command-line-murders/i-0b7ad2d5fe2765454
by SadServersMore by SadServers
linux-gnu/libpthread-2.31.so lsof 769 admin mem REG 259,1 1868linux-gnu/libdl-2.31.so lsof 769 admin mem REG 259,1 61712linux-gnu/libpcre2-8.so.0.10.1 lsof 769 admin mem REG 259,1 190153linux-gnu/libc-2.31.so lsof 769 admin mem REG 259,1 16612linux-gnu/libselinux.so.1 lsof 769 admin mem REG 259,1 17792linux-gnu/ld-2.31.so lsof 769 admin 4r FIFO 0,11 0tlsof 769 admin 7w FIFO 0,11 0tadmin@i-059fb7e158508f014:~$ lsof |grep webserver admin@i-059fb7e158508f014:~$ lsof |grep .pyu
paris/i-059fb7e158508f014 01:33
by SadServersOct 2 02:20:33 i-0be6959616eac2ed0 gotty[566]: 2023/10/02 02:20:33 172.31.16.10.ico Oct 2 02:20:33 i-0be6959616eac2ed0 gotty[566]: 2023/10/02 02:20:33 172.31.16.102.png Oct 2 02:20:33 i-0be6959616eac2ed0 gotty[566]: 2023/10/02 02:20:33 New client c54532, connections: 1/5 Oct 2 02:20:40 i-0be6959616eac2ed0 dhclient[471]: XMT: Solicit on ens5, intervaOct 2 02:20:57 i-0be6959616eac2ed0 systemd[1]: Starting Online ext4 Metadata Ch.. Oct 2 02:20:57 i-0be6959616eac2ed0 systemd[1]: e2scrub_all.service: Succeeded. Oct 2 02:20:57 i-0be6959616eac2ed0 systemd[1]: Finished Online ext4 Metadata ChOct 2 02:21:04 i-0be6959616eac2ed0 systemd[1]: Started Hammer Time. Oct 2 02:21:05 i-0be6959616eac2ed0 systemd[1]: mc.service: Succeeded. Oct 2 02:21:10 i-0be6959616eac2ed0 dhclient[471]: XMT: Solicit on ens5, intervaadmin@i-0be6959616eac2ed0:/var/log$ cat syslog
kihei/i-0be6959616eac2ed0 01:36
by SadServersdrwxr-xr-x 3 root root 16384 Jan 1 1970 data -rw-r--r-- 1 root root 5368709120 Sep 17 17:28 datafile -rwxr-xr-x 1 admin root 2207109 Sep 17 17:28 kihei admin@i-0e45767b31594566c:~$ chmod 777 data chmod: changing permissions of 'data': Operation not permitted admin@i-0e45767b31594566c:~$ sudo chmod 777 data admin@i-0e45767b31594566c:~$ ./kihei -v Deleting file /home/admin/data/newdatafile... panic: remove /home/admin/data/newdatafile: permission denied goroutine 1 [running]: main.main() ./main.go:50 +0x48d admin@i-0e45767b31594566c:~$ rm /home/admin/data/newdatafile rm: remove write-protected regular empty file '/home/admin/data/newdatafile'? n
kihei/i-0e45767b31594566c 09:15
by SadServersagent webserver.py admin@i-0c9542c7c8a29de76:~$ ls -la total 44 drwxr-xr-x 6 admin admin 4096 Sep 24 23:20 . drwxr-xr-x 3 root root 4096 Sep 17 16:44 .. drwx------ 3 admin admin 4096 Sep 20 15:52 .ansible -rw------- 1 admin admin 718 Nov 27 03:46 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 4 admin admin 4096 Nov 27 03:44 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-0c9542c7c8a29de76:~$