command-line-murders/i-040333cb27e21cfb9
by SadServersMore by SadServers
drwxr-xr-x 3 admin admin 4096 Sep 20 15:56 .config drwxr-xr-x 3 admin admin 4096 Dec 24 11:10 .local -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh -rw-r--r-- 1 admin admin 1024 Dec 24 11:10 .webserver.py.swp drwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-042a55932de644732:~$ su - Password: su: Authentication failure admin@i-042a55932de644732:~$ su - Password: su: Authentication failure admin@i-042a55932de644732:~$ ^C admin@i-042a55932de644732:~$ curl
paris/i-042a55932de644732 02:06
by SadServers/dev/nvme0n1p1 7.7G 6.1G 1.2G 84% / admin@i-0cb4275c09b1a51bf:~$ ls -l total 5245048 drwxr-xr-x 2 admin root 4096 Sep 17 2023 agent drwxr-xr-x 2 admin root 4096 Feb 26 13:33 data -rw-r--r-- 1 root root 5368709120 Sep 17 2023 datafile -rwxr-xr-x 1 admin root 2207109 Sep 17 2023 kihei admin@i-0cb4275c09b1a51bf:~$ du -sh . 5.1G . admin@i-0cb4275c09b1a51bf:~$ strings datafile |less bash: strings: command not found admin@i-0cb4275c09b1a51bf:~$ admin@i-0cb4275c09b1a51bf:~$ cd / admin@i-0cb4275c09b1a51bf:/$ cd admin@i-0cb4275c09b1a51bf:~$
kihei/i-0cb4275c09b1a51bf 03:42
by SadServersadmin 686 0.0 0.9 6740 4540 pts/0 S<s+ 22:25 0:00 bash -l admin 690 0.8 4.1 98188 19416 pts/0 D<l+ 22:25 0:00 /usr/bin/pyth-t paris/i-07602503257110b80 -q -i 2 /var/log/cast/i-076025032571 admin 693 0.0 3.0 24456 14444 pts/0 R<+ 22:25 0:00 /usr/bin/pyth-t paris/i-07602503257110b80 -q -i 2 /var/log/cast/i-076025032571 admin 694 0.0 0.1 2480 512 pts/1 S<s 22:25 0:00 sh -c /bin/baadmin 695 0.0 0.9 6820 4460 pts/1 S< 22:25 0:00 /bin/bash admin 730 0.0 0.6 8648 3160 pts/1 R<+ 22:26 0:00 ps aux admin@i-07602503257110b80:~$ ps aux | grep nginx admin 732 0.0 0.1 5264 640 pts/1 S<+ 22:26 0:00 grep nginx admin@i-07602503257110b80:~$ ps aux | grep apache admin 734 0.0 0.1 5264 640 pts/1 S<+ 22:26 0:00 grep apache admin@i-07602503257110b80:~$ ls agent webserver.py admin@i-07602503257110b80:~$ cat webserver.py