paris/i-00c8d7508d4dbeee3
by SadServersMore by SadServers
-rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout drwxr-xr-x 3 root root 4096 Sep 17 2023 .. drwx------ 2 admin admin 4096 Sep 17 2023 .ssh drwx------ 3 admin admin 4096 Sep 20 2023 .ansible drwxr-xr-x 3 admin admin 4096 Sep 20 2023 .config -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py drwxr-xr-x 6 admin admin 4096 Sep 24 2023 . drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rw------- 1 admin admin 359 Feb 4 03:35 .bash_history admin@i-0f4b72b9b2118ab71:~$ whoami admin admin@i-0f4b72b9b2118ab71:~$ chown admin webserver.py chown: changing ownership of 'webserver.py': Operation not permitted admin@i-0f4b72b9b2118ab71:~$ less .bash_history admin@i-0f4b72b9b2118ab71:~$ cd
paris/i-0f4b72b9b2118ab71 02:29
by SadServersadmin@i-0dbd5dce9178f03c1:~$ ls data lost+found admin@i-0dbd5dce9178f03c1:~$ touch data/newdatafile touch: cannot touch 'data/newdatafile': Permission denied admin@i-0dbd5dce9178f03c1:~$ sudo touch data/newdatafile admin@i-0dbd5dce9178f03c1:~$ sudo chown admin:admin data/newdatafile admin@i-0dbd5dce9178f03c1:~$ ./kihei panic: remove /home/admin/data/newdatafile: permission denied goroutine 1 [running]: main.main() ./main.go:50 +0x48d admin@i-0dbd5dce9178f03c1:~$ ls -alh /home/admin/data/newdatafile -rw-r--r-- 1 admin admin 0 Mar 8 16:31 /home/admin/data/newdatafile admin@i-0dbd5dce9178f03c1:~$
kihei/i-0dbd5dce9178f03c1 03:59
by SadServers_chrony 602 0.0 0.7 10856 3596 ? S 19:12 0:00 /usr/sbin/chrroot 609 0.0 3.7 26612 17272 ? Ss 19:12 0:00 /usr/bin/pyth-upgrades/unattended-upgrad _chrony 611 0.0 0.1 10724 552 ? S 19:12 0:00 /usr/sbin/chrroot 913 0.0 0.0 0 0 ? I 19:17 0:00 [kworker/1:1-admin 916 0.0 0.7 5920 3624 pts/0 S<s+ 19:18 0:00 bash -l admin 918 0.2 4.1 98188 19372 pts/0 R<l+ 19:18 0:00 /usr/bin/pythc -t kihei/i-058f99da3418f9 admin 921 0.0 3.2 24456 14984 pts/0 S<+ 19:18 0:00 /usr/bin/pythc -t kihei/i-058f99da3418f9 admin 922 0.0 0.1 2480 568 pts/1 S<s 19:18 0:00 sh -c /bin/baadmin 923 0.0 1.0 6952 4880 pts/1 S< 19:18 0:00 /bin/bash root 947 0.0 0.0 0 0 ? I 19:18 0:00 [kworker/0:0-admin 1046 0.0 0.7 8648 3268 pts/1 R<+ 19:19 0:00 ps waux admin@i-058f99da3418f95da:~$