command-line-murders/i-0899a99e40cd556ae
by SadServersMore by SadServers
-rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout drwxr-xr-x 3 root root 4096 Sep 17 2023 .. drwx------ 2 admin admin 4096 Sep 17 2023 .ssh drwx------ 3 admin admin 4096 Sep 20 2023 .ansible drwxr-xr-x 3 admin admin 4096 Sep 20 2023 .config -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py drwxr-xr-x 6 admin admin 4096 Sep 24 2023 . drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rw------- 1 admin admin 359 Feb 4 03:35 .bash_history admin@i-0f4b72b9b2118ab71:~$ whoami admin admin@i-0f4b72b9b2118ab71:~$ chown admin webserver.py chown: changing ownership of 'webserver.py': Operation not permitted admin@i-0f4b72b9b2118ab71:~$ less .bash_history admin@i-0f4b72b9b2118ab71:~$ cd
paris/i-0f4b72b9b2118ab71 02:29
by SadServersmain.main() ./main.go:64 +0x47d admin@i-0d4b0d36217ba962c:~$ mv datafile.tmp ../ mv: cannot move 'datafile.tmp' to '../datafile.tmp': Permission denied admin@i-0d4b0d36217ba962c:~$ cd .. admin@i-0d4b0d36217ba962c:/home$ ll bash: ll: command not found admin@i-0d4b0d36217ba962c:/home$ ls admin admin@i-0d4b0d36217ba962c:/home$ ls -lah total 12K drwxr-xr-x 3 root root 4.0K Sep 17 16:44 . drwxr-xr-x 18 root root 4.0K Nov 12 17:47 .. drwxr-xr-x 7 admin admin 4.0K Nov 12 17:49 admin admin@i-0d4b0d36217ba962c:/home$
kihei/i-0d4b0d36217ba962c 02:08
by SadServersunix 3 [ ] STREAM CONNECTED 11297 - unix 3 [ ] SEQPACKET CONNECTED 11367 - unix 3 [ ] STREAM CONNECTED 11437 - et unix 3 [ ] STREAM CONNECTED 10838 - unix 3 [ ] STREAM CONNECTED 10827 - unix 3 [ ] STREAM CONNECTED 10839 - et unix 3 [ ] STREAM CONNECTED 11473 - ut admin@i-01253b0100cbaa15e:~$ netstat -anp | grep 5000 (Not all processes could be identified, non-owned process info will not be shown, you would have to be root to see it all.) tcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN admin@i-01253b0100cbaa15e:~$ ps -ef | G