command-line-murders/i-06d6b09b136773d92
by SadServersMore by SadServers
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin _apt:x:100:65534::/nonexistent:/usr/sbin/nologin messagebus:x:101:101::/nonexistent:/usr/sbin/nologin uuidd:x:102:102::/run/uuidd:/usr/sbin/nologin tcpdump:x:103:103::/nonexistent:/usr/sbin/nologin _chrony:x:104:104:Chrony daemon,,,:/var/lib/chrony:/usr/sbin/nologin systemd-network:x:105:106:systemd Network Management,,,:/run/systemd:/usr/sbin/nsystemd-resolve:x:106:107:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin sshd:x:107:65534::/run/sshd:/usr/sbin/nologin systemd-timesync:x:999:999:systemd Time Synchronization:/:/usr/sbin/nologin systemd-coredump:x:998:998:systemd Core Dumper:/:/usr/sbin/nologin admin:x:1000:1000:Debian:/home/admin:/bin/bash admin@i-0f0c9e55a5c0d9a6f:~$ ls agent webserver.py admin@i-0f0c9e55a5c0d9a6f:~$ tcpdump
paris/i-0f0c9e55a5c0d9a6f 05:06
by SadServersinary_Operatorunicode.IDS_Trinary_Operatorunicode.Ideographicunicode.Join_Controcunicode.Other_Default_Ignorable_Code_Pointunicode.Other_Grapheme_Extendunicode.e.Other_Uppercaseunicode.Pattern_Syntaxunicode.Pattern_White_Spaceunicode.Prepennicode.Sentence_Terminalunicode.Soft_Dottedunicode.Terminal_Punctuationunicode.U.FoldCategoryunicode.foldLunicode.foldLlunicode.foldLtunicode.foldLuunicode.foldtedinternal/cpu.DebugOptionsinternal/cpu.CacheLineSizeinternal/cpu.X86internal/co.itab.*flag.boolValue,flag.Valuego.itab.*os.File,io.Writergo.itab.*strconv.NumEitab.*flag.float64Value,flag.Valuego.itab.*flag.intValue,flag.Valuego.itab.*flag.Valuego.itab.*flag.uint64Value,flag.Valuego.itab.*strings.Builder,io.Writergo.itab.*os.File,io.Readergo.itab.syscall.Signal,os.Signalgo.itab.*io/fs.PathError,eWritergo.itab.*os.fileStat,io/fs.FileInfogo.itab.*io.LimitedReader,io.Readergo.itab.*bufio.Reader,io.Readergo.itab.os/user.UnknownUserIdError,errorgo.itab.*inteb.*internal/fmtsort.SortedMap,sort.Interfacego.itab.runtime.errorString,error_cgo_munmap_cgo_sigactionruntime.mainPCgo.itab.*internal/poll.DeadlineExceededErrorersion.strruntime.modinfo.strtype.*runtime.textsectionmapadmin@i-08c990dcb570e62
i-08c990dcb570e6294 00:10
by SadServersadmin@i-01a673ffc56190f9c:~$ du -sh /tmp du: cannot read directory '/tmp/systemd-private-46dfb1a354a74f1fb453fc71b86b3775hrony.service-ebxZAh': Permission denied du: cannot read directory '/tmp/systemd-private-46dfb1a354a74f1fb453fc71b86b3775ystemd-logind.service-qF3RSh': Permission denied 32K /tmp admin@i-01a673ffc56190f9c:~$ sudo du -sh /tmp 40K /tmp admin@i-01a673ffc56190f9c:~$ sudo du -sh / du: cannot access '/proc/823/task/823/fd/4': No such file or directory du: cannot access '/proc/823/task/823/fdinfo/4': No such file or directory du: cannot access '/proc/823/fd/3': No such file or directory du: cannot access '/proc/823/fdinfo/3': No such file or directory 6.1G / admin@i-01a673ffc56190f9c:~$
kihei/i-01a673ffc56190f9c 03:37
by SadServersif [[ "$res" = "Done." ]] then echo -n "OK" else echo -n "NO" fi admin@i-040166f3418bf5873:~/agent$ cd admin@i-040166f3418bf5873:~$ /home/admin/kihei panic: exit status 1 goroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-040166f3418bf5873:~$ ls