command-line-murders/i-017030b44f86ef33b
by SadServersMore by SadServers
-rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 2023 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 2023 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-0c7688c6e49a68923:~$ cd /var/log admin@i-0c7688c6e49a68923:/var/log$ ls alternatives.log auth.log btmp chrony daemon.log journal kern.log.2.gz messages.1 private syslog.1 user.lalternatives.log.1 auth.log.1 btmp.1 cloud-init-output.log daemon.log.1 kern.log lastlog messages.2.gz runit syslog.2.gz user.lapt auth.log.2.gz cast cloud-init.log daemon.log.2.g kern.log.1 messages minio.log syslog unattended-upgrades user.ladmin@i-0c7688c6e49a68923:/var/log$ less
paris/i-0c7688c6e49a68923 04:44
by SadServersCreating journal (8192 blocks): done Writing superblocks and filesystem accounting information: done admin@i-05ecaf7ad85aff174:~$ sudo rsync -aAXv / --exclude=/mnt/newvol /mnt/newvosudo: rsync: command not found admin@i-05ecaf7ad85aff174:~$ df -h Filesystem Size Used Avail Use% Mounted on udev 217M 0 217M 0% /dev tmpfs 46M 372K 46M 1% /run /dev/nvme0n1p1 7.7G 6.1G 1.2G 84% / tmpfs 228M 12K 228M 1% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock /dev/nvme0n1p15 124M 5.9M 118M 5% /boot/efi /dev/mapper/myvg-mylv 1.9G 24K 1.8G 1% /mnt/newvol admin@i-05ecaf7ad85aff174:~$ fdisk
kihei/i-05ecaf7ad85aff174 01:34
by SadServersroot 574 0.0 0.3 2872 1672 tty1 Ss+ 10:17 0:00 /sbin/agetty root 575 0.0 0.4 4396 2040 ttyS0 Ss+ 10:17 0:00 /sbin/agetty _chrony 577 0.0 0.7 10852 3668 ? S 10:17 0:00 /usr/sbin/chr_chrony 578 0.0 0.1 10724 556 ? S 10:17 0:00 /usr/sbin/chrroot 579 0.0 1.5 13352 7084 ? Ss 10:17 0:00 sshd: /usr/sbroot 583 0.0 3.7 26612 17396 ? Ss 10:17 0:00 /usr/bin/pythroot 662 0.0 0.0 0 0 ? I 10:17 0:00 [kworker/1:4-admin 664 0.0 0.9 6740 4464 pts/0 S<s+ 10:17 0:00 bash -l admin 668 0.1 4.1 98320 19236 pts/0 D<l+ 10:17 0:00 /usr/bin/pythadmin 671 0.0 3.1 24456 14924 pts/0 R<+ 10:17 0:00 /usr/bin/pythadmin 672 0.0 0.1 2480 568 pts/1 S<s 10:17 0:00 sh -c /bin/baadmin 673 0.0 1.0 6952 4792 pts/1 S< 10:17 0:00 /bin/bash root 717 0.0 0.0 0 0 ? R 10:18 0:00 [kworker/u4:4admin 762 0.0 0.6 8648 3212 pts/1 R<+ 10:19 0:00 ps aux admin@i-0cace07c960fab3ec:/etc$ ps aux
paris/i-0cace07c960fab3ec 03:17
by SadServers[sudo] password for admin: Sorry, try again. [sudo] password for admin: Sorry, try again. [sudo] password for admin: sudo: 3 incorrect password attempts admin@i-048902c622e991104:~$ su Password: su: Authentication failure admin@i-048902c622e991104:~$ systemctl status nginx Unit nginx.service could not be found. admin@i-048902c622e991104:~$ systemctl status apache2 Unit apache2.service could not be found. admin@i-048902c622e991104:~$ curl -I local