command-line-murders/i-0fc986bc0324ae367
by SadServersMore by SadServers
root 593 0.0 1.4 13488 6708 ? Ss 11:53 0:00 /lib/systemd/_chrony 597 0.0 0.7 10856 3636 ? S 11:53 0:00 /usr/sbin/chrroot 598 0.0 1.5 13348 7144 ? Ss 11:53 0:00 sshd: /usr/sbroot 599 0.0 0.3 2872 1684 tty1 Ss+ 11:53 0:00 /sbin/agetty root 600 0.0 0.4 4396 2100 ttyS0 Ss+ 11:53 0:00 /sbin/agetty _chrony 601 0.0 0.1 10724 548 ? S 11:53 0:00 /usr/sbin/chrroot 622 0.0 3.7 26612 17332 ? Ss 11:53 0:00 /usr/bin/pythroot 677 0.0 0.0 0 0 ? I 11:53 0:00 [kworker/1:4-admin 789 0.0 0.7 5920 3552 pts/0 S<s+ 11:57 0:00 bash -l admin 791 0.7 4.1 98188 19356 pts/0 R<l+ 11:57 0:00 /usr/bin/pythadmin 794 0.0 3.1 24456 14504 pts/0 S<+ 11:57 0:00 /usr/bin/pythadmin 795 0.0 0.1 2480 508 pts/1 S<s 11:57 0:00 sh -c /bin/baadmin 796 0.0 0.9 6820 4532 pts/1 S< 11:57 0:00 /bin/bash admin 799 0.0 0.6 8648 3180 pts/1 R<+ 11:57 0:00 ps aux admin@i-0f090ab9a046ad6f3:~$ ps aux | gtr
kihei/i-0f090ab9a046ad6f3 00:16
by SadServersadmin@i-0e3126c91f22b8e7e:~$ cd /home/admin/ admin@i-0e3126c91f22b8e7e:~$ ls agent data datafile kihei admin@i-0e3126c91f22b8e7e:~$ ps aux | grep kihei admin 733 0.4 4.1 98188 19420 pts/0 S<l+ 21:13 0:00 /usr/bin/pyth-t kihei/i-0e3126c91f22b8e7e -q -i 2 /var/log/cast/i-0e3126c91f22b8e7e admin 736 0.0 3.0 24456 14364 pts/0 S<+ 21:13 0:00 /usr/bin/pyth-t kihei/i-0e3126c91f22b8e7e -q -i 2 /var/log/cast/i-0e3126c91f22b8e7e admin 747 0.0 0.1 5264 696 pts/1 S<+ 21:14 0:00 grep kihei admin@i-0e3126c91f22b8e7e:~$ chmod -R a-w /var/log/cast/ admin@i-0e3126c91f22b8e7e:~$
kihei/i-0e3126c91f22b8e7e 00:44
by SadServersadmin@i-0dc1e7b02108a472f:~$ curl localhost:5000 Unauthorizedadmin@i-0dc1e7b02108a472f:~$ curl localhost:5000 GET / Unauthorizedcurl: (6) Could not resolve host: GET curl: (3) URL using bad/illegal format or missing URL admin@i-0dc1e7b02108a472f:~$ admin@i-0dc1e7b02108a472f:~$ curl localhost:5000 GET / Unauthorizedcurl: (6) Could not resolve host: GET curl: (3) URL using bad/illegal format or missing URL admin@i-0dc1e7b02108a472f:~$ admin@i-0dc1e7b02108a472f:~$ curl --user-agent "whatever" localhost:5000 Welcome! Password is FDZPmh5AX3oiJtadmin@i-0dc1e7b02108a472f:~$ cd /home/