command-line-murders/i-0f54a327129bf2b6a
by SadServersMore by SadServers
admin@i-07ee6b558ede8f810:~$ file /home/admin/kihei /home/admin/kihei: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), staticalolUanvRPB7DWhc7e4I/nM83nW4qxDvf9asNaf7E/5u1Qa6jnFvq2KL4kV5G1/6IwNz7tVbey9uC58oKsadmin@i-07ee6b558ede8f810:~$ lsof /home/admin/kihei admin@i-07ee6b558ede8f810:~$ ls -l /home/admin/kihei -rwxr-xr-x 1 admin root 2207109 Sep 17 2023 /home/admin/kihei admin@i-07ee6b558ede8f810:~$ man strace
kihei/i-07ee6b558ede8f810 00:59
by SadServersdr-xr-xr-x 3 root root 0 Feb 6 06:31 task -rw-r--r-- 1 root root 0 Feb 6 06:31 timens_offsets -r--r--r-- 1 root root 0 Feb 6 06:31 timers -rw-rw-rw- 1 root root 0 Feb 6 06:31 timerslack_ns -rw-r--r-- 1 root root 0 Feb 6 06:31 uid_map -r--r--r-- 1 root root 0 Feb 6 06:31 wchan admin@i-0fb869488634369c7:/proc/575$ sudo usage: sudo -h | -K | -k | -V usage: sudo -v [-AknS] [-g group] [-h host] [-p prompt] [-u user] usage: sudo -l [-AknS] [-g group] [-h host] [-p prompt] [-U user] [-u user] [comusage: sudo [-AbEHknPS] [-r role] [-t type] [-C num] [-D directory] [-g group] [directory] [-T timeout] [-u user] [VAR=value] [-i|-s] [<command>] usage: sudo -e [-AknS] [-r role] [-t type] [-C num] [-D directory] [-g group] [-irectory] [-T timeout] [-u user] file ... admin@i-0fb869488634369c7:/proc/575$ sudo -
paris/i-0fb869488634369c7 02:09
by SadServersSaving to: ‘index.html’ index.html 100%[=====================================>] 12 2024-01-15 05:10:43 (1.55 MB/s) - ‘index.html’ saved [12/12] admin@i-0d60756cd4edc8643:~$ ls agent index.html webserver.py admin@i-0d60756cd4edc8643:~$ cat index.html Unauthorizedadmin@i-0d60756cd4edc8643:~$ telnet localhost 5000 Trying 127.0.0.1... Connected to localhost. Escape character is '^]'. GET /
paris/i-0d60756cd4edc8643 01:25
by SadServersadmin@i-0f543fbc21a7f9861:~$ ls -al total 5245080 drwxr-xr-x 7 admin admin 4096 Feb 7 22:52 . drwxr-xr-x 3 root root 4096 Sep 17 16:44 .. drwx------ 3 admin admin 4096 Sep 17 17:15 .ansible -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Feb 7 22:52 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4096 Sep 17 17:28 agent drwxr-xr-x 2 admin root 4096 Feb 7 22:53 data -rw-r--r-- 1 root root 5368709120 Sep 17 17:28 datafile -rwxr-xr-x 1 admin root 2207109 Sep 17 17:28 kihei admin@i-0f543fbc21a7f9861:~$