command-line-murders/i-01e13446800a4639f
by SadServersMore by SadServers
admin@i-0a31e5daa0d7a50e2:~$ ss -tlpn State Recv-Q Send-Q Local Address:Port Peer Address:Port Process LISTEN 0 128 127.0.0.1:5000 0.0.0.0:* LISTEN 0 128 0.0.0.0:22 0.0.0.0:* LISTEN 0 4096 *:6767 *:* users:(("sLISTEN 0 4096 *:8080 *:* users:(("gLISTEN 0 128 [::]:22 [::]:* admin@i-0a31e5daa0d7a50e2:~$ curl 127.0.0.1:5000 Unauthorizedadmin@i-0a31e5daa0d7a50e2:~$ sudo su
paris/i-0a31e5daa0d7a50e2 00:35
by SadServersroot 614 0.0 0.0 0 0 ? I 11:23 0:00 [kworker/0:3-root 678 0.0 0.0 0 0 ? I 11:23 0:00 [kworker/0:4-admin 709 0.0 0.9 6740 4376 pts/0 S<s+ 11:24 0:00 bash -l admin 714 0.2 4.1 98188 19364 pts/0 S<l+ 11:24 0:00 /usr/bin/pythadmin 717 0.0 3.1 24456 14504 pts/0 R<+ 11:24 0:00 /usr/bin/pythadmin 718 0.0 0.1 2480 508 pts/1 S<s 11:24 0:00 sh -c /bin/baadmin 719 0.0 0.9 6820 4612 pts/1 S< 11:24 0:00 /bin/bash admin 759 0.0 0.6 8648 3248 pts/1 R<+ 11:25 0:00 ps aux admin@i-0c3de957f9712f12c:~$ ls agent webserver.py admin@i-0c3de957f9712f12c:~$ less webserver.py webserver.py: Permission denied admin@i-0c3de957f9712f12c:~$ cat webserver.py cat: webserver.py: Permission denied admin@i-0c3de957f9712f12c:~$ ls -
paris/i-0c3de957f9712f12c 01:23
by SadServersioctl(1, TCGETS, {B38400 opost isig icanon echo ...}) = 0 ioctl(1, TIOCGWINSZ, {ws_row=74, ws_col=126, ws_xpixel=0, ws_ypixel=0}) = 0 openat(AT_FDCWD, ".", O_RDONLY|O_NONBLOCK|O_CLOEXEC|O_DIRECTORY) = 3 fstat(3, {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0 getdents64(3, 0x56467d9f3f60 /* 14 entries */, 32768) = 416 getdents64(3, 0x56467d9f3f60 /* 0 entries */, 32768) = 0 close(3) = 0 fstat(1, {st_mode=S_IFCHR|0620, st_rdev=makedev(0x88, 0x1), ...}) = 0 write(1, "agent data datafile kihei ne"..., 41agent data datafile kihei ) = 41 close(1) = 0 close(2) = 0 exit_group(0) = ? +++ exited with 0 +++ admin@i-013bda2fac98d365e:~$