command-line-murders/i-02b0978a95df0c4b9
by SadServersMore by SadServers
-rwxr-xr-x 1 admin root 2.2M Sep 17 17:28 kihei admin@i-061e6f1896de4e4aa:~$ tar -czvf datafile.tar.gz datafile datafile admin@i-061e6f1896de4e4aa:~$ ls -lh total 5.1G drwxr-xr-x 2 admin root 4.0K Sep 17 17:28 agent drwxr-xr-x 2 admin root 4.0K Dec 12 15:18 data -rw-r--r-- 1 root root 5.0G Sep 17 17:28 datafile -rw-r--r-- 1 admin admin 5.0M Dec 12 15:25 datafile.tar.gz -rwxr-xr-x 1 admin root 2.2M Sep 17 17:28 kihei admin@i-061e6f1896de4e4aa:~$ true > datafile bash: datafile: Permission denied admin@i-061e6f1896de4e4aa:~$ sudo true > datafile bash: datafile: Permission denied admin@i-061e6f1896de4e4aa:~$ chmod 664
kihei/i-061e6f1896de4e4aa 06:20
by SadServersroot 570 0.1 6.0 107132 28456 ? Ss 20:44 0:00 /usr/bin/pyth.py root 574 0.0 0.9 220796 4352 ? Ssl 20:44 0:00 /usr/sbin/rsyroot 579 0.0 1.4 13500 6772 ? Ss 20:44 0:00 /lib/systemd/root 582 0.0 0.3 2872 1676 tty1 Ss+ 20:44 0:00 /sbin/agetty 1 linux root 583 0.0 0.4 4396 2104 ttyS0 Ss+ 20:44 0:00 /sbin/agetty 15200,57600,38400,9600 ttyS0 vt220 root 584 0.0 1.5 13352 7184 ? Ss 20:44 0:00 sshd: /usr/sbf 10-100 startups _chrony 586 0.0 0.7 10852 3700 ? S 20:44 0:00 /usr/sbin/chr_chrony 588 0.0 0.1 10724 552 ? S 20:44 0:00 \_ /usr/sbinroot 589 0.0 3.6 26612 17248 ? Ss 20:44 0:00 /usr/bin/pyth-upgrades/unattended-upgrade-shutdown --wait-for-signal admin@i-07f79c3179505d899:~$
paris/i-07f79c3179505d899 03:35
by SadServersdrwxr-xr-x 7 admin admin 4096 Mar 4 20:45 . drwxr-xr-x 3 root root 4096 Sep 17 16:44 .. drwx------ 3 admin admin 4096 Sep 20 15:52 .ansible -rw------- 1 admin admin 576 Mar 4 20:45 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 15:56 .config drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py drwsr-sr-x 2 admin admin 4096 Mar 4 20:45 yolo admin@i-0914c01abdff80d82:~$ rmdir yolo admin@i-0914c01abdff80d82:~$ mkdir yolo admin@i-0914c01abdff80d82:~$ chmod +t yolo admin@i-0914c01abdff80d82:~$ mv