command-line-murders/i-0da7444792cf695ad
by SadServersMore by SadServers
drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-010d84eaab4d0fc03:~$ cp /home/admin/webserver.py /tmp/ cp: cannot open '/home/admin/webserver.py' for reading: Permission denied admin@i-010d84eaab4d0fc03:~$ admin@i-010d84eaab4d0fc03:~$ ls -la /home/admin/agent/ total 11144 drwxr-xr-x 2 admin root 4096 Sep 24 2023 . drwxr-xr-x 6 admin admin 4096 Sep 24 2023 .. -rwxr-xr-x 1 admin admin 230 Sep 24 2023 check.sh -rwxr-xr-x 1 admin root 11397096 Sep 20 2023 sadagent -rw-r--r-- 1 admin admin 0 Sep 20 2023 sadagent.txt admin@i-010d84eaab4d0fc03:~$ ls -la /home/admin/agent/sadagent -rwxr-xr-x 1 admin root 11397096 Sep 20 2023 /home/admin/agent/sadagent admin@i-010d84eaab4d0fc03:~$
paris/i-010d84eaab4d0fc03 02:29
by SadServersgoroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0643e3d538c33101b:~$ df -h Filesystem Size Used Avail Use% Mounted on udev 217M 0 217M 0% /dev tmpfs 46M 368K 46M 1% /run /dev/nvme0n1p1 7.7G 6.1G 1.2G 84% / tmpfs 228M 12K 228M 1% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock /dev/nvme0n1p15 124M 5.9M 118M 5% /boot/efi admin@i-0643e3d538c33101b:~$ ls agent data datafile kihei admin@i-0643e3d538c33101b:~$ ls data
kihei/i-0643e3d538c33101b 00:22
by SadServers<body> <div id="terminal"></div> <script src="./auth_token.js"></script> <script src="./config.js"></script> <script src="./js/gotty.js"></script> </body> </html>admin@i-059abcaabcac3684a:~$ curl localhost:8080/auth_token.js var gotty_auth_token = '';admin@i-059abcaabcac3684a:~$ admin@i-059abcaabcac3684a:~$ curl localhost:8080/config.js var gotty_term = 'xterm';admin@i-059abcaabcac3684a:~$ admin@i-059abcaabcac3684a:~$ admin@i-059abcaabcac3684a:~$ #bah that's asciinema admin@i-059abcaabcac3684a:~$
paris/i-059abcaabcac3684a 05:39
by SadServersopenat(AT_FDCWD, "/home/admin/webserver.py", O_RDONLY|O_CLOEXEC) = -1 EACCES (Pestat("/home/admin/webserver.py", {st_mode=S_IFREG|0770, st_size=360, ...}) = 0 readlink("/home/admin/webserver.py", 0x7ffcd0b15d90, 4096) = -1 EINVAL (Invalid lstat("/home", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0 lstat("/home/admin", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0 lstat("/home/admin/webserver.py", {st_mode=S_IFREG|0770, st_size=360, ...}) = 0 openat(AT_FDCWD, "/home/admin/webserver.py", O_RDONLY) = -1 EACCES (Permission dwrite(2, "python3: can't open file '/home/"..., 82python3: can't open file '/homrrno 13] Permission denied ) = 82 rt_sigaction(SIGINT, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=SA_RESTORER, sa_r{sa_handler=0x6402c0, sa_mask=[], sa_flags=SA_RESTORER, sa_restorer=0x7f1915bdf1exit_group(2) = ? +++ exited with 2 +++ admin@i-0c85c5a418bb83a0e:/etc/systemd/system$ strace python3 /home/admin/webser