command-line-murders/i-0b45a7e517afa8a37
by SadServersMore by SadServers
total 5.1G -rw-r--r-- 1 root root 5.0G Sep 17 2023 datafile drwxr-xr-x 2 admin root 4.0K Sep 17 2023 data drwxr-xr-x 2 admin root 4.0K Sep 17 2023 agent -rwxr-xr-x 1 admin root 2.2M Dec 3 14:28 kihei admin@i-028aa18574b00296c:~$ su -sh * su: user agent does not exist or the user entry does not contain all the requireadmin@i-028aa18574b00296c:~$ s\du -sh * bash: sdu: command not found admin@i-028aa18574b00296c:~$ du -sh * 11M agent 4.0K data 5.1G datafile 2.2M kihei admin@i-028aa18574b00296c:~$
kihei/i-028aa18574b00296c 01:56
by SadServerstotal 8 drwxr-xr-x 2 root root 4096 Sep 28 2021 . drwxr-xr-x 18 root root 4096 Mar 3 20:06 .. root@i-0bd285e932f3bd091:/home/admin# lsblk NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT nvme1n1 259:0 0 1G 0 disk nvme0n1 259:1 0 8G 0 disk ├─nvme0n1p1 259:3 0 7.9G 0 part / ├─nvme0n1p14 259:4 0 3M 0 part └─nvme0n1p15 259:5 0 124M 0 part /boot/efi nvme2n1 259:2 0 1G 0 disk root@i-0bd285e932f3bd091:/home/admin# fdisk /dev/^C root@i-0bd285e932f3bd091:/home/admin# ls /dev/sd* /dev/sdb /dev/sdc root@i-0bd285e932f3bd091:/home/admin# fdisk /dev/sd
kihei/i-0bd285e932f3bd091 01:57
by SadServersadmin@i-01938499a23dd6d8b:~$ curl http://localhost:5000 Unauthorizedadmin@i-01938499a23dd6d8b:~$ curl https://localhost:5000 curl: (35) error:1408F10B:SSL routines:ssl3_get_record:wrong version number admin@i-01938499a23dd6d8b:~$ strace -p 573 strace: attach: ptrace(PTRACE_SEIZE, 573): Operation not permitted admin@i-01938499a23dd6d8b:~$ sudo strace -p 573 We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin:
paris/i-01938499a23dd6d8b 05:03
by SadServersdrwxr-xr-x 7 admin admin 4096 Mar 4 20:45 . drwxr-xr-x 3 root root 4096 Sep 17 16:44 .. drwx------ 3 admin admin 4096 Sep 20 15:52 .ansible -rw------- 1 admin admin 576 Mar 4 20:45 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 15:56 .config drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py drwsr-sr-x 2 admin admin 4096 Mar 4 20:45 yolo admin@i-0914c01abdff80d82:~$ rmdir yolo admin@i-0914c01abdff80d82:~$ mkdir yolo admin@i-0914c01abdff80d82:~$ chmod +t yolo admin@i-0914c01abdff80d82:~$ mv