command-line-murders/i-0263644d84f9a9fc9
by SadServersMore by SadServers
#1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: sudo: a password is required admin@i-03a33d25bb83c1431:~$ ls agent webserver.py admin@i-03a33d25bb83c1431:~$ su ^C admin@i-03a33d25bb83c1431:~$ ls -l total 8 drwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-03a33d25bb83c1431:~$ python3
paris/i-03a33d25bb83c1431 02:18
by SadServersroot 587 0.0 1.4 13352 6828 ? Ss 21:55 0:00 sshd: /usr/sbroot 588 0.0 0.3 2872 1664 tty1 Ss+ 21:55 0:00 /sbin/agetty root 589 0.0 0.4 4396 2144 ttyS0 Ss+ 21:55 0:00 /sbin/agetty _chrony 591 0.0 0.7 10852 3664 ? S 21:55 0:00 /usr/sbin/chr_chrony 592 0.0 0.1 10724 548 ? S 21:55 0:00 /usr/sbin/chrroot 610 0.0 3.7 26612 17404 ? Ss 21:55 0:00 /usr/bin/pythroot 683 0.0 0.0 0 0 ? I 21:55 0:00 [kworker/1:3-admin 714 0.0 0.9 6740 4368 pts/0 S<s+ 21:56 0:00 bash -l admin 718 0.2 4.1 98320 19392 pts/0 R<l+ 21:56 0:00 /usr/bin/pythadmin 721 0.0 3.1 24456 14836 pts/0 R<+ 21:56 0:00 /usr/bin/pythadmin 722 0.0 0.1 2480 508 pts/1 S<s 21:56 0:00 sh -c /bin/baadmin 723 0.0 0.9 6820 4500 pts/1 S< 21:56 0:00 /bin/bash admin 819 0.0 0.6 8648 3260 pts/1 R<+ 21:59 0:00 ps aux admin@i-0cdefb94500ecc5ae:~$ vim log admin@i-0cdefb94500ecc5ae:~$ netsstat
paris/i-0cdefb94500ecc5ae 05:03
by SadServerslocal-fs-pre.target static - local-fs.target static - multi-user.target static - network-online.target static - admin@i-046eb98bd90d24c4a:~$ sudo -l Matching Defaults entries for admin on i-046eb98bd90d24c4a: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bi User admin may run the following commands on i-046eb98bd90d24c4a: (ALL : ALL) ALL (ALL) NOPASSWD: /sbin/shutdown admin@i-046eb98bd90d24c4a:~$ sudo /sbin/shutdown Shutdown scheduled for Fri 2024-02-23 19:06:27 UTC, use 'shutdown -c' to cancel.admin@i-046eb98bd90d24c4a:~$
paris/i-046eb98bd90d24c4a 05:02
by SadServers> GET / HTTP/1.1 > Host: localhost:5000 > User-Agent: curl/7.74.0 > Accept: */* > * Mark bundle as not supporting multiuse < HTTP/1.1 200 OK < Server: Werkzeug/2.3.7 Python/3.9.2 < Date: Mon, 10 Mar 2025 17:21:54 GMT < Content-Type: text/html; charset=utf-8 < Content-Length: 12 < Connection: close < * Closing connection 0 Unauthorizedadmin@i-0fe984bb4cc5c83b7:~$ wget -O - localhost:5000