command-line-murders/i-057898ace39765d92
by SadServersMore by SadServers
total 11M -rwxr-xr-x 1 admin root 11M Sep 20 15:53 sadagent -rw-r--r-- 1 admin admin 0 Sep 20 15:53 sadagent.txt -rwxr-xr-x 1 admin admin 230 Sep 24 23:20 check.sh admin@i-0cfcaf1d38addd2ba:~/agent$ cat sadagent.txt admin@i-0cfcaf1d38addd2ba:~/agent$ nc localhost 5000 admin@i-0cfcaf1d38addd2ba:~/agent$ GET / bash: GET: command not found admin@i-0cfcaf1d38addd2ba:~/agent$ GET / bash: GET: command not found admin@i-0cfcaf1d38addd2ba:~/agent$ curl --user-agent "password" localhost:5000 Welcome! Password is FDZPmh5AX3oiJtadmin@i-0cfcaf1d38addd2ba:~/agent$ curl --use5000
paris/i-0cfcaf1d38addd2ba 03:22
by SadServersadmin 771 697 0 16:53 pts/1 00:00:00 more admin@i-09f185fddd1e81888:~$ history 1 2023-09-20T15:57:57 > /home/admin/.bash_history 2 2023-09-20T15:58:02 exit 3 2025-03-07T16:52:03 sudo su - 4 2025-03-07T16:52:06 ls -l 5 2025-03-07T16:52:14 lsof -i :5000 6 2025-03-07T16:52:18 sudo lsof -i :5000 7 2025-03-07T16:52:22 ps -ef 8 2025-03-07T16:52:38 nstat -tlnp 9 2025-03-07T16:52:44 netstat -tlnp 10 2025-03-07T16:52:56 systemctl status 11 2025-03-07T16:53:15 ps -ef | more 12 2025-03-07T16:54:05 history admin@i-09f185fddd1e81888:~$ ls -l /home/admin/webserver.py
paris/i-09f185fddd1e81888 02:23
by SadServersgoroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0f6d76d4e64ebbaa3:~$ less /home/admin/kihei "/home/admin/kihei" may be a binary file. See it anyway? admin@i-0f6d76d4e64ebbaa3:~$ admin@i-0f6d76d4e64ebbaa3:~$ df -h Filesystem Size Used Avail Use% Mounted on udev 217M 0 217M 0% /dev tmpfs 46M 368K 46M 1% /run /dev/nvme0n1p1 7.7G 6.1G 1.2G 84% / tmpfs 228M 12K 228M 1% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock /dev/nvme0n1p15 124M 5.9M 118M 5% /boot/efi admin@i-0f6d76d4e64ebbaa3:~$