command-line-murders/i-0057713139fd485bb
by SadServersMore by SadServers
total 52 drwxr-xr-x 7 admin admin 4096 Sep 20 17:51 . drwxr-xr-x 3 root root 4096 Sep 17 16:44 .. drwx------ 3 admin admin 4096 Sep 20 15:52 .ansible -rw------- 1 admin admin 57 Sep 20 15:58 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 15:56 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4096 Sep 20 17:51 agent -rw-r--r-- 1 admin root 705 Sep 20 17:51 consumer.py -rw-r--r-- 1 admin root 760 Sep 20 17:51 producer.py drwxr-xr-x 2 root root 4096 May 16 2022 rabbitmq-cluster-docker-master admin@i-0dd91a304b34f6d63:~$
chennai/i-0dd91a304b34f6d63 00:08
by SadServers140 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 ext4-rsv- 204 root 20 0 64784 12840 11972 S 0.0 2.8 0:00.39 systemd-j 209 root 20 0 0 0 0 I 0.0 0.0 0:00.00 kworker/0 222 root 20 0 19476 5228 4192 S 0.0 1.1 0:00.09 systemd-u 250 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 cryptd
kihei/i-08de8893c7697f828 07:05
by SadServers-rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-093333d0150041494:~$ cd .. admin@i-093333d0150041494:/home$ find / -perm -4000 -type f 2>/dev/null /usr/lib/openssh/ssh-keysign /usr/lib/dbus-1.0/dbus-daemon-launch-helper /usr/bin/chsh /usr/bin/umount /usr/bin/mount /usr/bin/passwd /usr/bin/newgrp /usr/bin/sudo /usr/bin/chfn /usr/bin/su /usr/bin/gpasswd admin@i-093333d0150041494:/home$
paris/i-093333d0150041494 03:18
by SadServers# The program is typically sudo, sudoers.so, sudoreplay or visudo. # # Subsystems vary based on the program; "all" matches all subsystems. # Priority may be crit, err, warn, notice, diag, info, trace or debug. # Multiple subsystem@priority may be specified, separated by a comma. # #Debug sudo /var/log/sudo_debug all@debug #Debug sudoers.so /var/log/sudoers_debug all@debug admin@i-020f08eb573cc1e85:~$ ls agent webserver.py admin@i-020f08eb573cc1e85:~$ cat /etc/sudo sudo.conf sudo_logsrvd.conf sudoers sudoers.d/ admin@i-020f08eb573cc1e85:~$ cat /etc/sudoers cat: /etc/sudoers: Permission denied admin@i-020f08eb573cc1e85:~$