command-line-murders/i-07d27b83c65a56e8b
by SadServersMore by SadServers
Oct 2 02:20:33 i-0be6959616eac2ed0 gotty[566]: 2023/10/02 02:20:33 172.31.16.10.ico Oct 2 02:20:33 i-0be6959616eac2ed0 gotty[566]: 2023/10/02 02:20:33 172.31.16.102.png Oct 2 02:20:33 i-0be6959616eac2ed0 gotty[566]: 2023/10/02 02:20:33 New client c54532, connections: 1/5 Oct 2 02:20:40 i-0be6959616eac2ed0 dhclient[471]: XMT: Solicit on ens5, intervaOct 2 02:20:57 i-0be6959616eac2ed0 systemd[1]: Starting Online ext4 Metadata Ch.. Oct 2 02:20:57 i-0be6959616eac2ed0 systemd[1]: e2scrub_all.service: Succeeded. Oct 2 02:20:57 i-0be6959616eac2ed0 systemd[1]: Finished Online ext4 Metadata ChOct 2 02:21:04 i-0be6959616eac2ed0 systemd[1]: Started Hammer Time. Oct 2 02:21:05 i-0be6959616eac2ed0 systemd[1]: mc.service: Succeeded. Oct 2 02:21:10 i-0be6959616eac2ed0 dhclient[471]: XMT: Solicit on ens5, intervaadmin@i-0be6959616eac2ed0:/var/log$ cat syslog
kihei/i-0be6959616eac2ed0 01:36
by SadServersinary_Operatorunicode.IDS_Trinary_Operatorunicode.Ideographicunicode.Join_Controcunicode.Other_Default_Ignorable_Code_Pointunicode.Other_Grapheme_Extendunicode.e.Other_Uppercaseunicode.Pattern_Syntaxunicode.Pattern_White_Spaceunicode.Prepennicode.Sentence_Terminalunicode.Soft_Dottedunicode.Terminal_Punctuationunicode.U.FoldCategoryunicode.foldLunicode.foldLlunicode.foldLtunicode.foldLuunicode.foldtedinternal/cpu.DebugOptionsinternal/cpu.CacheLineSizeinternal/cpu.X86internal/co.itab.*flag.boolValue,flag.Valuego.itab.*os.File,io.Writergo.itab.*strconv.NumEitab.*flag.float64Value,flag.Valuego.itab.*flag.intValue,flag.Valuego.itab.*flag.Valuego.itab.*flag.uint64Value,flag.Valuego.itab.*strings.Builder,io.Writergo.itab.*os.File,io.Readergo.itab.syscall.Signal,os.Signalgo.itab.*io/fs.PathError,eWritergo.itab.*os.fileStat,io/fs.FileInfogo.itab.*io.LimitedReader,io.Readergo.itab.*bufio.Reader,io.Readergo.itab.os/user.UnknownUserIdError,errorgo.itab.*inteb.*internal/fmtsort.SortedMap,sort.Interfacego.itab.runtime.errorString,error_cgo_munmap_cgo_sigactionruntime.mainPCgo.itab.*internal/poll.DeadlineExceededErrorersion.strruntime.modinfo.strtype.*runtime.textsectionmapadmin@i-08c990dcb570e62
i-08c990dcb570e6294 00:10
by SadServersDec 16 19:58:09 i-087a04010afc840a2 sudo[686]: pam_unix(sudo:session): session o) by (uid=1000) root@i-087a04010afc840a2:/home/admin# ^C root@i-087a04010afc840a2:/home/admin# tail -f /etc/systemd/system/gotty.service [Service] User=admin Group=admin ExecStart=/usr/local/gotty --permit-write --reconnect --max-connection 5 bash -lWorkingDirectory=/home/admin Restart=on-failure Nice=-20 [Install] WantedBy=multi-user.target
kihei/i-087a04010afc840a2 00:58
by SadServersdrwxr-xr-x 6 admin admin 4096 Nov 4 03:11 . drwxr-xr-x 3 root root 4096 Sep 17 2023 .. drwx------ 3 admin admin 4096 Sep 20 2023 .ansible -rw------- 1 admin admin 448 Nov 4 03:13 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 2023 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 2023 .ssh -rw------- 1 admin admin 1232 Nov 4 03:11 .viminfo drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-0ae37c2b2950f7142:~$ visudo visudo: /etc/sudoers: Permission denied admin@i-0ae37c2b2950f7142:~$