kihei/i-067c3d70a29d1f4c2
by SadServersMore by SadServers
example: knock myserver.example.com 123:tcp 456:udp 789:tcp admin@i-080ac908debd2d3d7:~$ knock -v 127.0.0.1 80:tcp 1 hitting tcp 127.0.0.1:80 hitting tcp 127.0.0.1:1 admin@i-080ac908debd2d3d7:~$ knock -v 127.0.0.1 80:tcp hitting tcp 127.0.0.1:80 admin@i-080ac908debd2d3d7:~$ curl -D - -v localhost * Trying 127.0.0.1:80... * connect to 127.0.0.1 port 80 failed: Connection refused * Failed to connect to localhost port 80: Connection refused * Closing connection 0 curl: (7) Failed to connect to localhost port 80: Connection refused admin@i-080ac908debd2d3d7:~$ nc -vv 12
taipei/i-080ac908debd2d3d7 08:29
by SadServers24 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 netns 25 root 20 0 0 0 0 S 0.0 0.0 0:00.12 kauditd 26 root 20 0 0 0 0 S 0.0 0.0 0:00.00 khungtask 27 root 20 0 0 0 0 S 0.0 0.0 0:00.00 oom_reape 28 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 writeback 29 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kcompactd 30 root 25 5 0 0 0 S 0.0 0.0 0:00.00 ksmd 49 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kintegrit 50 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kblockd 51 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 blkcg_pun 52 root 20 0 0 0 0 I 0.0 0.0 0:00.03 kworker/1 53 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kworker/0 54 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kswapd0 55 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kthrotld admin@i-0bc8be230e1a6d230:~$ lso
paris/i-0bc8be230e1a6d230 01:07
by SadServers114 23 52 593 710 dynamic_debug loadavg swaps 115 235 53 595 73 execdomains locks sys 12 24 54 596 78 fb meminfo sysrq-trigger 13 25 55 6 8 filesystems misc sysvipc 133 26 56 60 889 fs modules thread-self 134 27 565 61 9 interrupts mounts timer_list 14 28 566 614 acpi iomem mtrr tty 15 29 57 62 buddyinfo ioports net uptime 16 3 572 63 bus irq pagetypeinfo version 17 30 575 682 cgroups kallsyms partitions vmallocinfo 18 31 58 685 cmdline kcore pressure vmstat 19 311 582 690 consoles key-users sched_debug zoneinfo 195 395 583 693 cpuinfo keys schedstat 2 4 586 694 crypto kmsg self admin@i-09f337b8d012c50bc:~$ ls /proc/
paris/i-09f337b8d012c50bc 04:02
by SadServersadmin@i-0102423b4d32663a7:~$ curl 127.0.0.1:5000 Unauthorizedadmin@i-0102423b4d32663a7:~$ admin@i-0102423b4d32663a7:~$ admin@i-0102423b4d32663a7:~$ ls agent webserver.py admin@i-0102423b4d32663a7:~$ less webserver.py webserver.py: Permission denied admin@i-0102423b4d32663a7:~$ ll bash: ll: command not found admin@i-0102423b4d32663a7:~$ cat webserver.py cat: webserver.py: Permission denied admin@i-0102423b4d32663a7:~$ cd agent/ admin@i-0102423b4d32663a7:~/agent$ ls check.sh sadagent sadagent.txt admin@i-0102423b4d32663a7:~/agent$ ls