NAME GENDER AGE ADDRESS Alicia Fuentes F 48 Walton Street, line 433 Jo-Ting Losev F 46 Hemenway Street, line 390 Elena Edmonds F 58 Elmwood Avenue, line 123 Naydene Cabral F 46 Winthrop Street, line 454 Dato Rosengren M 22 Mystic Street, line 477 Fernanda Serrano F 37 Redlands Road, line 392 Emiliano Wenk M 90 Paulding Street, line 490 Larry Lapin M 71 Atwill Road, line 298 Jakub Gondos M 61 Mitchell Street, line 187 Derek Kazanin M 55 Tennis Road, line 440 Jens Tuimalealiifano M 83 Rockwood Street, line 205 Nikola Kadhi M 75 Glenville Avenue, line 226 admin@i-0066b8658d8595e68:~/clmystery/mystery$ ls crimescene interviews memberships people streets vehicles admin@i-0066b8658d8595e68:~/clmystery/mystery$ cd .. admin@i-0066b8658d8595e68:~/clmystery$ ls LICENSE.md cheatsheet.md hint1 hint3 hint5 hint7 instructions README.md cheatsheet.pdf hint2 hint4 hint6 hint8 mystery admin@i-0066b8658d8595e68:~/clmystery$ cat hint2 Try using grep to search for the clues in the crimescene file: grep "CLUE" crimescene admin@i-0066b8658d8595e68:~/clmystery$ cat hint3 In order to track down our potential witness, we need to figure out where she lives. Try using 'head' on some of the files like 'people' and 'vehicles' and see where we might find that. admin@i-0066b8658d8595e68:~/clmystery$ cat hint4 To find all the Annabels' addresses, use the 'people' file: grep "Annabel" people Notice that not all of the results are worth investigating. Remember what we know about Annabel. admin@i-0066b8658d8595e68:~/clmystery$ grep 'Annabel' people grep: people: No such file or directory admin@i-0066b8658d8595e68:~/clmystery$ grep 'Annabel' /clmystery/mystery/people grep: /clmystery/mystery/people: No such file or directory admin@i-0066b8658d8595e68:~/clmystery$
command-line-murders/i-0066b8658d8595e68
by SadServersMore by SadServers
admin@i-0b117fa6b5ba9fe7f:~$ curl localhost:5000 Unauthorizedadmin@i-0b117fa6b5ba9fe7f:~$ netstat -ano | grep 5000 tcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN tcp 0 0 127.0.0.1:58914 127.0.0.1:5000 TIME_WAIT admin@i-0b117fa6b5ba9fe7f:~$ curl localhost:58914 curl: (7) Failed to connect to localhost port 58914: Connection refused admin@i-0b117fa6b5ba9fe7f:~$ netstat -ano | grep 5000 tcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN tcp 0 0 127.0.0.1:58914 127.0.0.1:5000 TIME_WAIT admin@i-0b117fa6b5ba9fe7f:~$ ls agent webserver.py admin@i-0b117fa6b5ba9fe7f:~$ cat
paris/i-0b117fa6b5ba9fe7f 03:03
by SadServerswrite(2, "main.main", 9main.main) = 9 write(2, "(", 1() = 1 write(2, ")\n", 2) ) = 2 write(2, "\t", 1 ) = 1 write(2, "./main.go", 9./main.go) = 9 write(2, ":", 1:) = 1 write(2, "64", 264) = 2 write(2, " +", 2 +) = 2 write(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-035d976ba3c56dd73:~$
kihei/i-035d976ba3c56dd73 00:05
by SadServersdrwx------ 5 root root 4096 Jan 25 19:49 root drwxr-xr-x 22 root root 620 Jan 25 19:49 run lrwxrwxrwx 1 root root 8 Sep 28 2021 sbin -> usr/sbin drwxr-xr-x 2 root root 4096 Sep 28 2021 srv dr-xr-xr-x 13 root root 0 Jan 25 19:48 sys drwxrwxrwt 9 root root 4096 Jan 25 19:49 tmp drwxr-xr-x 14 root root 4096 Sep 28 2021 usr drwxr-xr-x 11 root root 4096 Sep 28 2021 var admin@i-0f29e47a857c873d8:/$ ls opt admin@i-0f29e47a857c873d8:/$ ls run agetty.reload cloud-init dbus initramfs network sshblkid credentials dhclient.ens5.pid lock screen sshchrony crond.pid dhclient6.ens5.pid log sendsigs.omit.d sudchrony-dhcp crond.reboot initctl mount shm sysadmin@i-0f29e47a857c873d8:/$ cd run