command-line-murders/i-0ac17eb8abf847c1f
by SadServersMore by SadServers
_chrony 590 0.0 0.1 10724 556 ? S 09:28 0:00 /usr/sbin/chrroot 599 0.0 3.7 26612 17340 ? Ss 09:28 0:00 /usr/bin/pythroot 678 0.0 0.0 0 0 ? I 09:28 0:00 [kworker/1:4-admin 682 0.0 0.9 6704 4572 pts/0 S<s+ 09:28 0:00 bash -l admin 686 0.0 4.1 98188 19244 pts/0 R<l+ 09:28 0:00 /usr/bin/pythadmin 689 0.0 3.1 24456 14512 pts/0 S<+ 09:28 0:00 /usr/bin/pythadmin 690 0.0 0.1 2480 572 pts/1 S<s 09:28 0:00 sh -c /bin/baadmin 691 0.0 0.9 6820 4560 pts/1 S< 09:28 0:00 /bin/bash root 872 0.0 0.0 0 0 ? I 09:34 0:00 [kworker/1:1]admin 873 0.0 0.6 8648 3152 pts/1 R<+ 09:34 0:00 ps aux admin@i-041d7351af3904de5:~$ ps aux | grep 5000 admin 906 0.0 0.1 5264 636 pts/1 S<+ 09:35 0:00 grep 5000 admin@i-041d7351af3904de5:~$ ls -i :5000 ls: cannot access ':5000': No such file or directory admin@i-041d7351af3904de5:~$
paris/i-041d7351af3904de5 02:49
by SadServerstotal 8 drwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-06bbe1bb9a1bed390:~$ sudo wc -l webserver.py We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: sudo: a password is required admin@i-06bbe1bb9a1bed390:~$ grep password
paris/i-06bbe1bb9a1bed390 00:47
by SadServersirc:x:39:39:ircd:/run/ircd:/usr/sbin/nologin gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologinobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin _apt:x:100:65534::/nonexistent:/usr/sbin/nologin messagebus:x:101:101::/nonexistent:/usr/sbin/nologin uuidd:x:102:102::/run/uuidd:/usr/sbin/nologin tcpdump:x:103:103::/nonexistent:/usr/sbin/nologin _chrony:x:104:104:Chrony daemon,,,:/var/lib/chrony:/usr/sbin/nologin systemd-network:x:105:106:systemd Network Management,,,:/run/systemd:/usr/sbin/nsystemd-resolve:x:106:107:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin sshd:x:107:65534::/run/sshd:/usr/sbin/nologin systemd-timesync:x:999:999:systemd Time Synchronization:/:/usr/sbin/nologin systemd-coredump:x:998:998:systemd Core Dumper:/:/usr/sbin/nologin admin:x:1000:1000:Debian:/home/admin:/bin/bash admin@i-09dd7a16c1516f9c8:~$ sudo cat /etc/passwd\
kihei/i-09dd7a16c1516f9c8 05:30
by SadServers} } } }, { "manager": "kube-controller-manager", "operation": "Update", "apiVersion": "apps/v1", "time": "2025-03-05T11:00:44Z", "fieldsType": "FieldsV1" }^C } admin@i-0a3506b35004c40b1:~$ admin@i-0a3506b35004c40b1:~$ admin@i-0a3506b35004c40b1:~$ admin@i-0a3506b35004c40b1:~$ sudo pvcre