command-line-murders/i-0ac32ce9b99426cca
by SadServersMore by SadServers
We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: Sorry, try again. [sudo] password for admin: Sorry, try again. [sudo] password for admin: sudo: 3 incorrect password attempts admin@i-040ec55e8e002101c:~$ find / -name webserver
paris/i-040ec55e8e002101c 02:48
by SadServersadmin@i-0346e20b3ceb89391:~$ nmap -v -O localhost -P 5000 Warning: The -P option is deprecated. Please use -PE Warning: You are not root -- using TCP pingscan rather than ICMP TCP/IP fingerprinting (for OS scan) requires root privileges. QUITTING! admin@i-0346e20b3ceb89391:~$
paris/i-0346e20b3ceb89391 00:44
by SadServerswrite(2, ":", 1:) = 1 write(2, "64", 264) = 2 write(2, " +", 2 +) = 2 write(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-0383999b6e9ab8158:~$ ls agent data datafile kihei admin@i-0383999b6e9ab8158:~$ ls datafile datafile admin@i-0383999b6e9ab8158:~$ ls /usr/local/sbin/fallocate ls: cannot access '/usr/local/sbin/fallocate': No such file or directory admin@i-0383999b6e9ab8158:~$ whereis fallo
kihei/i-0383999b6e9ab8158 01:37
by SadServersdrwxr-xr-x 7 admin admin 4096 Dec 6 15:59 . drwxr-xr-x 3 root root 4096 Sep 17 16:44 .. drwx------ 3 admin admin 4096 Sep 17 17:15 .ansible -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Dec 6 15:59 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4096 Sep 17 17:28 agent drwxr-xr-x 2 admin root 4096 Sep 17 17:28 data -rw-r--r-- 1 root root 5368709120 Sep 17 17:28 datafile -rwxr-xr-x 1 admin root 2207109 Sep 17 17:28 kihei admin@i-06aaa324a79f9607e:~$ less kihei "kihei" may be a binary file. See it anyway? admin@i-06aaa324a79f9607e:~$