paris/i-00eb05101ee0e1b16
by SadServersMore by SadServers
/home/admin admin@i-04d9fdf17ef2b370a:~$ ls -la total 44 drwxr-xr-x 6 admin admin 4096 Sep 24 23:20 . drwxr-xr-x 3 root root 4096 Sep 17 16:44 .. drwx------ 3 admin admin 4096 Sep 20 15:52 .ansible -rw------- 1 admin admin 93 Jan 31 18:51 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 15:56 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-04d9fdf17ef2b370a:~$ nano webserver.py
paris/i-04d9fdf17ef2b370a 01:05
by SadServersdrwx------ 5 root root 4096 Jan 25 19:49 root drwxr-xr-x 22 root root 620 Jan 25 19:49 run lrwxrwxrwx 1 root root 8 Sep 28 2021 sbin -> usr/sbin drwxr-xr-x 2 root root 4096 Sep 28 2021 srv dr-xr-xr-x 13 root root 0 Jan 25 19:48 sys drwxrwxrwt 9 root root 4096 Jan 25 19:49 tmp drwxr-xr-x 14 root root 4096 Sep 28 2021 usr drwxr-xr-x 11 root root 4096 Sep 28 2021 var admin@i-0f29e47a857c873d8:/$ ls opt admin@i-0f29e47a857c873d8:/$ ls run agetty.reload cloud-init dbus initramfs network sshblkid credentials dhclient.ens5.pid lock screen sshchrony crond.pid dhclient6.ens5.pid log sendsigs.omit.d sudchrony-dhcp crond.reboot initctl mount shm sysadmin@i-0f29e47a857c873d8:/$ cd run
paris/i-0f29e47a857c873d8 03:51
by SadServerscast/ dpkg.log messages.2.gz user.log.2.chrony/ dpkg.log.1 minio.log wtmp admin@i-069e102734ffdd250:~$ less /var/log/messages admin@i-069e102734ffdd250:~$ cd /var/log/ admin@i-069e102734ffdd250:/var/log$ ls alternatives.log cast debug.1 kern.log.2.gz syslog alternatives.log.1 chrony debug.2.gz lastlog syslog.1 apt cloud-init-output.log dpkg.log messages syslog.2.gauth.log cloud-init.log dpkg.log.1 messages.1 unattendedauth.log.1 daemon.log faillog messages.2.gz user.log auth.log.2.gz daemon.log.1 journal minio.log user.log.1btmp daemon.log.2.gz kern.log private user.log.2btmp.1 debug kern.log.1 runit wtmp admin@i-069e102734ffdd250:/var/log$ less auth.log admin@i-069e102734ffdd250:/var/log$ less
paris/i-069e102734ffdd250 06:56
by SadServersadmin 801 0.0 4.1 98188 19424 pts/0 S<l+ 10:11 0:00 /usr/bin/pythec -t kihei/i-025570eb46de4c5ab -q -i 2 /var/log/cast/i-025570eb46de4c5ab admin 804 0.0 3.0 24456 14368 pts/0 S<+ 10:11 0:00 /usr/bin/pythec -t kihei/i-025570eb46de4c5ab -q -i 2 /var/log/cast/i-025570eb46de4c5ab admin 953 0.0 0.1 5264 640 pts/1 S<+ 10:16 0:00 grep kihei admin@i-025570eb46de4c5ab:~$ kill 801 admin@i-025570eb46de4c5ab:~$ ps aux | grep kihei admin 987 2.0 4.1 98188 19436 pts/0 S<l+ 10:16 0:00 /usr/bin/pythec -t kihei/i-025570eb46de4c5ab --append -q -i 2 /var/log/cast/i-025570eb46de4c5admin 990 0.0 3.1 24456 14872 pts/0 S<+ 10:16 0:00 /usr/bin/pythec -t kihei/i-025570eb46de4c5ab --append -q -i 2 /var/log/cast/i-025570eb46de4c5admin 996 0.0 0.1 5264 640 pts/1 S<+ 10:16 0:00 grep kihei admin@i-025570eb46de4c5ab:~$ ls -al /var/log/cast/i-025570eb46de4c5ab -rw-r--r-- 1 admin admin 19241 Nov 5 10:17 /var/log/cast/i-025570eb46de4c5ab admin@i-025570eb46de4c5ab:~$ l /var/log/cast/i-025570eb46de4c5ab