kihei/i-0796b0b18597b116d
by SadServersMore by SadServers
[:delay_enter=DELAY][:delay_exit=DELAY][:when=WHEN], --inject=SET[:error=ERRNO|:retval=VALUE][:signal=SIG][:syscall=SYSCALL] [:delay_enter=DELAY][:delay_exit=DELAY][:when=WHEN] perform syscall tampering for the syscalls in SET delay: microseconds or NUMBER{s|ms|us|ns} when: FIRST[..LAST][+[STEP]] -e fault=SET[:error=ERRNO][:when=WHEN], --fault=SET[:error=ERRNO][:when=WHEN] synonym for -e inject with default ERRNO set to ENOSYS. Miscellaneous: -d, --debug enable debug output to stderr -h, --help print help message --seccomp-bpf enable seccomp-bpf filtering -V, --version print version admin@i-054157b3157fdc4cd:~$ strace ./kihei -v
kihei/i-054157b3157fdc4cd 01:21
by SadServersadmin@i-0eb97cd7b88e01b26:~$ ls agent webserver.py admin@i-0eb97cd7b88e01b26:~$ cd we bash: cd: we: No such file or directory admin@i-0eb97cd7b88e01b26:~$ ls agent/ check.sh sadagent sadagent.txt admin@i-0eb97cd7b88e01b26:~$ cd .. admin@i-0eb97cd7b88e01b26:/home$ ls
paris/i-0eb97cd7b88e01b26 00:43
by SadServersls: cannot access '/pid/579': No such file or directory admin@i-02fded2ca795f43ce:~$ ls /proc/579 ls: cannot read symbolic link '/proc/579/cwd': Permission denied ls: cannot read symbolic link '/proc/579/root': Permission denied ls: cannot read symbolic link '/proc/579/exe': Permission denied arch_status cgroup coredump_filter environ gid_map map_files mountattr clear_refs cpu_resctrl_groups exe io maps mountautogroup cmdline cpuset fd limits mem net auxv comm cwd fdinfo loginuid mountinfo ns admin@i-02fded2ca795f43ce:~$ ls /proc/579^C admin@i-02fded2ca795f43ce:~$ ^C admin@i-02fded2ca795f43ce:~$ ^C admin@i-02fded2ca795f43ce:~$ /proc/579/root curl localhost:5000 bash: /proc/579/root: Permission denied admin@i-02fded2ca795f43ce:~$