command-line-murders/i-097e06017eae9dfe7
by SadServersMore by SadServers
-rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 2023 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 2023 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-0c7688c6e49a68923:~$ cd /var/log admin@i-0c7688c6e49a68923:/var/log$ ls alternatives.log auth.log btmp chrony daemon.log journal kern.log.2.gz messages.1 private syslog.1 user.lalternatives.log.1 auth.log.1 btmp.1 cloud-init-output.log daemon.log.1 kern.log lastlog messages.2.gz runit syslog.2.gz user.lapt auth.log.2.gz cast cloud-init.log daemon.log.2.g kern.log.1 messages minio.log syslog unattended-upgrades user.ladmin@i-0c7688c6e49a68923:/var/log$ less
paris/i-0c7688c6e49a68923 04:44
by SadServerssudo: a password is required admin@i-02a189271ae7f8c79:~$ ls -lah total 44K drwxr-xr-x 6 admin admin 4.0K Sep 24 23:20 . drwxr-xr-x 3 root root 4.0K Sep 17 16:44 .. drwx------ 3 admin admin 4.0K Sep 20 15:52 .ansible -rw------- 1 admin admin 268 Jan 7 12:26 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3.5K Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4.0K Sep 20 15:56 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4.0K Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4.0K Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-02a189271ae7f8c79:~$
paris/i-02a189271ae7f8c79 01:32
by SadServerslsof 835 admin mem REG 259,1 61712-linux-gnu/libpcre2-8.so.0.10.1 lsof 835 admin mem REG 259,1 190153-linux-gnu/libc-2.31.so lsof 835 admin mem REG 259,1 16612-linux-gnu/libselinux.so.1 lsof 835 admin mem REG 259,1 17792-linux-gnu/ld-2.31.so lsof 835 admin 4r FIFO 0,11 0tlsof 835 admin 7w FIFO 0,11 0tadmin@i-00d15eebefe1eaf63:~$ lsof -nP -iTCP -sTCP:LISTEN COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME gotty 563 admin 6u IPv6 1900 0t0 TCP *:8080 (LISTEN) sadagent 564 admin 7u IPv6 1875 0t0 TCP *:6767 (LISTEN) admin@i-00d15eebefe1eaf63:~$ lsof -nP -i
paris/i-00d15eebefe1eaf63 01:35
by SadServers<head> <meta http-equiv="Content-Type" content="text/html;charset=utf-8"> <title>Error response</title> </head> <body> <h1>Error response</h1> <p>Error code: 400</p> <p>Message: Bad request syntax ('/GET').</p> <p>Error code explanation: HTTPStatus.BAD_REQUEST - Bad request syntax o </body> </html> GET / admin@i-05c58840f2cef0922:~$ nc localhost 5000 GET /