command-line-murders/i-021c8a26583681fde
by SadServersMore by SadServers
-rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4096 Sep 17 17:28 agent drwxr-xr-x 2 admin root 4096 Dec 22 23:35 data -rw-r--r-- 1 root root 5368709120 Sep 17 17:28 datafile -rwxr-xr-x 1 admin root 2207109 Sep 17 17:28 kihei admin@i-09847815c1c995975:~$ cd data admin@i-09847815c1c995975:~/data$ ls admin@i-09847815c1c995975:~/data$ ls -la total 8 drwxr-xr-x 2 admin root 4096 Dec 22 23:35 . drwxr-xr-x 7 admin admin 4096 Dec 22 23:35 .. admin@i-09847815c1c995975:~/data$ du 4 . admin@i-09847815c1c995975:~/data$ ls
kihei/i-09847815c1c995975 03:03
by SadServersDec 16 19:58:09 i-087a04010afc840a2 sudo[686]: pam_unix(sudo:session): session o) by (uid=1000) root@i-087a04010afc840a2:/home/admin# ^C root@i-087a04010afc840a2:/home/admin# tail -f /etc/systemd/system/gotty.service [Service] User=admin Group=admin ExecStart=/usr/local/gotty --permit-write --reconnect --max-connection 5 bash -lWorkingDirectory=/home/admin Restart=on-failure Nice=-20 [Install] WantedBy=multi-user.target
kihei/i-087a04010afc840a2 00:58
by SadServersroot 588 0.1 0.3 2872 1652 tty1 Ss+ 15:43 0:00 /sbin/agetty -o -p -- \u --noclear tty1 linux root 590 0.0 0.4 4396 2140 ttyS0 Ss+ 15:43 0:00 /sbin/agetty -o -p -- \u --keep-baud 115200,57600,38400,9600 ttyS0 vt220 root 591 0.0 1.5 13352 7188 ? Ss 15:43 0:00 sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 startups _chrony 593 0.0 0.7 10852 3596 ? S 15:43 0:00 /usr/sbin/chronyd -F 1 _chrony 604 0.0 0.1 10724 552 ? S 15:43 0:00 \_ /usr/sbin/chronyd -F 1 root 603 0.0 3.7 26612 17364 ? Ss 15:43 0:00 /usr/bin/python3 /usr/share/unattended-upgrades/unattended-upgrade-shutdown --wait-for-signaladmin@i-001eabc18e1752db3:~$ cat ~/webserver.py cat: /home/admin/webserver.py: Permission denied admin@i-001eabc18e1752db3:~$