command-line-murders/i-071c8194e55528ee9
by SadServersMore by SadServers
admin@i-006f0e9a73bb6b96a:~/.ansible$ cd tmp/ admin@i-006f0e9a73bb6b96a:~/.ansible/tmp$ ls admin@i-006f0e9a73bb6b96a:~/.ansible/tmp$ ls -lah total 8.0K drwx------ 2 admin admin 4.0K Sep 24 2023 . drwx------ 3 admin admin 4.0K Sep 20 2023 .. admin@i-006f0e9a73bb6b96a:~/.ansible/tmp$ chage -l admin Last password change : Sep 17, 2023 Password expires : never Password inactive : never Account expires : never Minimum number of days between password change : 0 Maximum number of days between password change : 99999 Number of days of warning before password expires : 7 admin@i-006f0e9a73bb6b96a:~/.ansible/tmp$ cd /etc
paris/i-006f0e9a73bb6b96a 03:24
by SadServers24 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 netns 25 root 20 0 0 0 0 S 0.0 0.0 0:00.12 kauditd 26 root 20 0 0 0 0 S 0.0 0.0 0:00.00 khungtask 27 root 20 0 0 0 0 S 0.0 0.0 0:00.00 oom_reape 28 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 writeback 29 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kcompactd 30 root 25 5 0 0 0 S 0.0 0.0 0:00.00 ksmd 49 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kintegrit 50 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kblockd 51 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 blkcg_pun 52 root 20 0 0 0 0 I 0.0 0.0 0:00.03 kworker/1 53 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kworker/0 54 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kswapd0 55 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kthrotld admin@i-0bc8be230e1a6d230:~$ lso
paris/i-0bc8be230e1a6d230 01:07
by SadServersroot 587 0.0 1.4 13352 6828 ? Ss 21:55 0:00 sshd: /usr/sbroot 588 0.0 0.3 2872 1664 tty1 Ss+ 21:55 0:00 /sbin/agetty root 589 0.0 0.4 4396 2144 ttyS0 Ss+ 21:55 0:00 /sbin/agetty _chrony 591 0.0 0.7 10852 3664 ? S 21:55 0:00 /usr/sbin/chr_chrony 592 0.0 0.1 10724 548 ? S 21:55 0:00 /usr/sbin/chrroot 610 0.0 3.7 26612 17404 ? Ss 21:55 0:00 /usr/bin/pythroot 683 0.0 0.0 0 0 ? I 21:55 0:00 [kworker/1:3-admin 714 0.0 0.9 6740 4368 pts/0 S<s+ 21:56 0:00 bash -l admin 718 0.2 4.1 98320 19392 pts/0 R<l+ 21:56 0:00 /usr/bin/pythadmin 721 0.0 3.1 24456 14836 pts/0 R<+ 21:56 0:00 /usr/bin/pythadmin 722 0.0 0.1 2480 508 pts/1 S<s 21:56 0:00 sh -c /bin/baadmin 723 0.0 0.9 6820 4500 pts/1 S< 21:56 0:00 /bin/bash admin 819 0.0 0.6 8648 3260 pts/1 R<+ 21:59 0:00 ps aux admin@i-0cdefb94500ecc5ae:~$ vim log admin@i-0cdefb94500ecc5ae:~$ netsstat
paris/i-0cdefb94500ecc5ae 05:03
by SadServers_apt:x:100:65534::/nonexistent:/usr/sbin/nologin messagebus:x:101:101::/nonexistent:/usr/sbin/nologin uuidd:x:102:102::/run/uuidd:/usr/sbin/nologin tcpdump:x:103:103::/nonexistent:/usr/sbin/nologin _chrony:x:104:104:Chrony daemon,,,:/var/lib/chrony:/usr/sbin/nologin systemd-network:x:105:106:systemd Network Management,,,:/run/systemd:/usr/sbin/nsystemd-resolve:x:106:107:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin sshd:x:107:65534::/run/sshd:/usr/sbin/nologin systemd-timesync:x:999:999:systemd Time Synchronization:/:/usr/sbin/nologin systemd-coredump:x:998:998:systemd Core Dumper:/:/usr/sbin/nologin admin:x:1000:1000:Debian:/home/admin:/bin/bash admin@i-02f008a4ef093b898:~$ su - www-data bash Password: ^C admin@i-02f008a4ef093b898:~$ curl -A