93a:~$ curl 127.0.0.1:5000 Unauthorizedadmin@i-0bb664b967d26d93a:~$ admin@i-0bb664b967d26d93a:~$ nc localhost 5000
paris/i-0bb664b967d26d93a 00:35
by SadServersDec 16 19:58:09 i-087a04010afc840a2 sudo[686]: pam_unix(sudo:session): session o) by (uid=1000) root@i-087a04010afc840a2:/home/admin# ^C root@i-087a04010afc840a2:/home/admin# tail -f /etc/systemd/system/gotty.service [Service] User=admin Group=admin ExecStart=/usr/local/gotty --permit-write --reconnect --max-connection 5 bash -lWorkingDirectory=/home/admin Restart=on-failure Nice=-20 [Install] WantedBy=multi-user.target
kihei/i-087a04010afc840a2 00:58
by SadServers> GET / HTTP/1.1 > Host: localhost:5000 > Accept: */* > User-Agent: Firefix > * Mark bundle as not supporting multiuse < HTTP/1.1 200 OK < Server: Werkzeug/2.3.7 Python/3.9.2 < Date: Fri, 20 Oct 2023 18:27:19 GMT < Content-Type: text/html; charset=utf-8 < Content-Length: 35 < Connection: close < * Closing connection 0 Welcome! Password is FDZPmh5AX3oiJtadmin@i-09dc8f23dc5f45423:~$
paris/i-09dc8f23dc5f45423 01:53
by SadServersgoroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0f6d76d4e64ebbaa3:~$ less /home/admin/kihei "/home/admin/kihei" may be a binary file. See it anyway? admin@i-0f6d76d4e64ebbaa3:~$ admin@i-0f6d76d4e64ebbaa3:~$ df -h Filesystem Size Used Avail Use% Mounted on udev 217M 0 217M 0% /dev tmpfs 46M 368K 46M 1% /run /dev/nvme0n1p1 7.7G 6.1G 1.2G 84% / tmpfs 228M 12K 228M 1% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock /dev/nvme0n1p15 124M 5.9M 118M 5% /boot/efi admin@i-0f6d76d4e64ebbaa3:~$