command-line-murders/i-0b27c88934d5e8702
by SadServersMore by SadServers
admin@i-0342ea88046ffbc17:~$ ls agent webserver.py admin@i-0342ea88046ffbc17:~$ cat webserver.py cat: webserver.py: Permission denied admin@i-0342ea88046ffbc17:~$ ls -l webserver.py -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-0342ea88046ffbc17:~$ fuser 5000/tcp admin@i-0342ea88046ffbc17:~$
paris/i-0342ea88046ffbc17 04:47
by SadServers-rw------- 1 admin admin 718 Oct 1 22:38 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 15:56 .config drwxr-xr-x 8 admin admin 4096 Sep 30 17:45 .git -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4096 Sep 30 17:45 agent admin@i-0352eb7560afc8ca9:~$ git log commit bcef9dd4e3d8d7df272b9d644548424bff71d58a (HEAD -> master) Author: root <root@i-0d51cf049c4fac95c.us-east-2.compute.internal> Date: Sat Sep 30 17:45:52 2023 +0000 first draft admin@i-0352eb7560afc8ca9:~$ git sh
monaco/i-0352eb7560afc8ca9 03:27
by SadServerswrite(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-05088a4f1fc43f619:~$ strace ./kihei 2>&1 | grep datafile newfstatat(AT_FDCWD, "/home/admin/data/newdatafile", 0xc00008e9f8, 0) = -1 ENOENunlinkat(AT_FDCWD, "/home/admin/data/newdatafile", 0) = 0 admin@i-05088a4f1fc43f619:~$ cd data admin@i-05088a4f1fc43f619:~/data$ ls -al total 8 drwxr-xr-x 2 admin root 4096 Dec 5 09:17 . drwxr-xr-x 7 admin admin 4096 Dec 5 09:12 .. admin@i-05088a4f1fc43f619:~/data$ touch newdatafile admin@i-05088a4f1fc43f619:~/data$ strace .../kihei 2>&1 | grep datafile
kihei/i-05088a4f1fc43f619 07:44
by SadServers0 proc du: cannot read directory 'root': Permission denied 4.0K root du: cannot read directory 'run/chrony': Permission denied du: cannot read directory 'run/sudo': Permission denied du: cannot read directory 'run/lvm': Permission denied du: cannot read directory 'run/systemd/unit-root': Permission denied du: cannot read directory 'run/systemd/inaccessible/dir': Permission denied du: cannot read directory 'run/lock/lvm': Permission denied du: cannot read directory 'run/initramfs': Permission denied 356K run 0 sbin 4.0K srv du: cannot read directory 'sys/kernel/tracing': Permission denied