command-line-murders/i-09ca104d15c5fd532
by SadServersMore by SadServers
5.1G . admin@i-04ba647eafae86351:~$ ls agent data datafile kihei admin@i-04ba647eafae86351:~$ cd .. admin@i-04ba647eafae86351:/home$ du -h . 11M ./admin/agent 4.0K ./admin/.ansible/tmp 8.0K ./admin/.ansible 4.0K ./admin/data 8.0K ./admin/.config/asciinema 12K ./admin/.config 8.0K ./admin/.ssh 5.1G ./admin 5.1G . admin@i-04ba647eafae86351:/home$ cd
kihei/i-04ba647eafae86351 04:09
by SadServersadmin@i-0e2c9c64a6cc5b706:~$ ls agent webserver.py admin@i-0e2c9c64a6cc5b706:~$ ls agent/ check.sh sadagent sadagent.txt admin@i-0e2c9c64a6cc5b706:~$ ls agent/sadagent agent/sadagent admin@i-0e2c9c64a6cc5b706:~$ file agent/sadagent agent/sadagent: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, Go BuildID=H6A8cVluPFUvaNojVwMi/C5t-5rNiA5GJLWeSm5Qz/KXfivG_lDFnrqPGrWEJo/K_OQEFevUZEPr4lPEnoe, not stripped admin@i-0e2c9c64a6cc5b706:~$ ./agent/check.sh md5sum: /home/admin/mysolution: No such file or directory NOadmin@i-0e2c9c64a6cc5b706:~$ ./agent/
paris/i-0e2c9c64a6cc5b706 01:06
by SadServers< HTTP/1.1 404 NOT FOUND < Server: Werkzeug/2.3.7 Python/3.9.2 < Date: Mon, 27 Nov 2023 04:23:02 GMT < Content-Type: text/html; charset=utf-8 < Content-Length: 207 < Connection: close < <!doctype html> <html lang=en> <title>404 Not Found</title> <h1>Not Found</h1> <p>The requested URL was not found on the server. If you entered the URL manuallgain.</p> * Closing connection 0 admin@i-06333f5caffef4d07:~$ curl -vvvv -XGET http://127.0.0.1:5000/password
paris/i-06333f5caffef4d07 04:45
by SadServersadmin@i-0e3126c91f22b8e7e:~$ cd /home/admin/ admin@i-0e3126c91f22b8e7e:~$ ls agent data datafile kihei admin@i-0e3126c91f22b8e7e:~$ ps aux | grep kihei admin 733 0.4 4.1 98188 19420 pts/0 S<l+ 21:13 0:00 /usr/bin/pyth-t kihei/i-0e3126c91f22b8e7e -q -i 2 /var/log/cast/i-0e3126c91f22b8e7e admin 736 0.0 3.0 24456 14364 pts/0 S<+ 21:13 0:00 /usr/bin/pyth-t kihei/i-0e3126c91f22b8e7e -q -i 2 /var/log/cast/i-0e3126c91f22b8e7e admin 747 0.0 0.1 5264 696 pts/1 S<+ 21:14 0:00 grep kihei admin@i-0e3126c91f22b8e7e:~$ chmod -R a-w /var/log/cast/ admin@i-0e3126c91f22b8e7e:~$