command-line-murders/i-06d748b27203fae33
by SadServersMore by SadServers
-r--r--r-- 1 root root 0 Nov 28 20:01 timers -rw-rw-rw- 1 root root 0 Nov 28 20:01 timerslack_ns -rw-r--r-- 1 root root 0 Nov 28 20:01 uid_map -r--r--r-- 1 root root 0 Nov 28 20:01 wchan admin@i-03c3097309a075b56:/proc/576$ cd map_files/ bash: cd: map_files/: Permission denied admin@i-03c3097309a075b56:/proc/576$ ls -l^C admin@i-03c3097309a075b56:/proc/576$ less smaps smaps: Permission denied admin@i-03c3097309a075b56:/proc/576$ cat smaps cat: smaps: Permission denied admin@i-03c3097309a075b56:/proc/576$ stra^C admin@i-03c3097309a075b56:/proc/576$ strace -p 576 strace: attach: ptrace(PTRACE_SEIZE, 576): Operation not permitted admin@i-03c3097309a075b56:/proc/576$
paris/i-03c3097309a075b56 01:47
by SadServersirc:x:39:39:ircd:/run/ircd:/usr/sbin/nologin gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologinobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin _apt:x:100:65534::/nonexistent:/usr/sbin/nologin messagebus:x:101:101::/nonexistent:/usr/sbin/nologin uuidd:x:102:102::/run/uuidd:/usr/sbin/nologin tcpdump:x:103:103::/nonexistent:/usr/sbin/nologin _chrony:x:104:104:Chrony daemon,,,:/var/lib/chrony:/usr/sbin/nologin systemd-network:x:105:106:systemd Network Management,,,:/run/systemd:/usr/sbin/nsystemd-resolve:x:106:107:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin sshd:x:107:65534::/run/sshd:/usr/sbin/nologin systemd-timesync:x:999:999:systemd Time Synchronization:/:/usr/sbin/nologin systemd-coredump:x:998:998:systemd Core Dumper:/:/usr/sbin/nologin admin:x:1000:1000:Debian:/home/admin:/bin/bash admin@i-09dd7a16c1516f9c8:~$ sudo cat /etc/passwd\
kihei/i-09dd7a16c1516f9c8 05:30
by SadServerssystemd-udev-trigger.service loaded active exited Coldplug All udev Dev systemd-udevd.service loaded active running Rule-based Manager fo systemd-update-utmp.service loaded active exited Update UTMP about Sys systemd-user-sessions.service loaded active exited Permit User Sessions unattended-upgrades.service loaded active running Unattended Upgrades S LOAD = Reflects whether the unit definition was properly loaded. ACTIVE = The high-level unit activation state, i.e. generalization of SUB. admin@i-0de83ec36426f6541:~$ systemctl --type=service | grep kihei admin@i-0de83ec36426f6541:~$ cd /home/admin admin@i-0de83ec36426f6541:~$ ls agent data datafile kihei admin@i-0de83ec36426f6541:~$ kehei bash: kehei: command not found admin@i-0de83ec36426f6541:~$ kehei
kihei/i-0de83ec36426f6541 01:28
by SadServersroot 590 0.0 0.4 4396 2140 ttyS0 Ss+ 14:50 0:00 /sbin/agetty 15200,57600,38400,9600 ttyS0 vt220 root 591 0.0 1.5 13352 7152 ? Ss 14:50 0:00 sshd: /usr/sbf 10-100 startups _chrony 593 0.0 0.7 10852 3600 ? S 14:50 0:00 /usr/sbin/chr_chrony 594 0.0 0.1 10724 548 ? S 14:50 0:00 \_ /usr/sbinroot 606 0.1 3.7 26612 17420 ? Ss 14:50 0:00 /usr/bin/pyth-upgrades/unattended-upgrade-shutdown --wait-for-signal admin@i-06fb99aa236dc5e81:~$ python -m http.server bash: python: command not found admin@i-06fb99aa236dc5e81:~$ python3 -m http.server Serving HTTP on 0.0.0.0 port 8000 (http://0.0.0.0:8000/) ... ^C Keyboard interrupt received, exiting. admin@i-06fb99aa236dc5e81:~$ ls INPUT -p tcp -m tcp --dport 80 -j DROP