kihei/i-0de4925f02641172c
by SadServersMore by SadServers
Dec 16 19:58:09 i-087a04010afc840a2 sudo[686]: pam_unix(sudo:session): session o) by (uid=1000) root@i-087a04010afc840a2:/home/admin# ^C root@i-087a04010afc840a2:/home/admin# tail -f /etc/systemd/system/gotty.service [Service] User=admin Group=admin ExecStart=/usr/local/gotty --permit-write --reconnect --max-connection 5 bash -lWorkingDirectory=/home/admin Restart=on-failure Nice=-20 [Install] WantedBy=multi-user.target
kihei/i-087a04010afc840a2 00:58
by SadServersdrwxr-xr-x 7 admin admin 4096 Dec 6 15:59 . drwxr-xr-x 3 root root 4096 Sep 17 16:44 .. drwx------ 3 admin admin 4096 Sep 17 17:15 .ansible -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Dec 6 15:59 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4096 Sep 17 17:28 agent drwxr-xr-x 2 admin root 4096 Sep 17 17:28 data -rw-r--r-- 1 root root 5368709120 Sep 17 17:28 datafile -rwxr-xr-x 1 admin root 2207109 Sep 17 17:28 kihei admin@i-06aaa324a79f9607e:~$ less kihei "kihei" may be a binary file. See it anyway? admin@i-06aaa324a79f9607e:~$
kihei/i-06aaa324a79f9607e 00:49
by SadServersadmin@i-08bead324c6bc394c:~$ admin@i-08bead324c6bc394c:~$ admin@i-08bead324c6bc394c:~$ netstat -tnlp (Not all processes could be identified, non-owned process info will not be shown, you would have to be root to see it all.) Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State tcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN tcp6 0 0 :::6767 :::* LISTEN tcp6 0 0 :::8080 :::* LISTEN tcp6 0 0 :::22 :::* LISTEN admin@i-08bead324c6bc394c:~$ admin@i-08bead324c6bc394c:~$ admin@i-08bead324c6bc394c:~$