command-line-murders/i-07b29805c782c7969
by SadServersMore by SadServers
# The program is typically sudo, sudoers.so, sudoreplay or visudo. # # Subsystems vary based on the program; "all" matches all subsystems. # Priority may be crit, err, warn, notice, diag, info, trace or debug. # Multiple subsystem@priority may be specified, separated by a comma. # #Debug sudo /var/log/sudo_debug all@debug #Debug sudoers.so /var/log/sudoers_debug all@debug admin@i-020f08eb573cc1e85:~$ ls agent webserver.py admin@i-020f08eb573cc1e85:~$ cat /etc/sudo sudo.conf sudo_logsrvd.conf sudoers sudoers.d/ admin@i-020f08eb573cc1e85:~$ cat /etc/sudoers cat: /etc/sudoers: Permission denied admin@i-020f08eb573cc1e85:~$
paris/i-020f08eb573cc1e85 06:02
by SadServersroot 614 0.0 0.0 0 0 ? I 11:23 0:00 [kworker/0:3-root 678 0.0 0.0 0 0 ? I 11:23 0:00 [kworker/0:4-admin 709 0.0 0.9 6740 4376 pts/0 S<s+ 11:24 0:00 bash -l admin 714 0.2 4.1 98188 19364 pts/0 S<l+ 11:24 0:00 /usr/bin/pythadmin 717 0.0 3.1 24456 14504 pts/0 R<+ 11:24 0:00 /usr/bin/pythadmin 718 0.0 0.1 2480 508 pts/1 S<s 11:24 0:00 sh -c /bin/baadmin 719 0.0 0.9 6820 4612 pts/1 S< 11:24 0:00 /bin/bash admin 759 0.0 0.6 8648 3248 pts/1 R<+ 11:25 0:00 ps aux admin@i-0c3de957f9712f12c:~$ ls agent webserver.py admin@i-0c3de957f9712f12c:~$ less webserver.py webserver.py: Permission denied admin@i-0c3de957f9712f12c:~$ cat webserver.py cat: webserver.py: Permission denied admin@i-0c3de957f9712f12c:~$ ls -
paris/i-0c3de957f9712f12c 01:23
by SadServersadmin@i-058087a6dfc6f1217:~$ /home/admin/kihei panic: exit status 1 goroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-058087a6dfc6f1217:~$ ps aux | grep kihei admin 682 0.1 4.1 98188 19204 pts/0 S<l+ 09:17 0:00 /usr/bin/pyth-t kihei/i-058087a6dfc6f1217 -q -i 2 /var/log/cast/i-058087a6dfc6f1217 admin 685 0.0 3.0 24456 14420 pts/0 S<+ 09:17 0:00 /usr/bin/pyth-t kihei/i-058087a6dfc6f1217 -q -i 2 /var/log/cast/i-058087a6dfc6f1217 admin 793 0.0 0.1 5264 704 pts/1 S<+ 09:19 0:00 grep kihei admin@i-058087a6dfc6f1217:~$