command-line-murders/i-0033e63d65834a13d
by SadServersMore by SadServers
drwxr-xr-x 7 admin admin 4096 Dec 28 20:34 . drwxr-xr-x 3 root root 4096 Sep 17 2023 .. drwx------ 3 admin admin 4096 Sep 17 2023 .ansible -rw------- 1 admin admin 75 Dec 28 20:34 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Dec 28 20:34 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 2023 .ssh -rw------- 1 admin admin 688 Dec 28 20:34 .viminfo drwxr-xr-x 2 admin root 4096 Sep 17 2023 agent drwxr-xr-x 2 admin root 4096 Dec 28 20:36 data -rw-r--r-- 1 root root 5368709120 Sep 17 2023 datafile -rwxr-xr-x 1 admin root 2207109 Sep 17 2023 kihei admin@i-018da4c7d7c33aafe:~$ vi
kihei/i-018da4c7d7c33aafe 05:03
by SadServersadmin@i-06a632625d40e1c3d:~$ lvdisplay WARNING: Running as a non-root user. Functionality may be unavailable. /run/lock/lvm/P_global:aux: open failed: Permission denied admin@i-06a632625d40e1c3d:~$ sudo lvdisplay admin@i-06a632625d40e1c3d:~$ umount data umount: /home/admin/data: must be superuser to unmount. admin@i-06a632625d40e1c3d:~$ sudo umount data admin@i-06a632625d40e1c3d:~$ shred -v^C admin@i-06a632625d40e1c3d:~$ pvdisplay WARNING: Running as a non-root user. Functionality may be unavailable. /run/lock/lvm/P_global:aux: open failed: Permission denied admin@i-06a632625d40e1c3d:~$ sudo pvdispaly sudo: pvdispaly: command not found admin@i-06a632625d40e1c3d:~$ sudo pvdisplay admin@i-06a632625d40e1c3d:~$
kihei/i-06a632625d40e1c3d 05:03
by SadServersle="unconfined" name="man_filter" pid=355 comm="apparmor_parser" [ 4.838571] audit: type=1400 audit(1703061908.844:6): apparmor="STATUS" operale="unconfined" name="man_groff" pid=355 comm="apparmor_parser" [ 4.854310] audit: type=1400 audit(1703061908.884:7): apparmor="STATUS" operale="unconfined" name="lsb_release" pid=356 comm="apparmor_parser" [ 4.869891] audit: type=1400 audit(1703061908.892:8): apparmor="STATUS" operale="unconfined" name="tcpdump" pid=357 comm="apparmor_parser" [ 4.885181] audit: type=1400 audit(1703061908.908:9): apparmor="STATUS" operale="unconfined" name="/usr/sbin/chronyd" pid=358 comm="apparmor_parser" [ 56.344814] IPv6: ADDRCONF(NETDEV_CHANGE): ens5: link becomes ready [ 58.685545] device-mapper: uevent: version 1.0.3 [ 58.690960] device-mapper: ioctl: 4.43.0-ioctl (2020-10-01) initialised: dm-dadmin@i-0934faf01c3d7420c:~$ vim /home/admin/kihei root@i-0934faf01c3d7420c:/home/admin# tar czf datafile > /tmp/datafile.tar.gz