command-line-murders/i-0e1d39a1e66993ba4
by SadServersMore by SadServers
root 587 0.0 0.4 4396 2156 ttyS0 Ss+ 11:42 0:00 /sbin/agetty 15200,57600,38400,9600 ttyS0 vt220 _chrony 589 0.0 0.7 10852 3696 ? S 11:42 0:00 /usr/sbin/chr_chrony 590 0.0 0.1 10724 548 ? S 11:42 0:00 /usr/sbin/chrroot 601 0.0 3.7 26612 17380 ? Ss 11:42 0:00 /usr/bin/pyth-upgrades/unattended-upgrade-shutdown --wait-for-sign admin 708 0.0 0.9 6740 4428 pts/0 S<s+ 11:43 0:00 bash -l admin 712 0.1 4.1 98188 19252 pts/0 D<l+ 11:43 0:00 /usr/bin/pythc -t paris/i-0295f93e991e74c58 -q -i 2 /var/log/cast/ admin 715 0.0 3.0 24456 14392 pts/0 R<+ 11:43 0:00 /usr/bin/pythc -t paris/i-0295f93e991e74c58 -q -i 2 /var/log/cast/ admin 716 0.0 0.1 2480 512 pts/1 S<s 11:43 0:00 sh -c /bin/baadmin 717 0.0 1.0 6952 4844 pts/1 S< 11:43 0:00 /bin/bash admin 814 0.0 0.7 8648 3316 pts/1 R<+ 11:46 0:00 ps aux admin@i-0295f93e991e74c58:~$ pgrep -lfa
paris/i-0295f93e991e74c58 03:57
by SadServers8c146fbbcadb haproxy:1.7 "docker-entrypoint.s…" 19 minutes ago rabbitmq-cluster-docker-master-haproxy-1 7a58702c1c56 rabbitmq:3-management "/usr/local/bin/clus…" 19 minutes ago rabbitmq-cluster-docker-master-rabbitmq2-1 74b97f9f59e1 rabbitmq:3-management "/usr/local/bin/clus…" 19 minutes ago rabbitmq-cluster-docker-master-rabbitmq3-1 2c14cac232f9 rabbitmq:3-management "/usr/local/bin/clus…" 19 minutes ago rabbitmq-cluster-docker-master-rabbitmq1-1 admin@i-0afad6e3069679be1:~/rabbitmq-cluster-docker-master$ docker rm rabbitmq-crabbitmq-cluster-docker-master-haproxy-1 rabbitmq-cluster-docker-master-rabbier-master-rabbitmq2-1 rabbitmq-cluster-docker-master-rabbitmq3-1 admin@i-0afad6e3069679be1:~/rabbitmq-cluster-docker-master$ docker rm rabbitmq-crabbitmq-cluster-docker-master-haproxy-1 rabbitmq-cluster-docker-master-rabbier-master-rabbitmq2-1 rabbitmq-cluster-docker-master-rabbitmq3-1 admin@i-0afad6e3069679be1:~/rabbitmq-cluster-docker-master$ docker rm rabbitmq-c
chennai/i-0afad6e3069679be1 11:02
by SadServersdrwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-010d84eaab4d0fc03:~$ cp /home/admin/webserver.py /tmp/ cp: cannot open '/home/admin/webserver.py' for reading: Permission denied admin@i-010d84eaab4d0fc03:~$ admin@i-010d84eaab4d0fc03:~$ ls -la /home/admin/agent/ total 11144 drwxr-xr-x 2 admin root 4096 Sep 24 2023 . drwxr-xr-x 6 admin admin 4096 Sep 24 2023 .. -rwxr-xr-x 1 admin admin 230 Sep 24 2023 check.sh -rwxr-xr-x 1 admin root 11397096 Sep 20 2023 sadagent -rw-r--r-- 1 admin admin 0 Sep 20 2023 sadagent.txt admin@i-010d84eaab4d0fc03:~$ ls -la /home/admin/agent/sadagent -rwxr-xr-x 1 admin root 11397096 Sep 20 2023 /home/admin/agent/sadagent admin@i-010d84eaab4d0fc03:~$
paris/i-010d84eaab4d0fc03 02:29
by SadServerswrite(2, " +", 2 +) = 2 write(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-0d8dc547f45c534d8:~$ lsblk -l NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT nvme1n1 259:0 0 1G 0 disk nvme0n1 259:1 0 8G 0 disk nvme0n1p1 259:2 0 7.9G 0 part / nvme0n1p14 259:3 0 3M 0 part nvme0n1p15 259:4 0 124M 0 part /boot/efi nvme2n1 259:5 0 1G 0 disk admin@i-0d8dc547f45c534d8:~$