command-line-murders/i-054f01fab5c639973
by SadServersMore by SadServers
admin 740 0.0 0.1 2480 512 pts/1 S<s 03:27 0:00 sh -c /bin/baadmin 741 0.0 0.9 6820 4524 pts/1 S< 03:27 0:00 /bin/bash root 744 0.0 0.9 9336 4588 pts/1 S< 03:27 0:00 sudo su root 745 0.0 0.9 8672 4480 pts/1 S< 03:27 0:00 su root 747 0.1 1.6 15048 7636 ? Ss 03:27 0:00 /lib/systemd/root 748 0.0 0.5 101096 2640 ? S 03:27 0:00 (sd-pam) root 753 0.0 0.7 6052 3720 pts/1 S< 03:27 0:00 bash root 760 0.0 0.9 8672 4476 pts/1 S< 03:27 0:00 su admin admin 761 0.0 0.9 6824 4524 pts/1 S< 03:27 0:00 bash admin 770 0.0 0.6 8648 3164 pts/1 R<+ 03:28 0:00 ps aux admin@i-0f837dbf94cba2c30:~$ ls agent data datafile kihei admin@i-0f837dbf94cba2c30:~$ type kihei bash: type: kihei: not found admin@i-0f837dbf94cba2c30:~$ f
kihei/i-0f837dbf94cba2c30 01:20
by SadServersnvme0n1 ├─nvme0n1p1 ext4 1.0 811e12d8-f542-4650-9330-8d96633bd90c 1.2G ├─nvme0n1p14 └─nvme0n1p15 vfat FAT16 8690-F844 117.8M nvme1n1 nvme2n1 admin@i-03e8621f09ba2ba4e:~$ lvs WARNING: Running as a non-root user. Functionality may be unavailable. /run/lock/lvm/P_global:aux: open failed: Permission denied admin@i-03e8621f09ba2ba4e:~$ sudo lvs admin@i-03e8621f09ba2ba4e:~$ ls -la data total 8 drwxr-xr-x 2 admin root 4096 Oct 26 07:02 . drwxr-xr-x 7 admin admin 4096 Oct 26 07:02 .. admin@i-03e8621f09ba2ba4e:~$ sudo
kihei/i-03e8621f09ba2ba4e 03:40
by SadServers_chrony:x:104:104:Chrony daemon,,,:/var/lib/chrony:/usr/sbin/nologin systemd-network:x:105:106:systemd Network Management,,,:/run/systemd:/usr/sbin/nsystemd-resolve:x:106:107:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin sshd:x:107:65534::/run/sshd:/usr/sbin/nologin systemd-timesync:x:999:999:systemd Time Synchronization:/:/usr/sbin/nologin systemd-coredump:x:998:998:systemd Core Dumper:/:/usr/sbin/nologin admin:x:1000:1000:Debian:/home/admin:/bin/bash admin@i-0a733800c5258249a:~$ admin@i-0a733800c5258249a:~$ admin@i-0a733800c5258249a:~$ admin@i-0a733800c5258249a:~$ admin@i-0a733800c5258249a:~$ admin@i-0a733800c5258249a:~$ admin@i-0a733800c5258249a:~$ admin@i-0a733800c5258249a:~$ cat /etc/sha