command-line-murders/i-037d4ec437844d425
by SadServersMore by SadServers
tcp ESTAB 0 0 [::ffff:172.31. [::ffff:172.31.16.109]:49770 timer:(keepalive,3.216ms,0) admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$ lsof -i:5000 admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$ lsof -i COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME gotty 558 admin 6u IPv6 10895 0t0 TCP *:http-alt (LISTEN) gotty 558 admin 7u IPv6 12340 0t0 TCP ip-172-31-40-35.us-east-2.co>ip-172-31-16-109.us-east-2.compute.internal:49770 (ESTABLISHED) sadagent 559 admin 7u IPv6 1958 0t0 TCP *:6767 (LISTEN) admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$
paris/i-0bce630416db45b25 03:00
by SadServers> GET / HTTP/1.1 > Host: sth:5000 > User-Agent: curl/7.74.0 > Accept: */* > * Mark bundle as not supporting multiuse < HTTP/1.1 200 OK < Server: Werkzeug/2.3.7 Python/3.9.2 < Date: Wed, 18 Dec 2024 19:41:10 GMT < Content-Type: text/html; charset=utf-8 < Content-Length: 12 < Connection: close < * Closing connection 0 Unauthorizedadmin@i-0e74e27947cf1a85c:~$ curl sth:5000/[0-]
paris/i-0e74e27947cf1a85c 03:51
by SadServersadmin@i-0bf562d53de649339:~/agent$ cd ../ admin@i-0bf562d53de649339:~$ ls -lah total 44K drwxr-xr-x 6 admin admin 4.0K Sep 24 23:20 . drwxr-xr-x 3 root root 4.0K Sep 17 16:44 .. drwx------ 3 admin admin 4.0K Sep 20 15:52 .ansible -rw------- 1 admin admin 186 Jan 18 18:58 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3.5K Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4.0K Sep 20 15:56 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4.0K Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4.0K Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-0bf562d53de649339:~$ curl -v http://localhos