command-line-murders/i-0ef3e084d521485fc
by SadServersMore by SadServers
mmap(0x7f6d4f8a6000, 151552, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, mmap(0x7f6d4f8cb000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENY6d4f8cb000 mmap(0x7f6d4f8d1000, 848, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYM000 close(3) = 0 openat(AT_FDCWD, "/usr/lib/sudo/libpam.so.0", O_RDONLY|O_CLOEXEC) = -1 ENOENT (Nopenat(AT_FDCWD, "/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 3 fstat(3, {st_mode=S_IFREG|0644, st_size=17664, ...}) = 0 mmap(NULL, 17664, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f6d4f8e6000 close(3) = 0 openat(AT_FDCWD, "/lib/x86_64-linux-gnu/libpam.so.0", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\2005\0\0\0\0\0\0"..., 83fstat(3, {st_mode=S_IFREG|0644, st_size=67584, ...}) = 0 :
kihei/i-0a8c0a88489f2c5dc 03:24
by SadServers> GET / HTTP/1.1 > Host: localhost:5000 > User-Agent: curl/7.74.0 > Accept: */* > * Mark bundle as not supporting multiuse < HTTP/1.1 200 OK < Server: Werkzeug/2.3.7 Python/3.9.2 < Date: Thu, 22 Feb 2024 07:21:02 GMT < Content-Type: text/html; charset=utf-8 < Content-Length: 12 < Connection: close < * Closing connection 0 Unauthorizedadmin@i-050cad83ab4faeb81:~$ curl -v localhost:5000
paris/i-050cad83ab4faeb81 00:17
by SadServerslsof 905 admin mem REG 259,1 16612-linux-gnu/libselinux.so.1 lsof 905 admin mem REG 259,1 17792-linux-gnu/ld-2.31.so lsof 905 admin 4r FIFO 0,11 0tlsof 905 admin 7w FIFO 0,11 0tadmin@i-0032345432e40698b:~$ curl 172.31.44.67:5000 curl: (7) Failed to connect to 172.31.44.67 port 5000: Connection refused admin@i-0032345432e40698b:~$ curl localhost:5000 Unauthorizedadmin@i-0032345432e40698b:~$ md5sum Unauthorize md5sum: Unauthorize: No such file or directory admin@i-0032345432e40698b:~$ echo Unauthorize > ~/mysolution admin@i-0032345432e40698b:~$ md5sum ~/mysolution 0292f6b5fcbc291aa125a82d9ff97dc2 /home/admin/mysolution admin@i-0032345432e40698b:~$
paris/i-0032345432e40698b 02:05
by SadServersdrwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-08d654c3783758f46:~$ vim webserver.py admin@i-08d654c3783758f46:~$ sudo vim webserver.py We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: sudo: a password is required admin@i-08d654c3783758f46:~$