command-line-murders/i-07ab54530b3e98bee
by SadServersMore by SadServers
find: ‘./var/cache/ldconfig’: Permission denied find: ‘./var/cache/apt/archives/partial’: Permission denied find: ‘./var/cache/apparmor/c08a2770.0’: Permission denied find: ‘./var/spool/rsyslog’: Permission denied find: ‘./var/spool/cron/crontabs’: Permission denied find: ‘./var/tmp/systemd-private-b754c07b3fa742cb9df32f2da130ce62-systemd-logindfind: ‘./var/tmp/systemd-private-b754c07b3fa742cb9df32f2da130ce62-chrony.servicefind: ‘./var/log/private’: Permission denied find: ‘./var/log/chrony’: Permission denied find: ‘./var/lib/private’: Permission denied find: ‘./var/lib/apt/lists/partial’: Permission denied find: ‘./var/lib/chrony’: Permission denied admin@i-0840e6f1dc550a03a:/$ tree bash: tree: command not found admin@i-0840e6f1dc550a03a:/$ find . -iname pass
paris/i-0840e6f1dc550a03a 03:20
by SadServersroot 588 0.1 0.3 2872 1652 tty1 Ss+ 15:43 0:00 /sbin/agetty -o -p -- \u --noclear tty1 linux root 590 0.0 0.4 4396 2140 ttyS0 Ss+ 15:43 0:00 /sbin/agetty -o -p -- \u --keep-baud 115200,57600,38400,9600 ttyS0 vt220 root 591 0.0 1.5 13352 7188 ? Ss 15:43 0:00 sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 startups _chrony 593 0.0 0.7 10852 3596 ? S 15:43 0:00 /usr/sbin/chronyd -F 1 _chrony 604 0.0 0.1 10724 552 ? S 15:43 0:00 \_ /usr/sbin/chronyd -F 1 root 603 0.0 3.7 26612 17364 ? Ss 15:43 0:00 /usr/bin/python3 /usr/share/unattended-upgrades/unattended-upgrade-shutdown --wait-for-signaladmin@i-001eabc18e1752db3:~$ cat ~/webserver.py cat: /home/admin/webserver.py: Permission denied admin@i-001eabc18e1752db3:~$
paris/i-001eabc18e1752db3 03:40
by SadServersadmin@i-0e3126c91f22b8e7e:~$ cd /home/admin/ admin@i-0e3126c91f22b8e7e:~$ ls agent data datafile kihei admin@i-0e3126c91f22b8e7e:~$ ps aux | grep kihei admin 733 0.4 4.1 98188 19420 pts/0 S<l+ 21:13 0:00 /usr/bin/pyth-t kihei/i-0e3126c91f22b8e7e -q -i 2 /var/log/cast/i-0e3126c91f22b8e7e admin 736 0.0 3.0 24456 14364 pts/0 S<+ 21:13 0:00 /usr/bin/pyth-t kihei/i-0e3126c91f22b8e7e -q -i 2 /var/log/cast/i-0e3126c91f22b8e7e admin 747 0.0 0.1 5264 696 pts/1 S<+ 21:14 0:00 grep kihei admin@i-0e3126c91f22b8e7e:~$ chmod -R a-w /var/log/cast/ admin@i-0e3126c91f22b8e7e:~$