command-line-murders/i-0d44986a869a81961
by SadServersMore by SadServers
Memory: 21.9M CPU: 345ms CGroup: /system.slice/flaskapp.service └─582 /usr/bin/python3 /home/admin/webserver.py Dec 17 20:47:26 i-0d7d6ed418963724f systemd[1]: Started Flask Application. Dec 17 20:47:27 i-0d7d6ed418963724f python3[582]: * Serving Flask app 'webserveDec 17 20:47:27 i-0d7d6ed418963724f python3[582]: * Debug mode: off Dec 17 20:47:27 i-0d7d6ed418963724f python3[582]: WARNING: This is a developmentDec 17 20:47:27 i-0d7d6ed418963724f python3[582]: * Running on http://127.0.0.1Dec 17 20:47:27 i-0d7d6ed418963724f python3[582]: Press CTRL+C to quit Dec 17 20:48:01 i-0d7d6ed418963724f python3[582]: 127.0.0.1 - - [17/Dec/2023 20:Dec 17 20:48:40 i-0d7d6ed418963724f python3[582]: 127.0.0.1 - - [17/Dec/2023 20:Dec 17 20:51:59 i-0d7d6ed418963724f python3[582]: 127.0.0.1 - - [17/Dec/2023 20:(reverse-i-search)`curl': curl localhost:5000
paris/i-0d7d6ed418963724f 04:32
by SadServersadmin@i-0f7e099fcadc77c31:~$ cat /proc/568/environ LANG=C.UTF-8PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/binHOMAM=8:11432SUPERSECRETPASSWORD=bdFBkE4suaCyadmin@i-0f7e099fcadc77c31:~$ cat /procLANG=C.UTF-8 PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin HOME=/home/admin LOGNAME=admin USER=admin SHELL=/bin/bash INVOCATION_ID=c958d25f18954f39ab0e46766a35d29f JOURNAL_STREAM=8:11432 SUPERSECRETPASSWORD=bdFBkE4suaCy admin@i-0f7e099fcadc77c31:~$ cat /proc/568/environ | tr '\0' '\n' | grep SUPER SUPERSECRETPASSWORD=bdFBkE4suaCy admin@i-0f7e099fcadc77c31:~$ cat /proc/568/environ | tr '\0' '\n' | grep SUPER
monaco/i-0f7e099fcadc77c31 03:43
by SadServersnt-Type: application/x-www-form-urlencoded' --data-urlencode 'password=" or 1=1'Access denied!admin@i-09f0e7c74e34fbdd9:~$ curl --location --request POST 'localnt-Type: application/x-www-form-urlencoded' --data-urlencode 'password=" or "1"=Access denied!admin@i-09f0e7c74e34fbdd9:~$ curl --location --request POST 'localnt-Type: application/x-www-form-urlencoded' --data-urlencode 'password=^Cor "1"=admin@i-09f0e7c74e34fbdd9:~$ curl --location --request POST 'localhost:5000' \ --header 'Content-Type: application/x-www-form-urlencoded' \ --data-urlencode 'password='\'' or '\''1'\''='\''1' admin@i-09f0e7c74e34fbdd9:~$ curl --location --request POST 'localhost:5000' \al--header 'Content-Type: application/x-www-form-urlencoded' \ --data-urlencode 'password=' admin@i-09f0e7c74e34fbdd9:~$ curl --location --request POST 'localhost:5000' \al--form 'password="admin"' Access denied!admin@i-09f0e7c74e34fbdd9:~$ curl --location --request POST 'locald="admin"'