command-line-murders/i-0df1730d9c6a5c27d
by SadServersMore by SadServers
admin@i-001eda64855cc97ed:~$ id -a uid=1000(admin) gid=1000(admin) groups=1000(admin),4(adm),20(dialout),24(cdrom),udio),30(dip),44(video),46(plugdev),109(netdev) admin@i-001eda64855cc97ed:~$ sudo vim We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: sudo: a password is required admin@i-001eda64855cc97ed:~$ sudo -l
paris/i-001eda64855cc97ed 03:34
by SadServersroot 593 0.0 1.4 13488 6708 ? Ss 11:53 0:00 /lib/systemd/_chrony 597 0.0 0.7 10856 3636 ? S 11:53 0:00 /usr/sbin/chrroot 598 0.0 1.5 13348 7144 ? Ss 11:53 0:00 sshd: /usr/sbroot 599 0.0 0.3 2872 1684 tty1 Ss+ 11:53 0:00 /sbin/agetty root 600 0.0 0.4 4396 2100 ttyS0 Ss+ 11:53 0:00 /sbin/agetty _chrony 601 0.0 0.1 10724 548 ? S 11:53 0:00 /usr/sbin/chrroot 622 0.0 3.7 26612 17332 ? Ss 11:53 0:00 /usr/bin/pythroot 677 0.0 0.0 0 0 ? I 11:53 0:00 [kworker/1:4-admin 789 0.0 0.7 5920 3552 pts/0 S<s+ 11:57 0:00 bash -l admin 791 0.7 4.1 98188 19356 pts/0 R<l+ 11:57 0:00 /usr/bin/pythadmin 794 0.0 3.1 24456 14504 pts/0 S<+ 11:57 0:00 /usr/bin/pythadmin 795 0.0 0.1 2480 508 pts/1 S<s 11:57 0:00 sh -c /bin/baadmin 796 0.0 0.9 6820 4532 pts/1 S< 11:57 0:00 /bin/bash admin 799 0.0 0.6 8648 3180 pts/1 R<+ 11:57 0:00 ps aux admin@i-0f090ab9a046ad6f3:~$ ps aux | gtr
kihei/i-0f090ab9a046ad6f3 00:16
by SadServerscheck.sh sadagent sadagent.txt admin@i-095ed92c0df54793b:~$ cat agent/ check.sh sadagent sadagent.txt admin@i-095ed92c0df54793b:~$ cat agent/sadagent.txt | tr -cd "[:print:]" admin@i-095ed92c0df54793b:~$ admin@i-095ed92c0df54793b:~$ admin@i-095ed92c0df54793b:~$ admin@i-095ed92c0df54793b:~$ apt install strings E: Could not open lock file /var/lib/dpkg/lock-frontend - open (13: Permission dE: Unable to acquire the dpkg frontend lock (/var/lib/dpkg/lock-frontend), are yadmin@i-095ed92c0df54793b:~$ telnet localhost 5000 Trying 127.0.0.1... Connected to localhost. Escape character is '^]'.