paris/i-0707672206f080b13
by SadServersMore by SadServers
-rw-r--r-- 1 root root 0 Nov 28 19:24 setgroups -r--r--r-- 1 root root 0 Nov 28 19:24 smaps -r--r--r-- 1 root root 0 Nov 28 19:24 smaps_rollup -r-------- 1 root root 0 Nov 28 19:24 stack -r--r--r-- 1 root root 0 Nov 28 19:20 stat -r--r--r-- 1 root root 0 Nov 28 19:24 statm -r--r--r-- 1 root root 0 Nov 28 19:20 status -r-------- 1 root root 0 Nov 28 19:24 syscall dr-xr-xr-x 3 root root 0 Nov 28 19:24 task -rw-r--r-- 1 root root 0 Nov 28 19:24 timens_offsets -r--r--r-- 1 root root 0 Nov 28 19:24 timers -rw-rw-rw- 1 root root 0 Nov 28 19:24 timerslack_ns -rw-r--r-- 1 root root 0 Nov 28 19:24 uid_map -r--r--r-- 1 root root 0 Nov 28 19:24 wchan admin@i-0f502522293dd2f2c:/proc/571$ ps axuwwf |"
paris/i-0f502522293dd2f2c 05:01
by SadServersfind: ‘/var/tmp/systemd-private-52eea95e00ec40f0923b8cd5c285895b-systemd-logind./var/log/journal /var/log/journal/ec26942be8219bc22967aa0256120fca find: ‘/var/log/private’: Permission denied find: ‘/var/log/chrony’: Permission denied find: ‘/var/lib/private’: Permission denied find: ‘/var/lib/apt/lists/partial’: Permission denied find: ‘/var/lib/chrony’: Permission denied /var/local /var/mail admin@i-0f5168148868846b7:~$ docker bash: docker: command not found admin@i-0f5168148868846b7:~$ podman bash: podman: command not found admin@i-0f5168148868846b7:~$
paris/i-0f5168148868846b7 05:49
by SadServersdrwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-010d84eaab4d0fc03:~$ cp /home/admin/webserver.py /tmp/ cp: cannot open '/home/admin/webserver.py' for reading: Permission denied admin@i-010d84eaab4d0fc03:~$ admin@i-010d84eaab4d0fc03:~$ ls -la /home/admin/agent/ total 11144 drwxr-xr-x 2 admin root 4096 Sep 24 2023 . drwxr-xr-x 6 admin admin 4096 Sep 24 2023 .. -rwxr-xr-x 1 admin admin 230 Sep 24 2023 check.sh -rwxr-xr-x 1 admin root 11397096 Sep 20 2023 sadagent -rw-r--r-- 1 admin admin 0 Sep 20 2023 sadagent.txt admin@i-010d84eaab4d0fc03:~$ ls -la /home/admin/agent/sadagent -rwxr-xr-x 1 admin root 11397096 Sep 20 2023 /home/admin/agent/sadagent admin@i-010d84eaab4d0fc03:~$