command-line-murders/i-0ab41fd8b91994a90
by SadServersMore by SadServers
drwxr-xr-x 2 admin root 4096 Nov 6 03:17 data drwxr-xr-x 7 admin admin 4096 Nov 6 03:17 . drwxr-xr-x 3 admin admin 4096 Nov 6 03:17 .config drwxr-xr-x 2 admin root 4096 Sep 17 17:28 agent -rwxr-xr-x 1 admin root 2207109 Sep 17 17:28 kihei -rw-r--r-- 1 root root 5368709120 Sep 17 17:28 datafile drwx------ 3 admin admin 4096 Sep 17 17:15 .ansible drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 3 root root 4096 Sep 17 16:44 .. -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile admin@i-0053f9210f2384812:~$ cd /ad bash: cd: /ad: No such file or directory admin@i-0053f9210f2384812:~$ cd /hom
kihei/i-0053f9210f2384812 00:55
by SadServersadmin@i-0be5d169af42c0cb5:~$ admin@i-0be5d169af42c0cb5:~$ admin@i-0be5d169af42c0cb5:~$ admin@i-0be5d169af42c0cb5:~$ localhost:5000 bash: localhost:5000: command not found admin@i-0be5d169af42c0cb5:~$ curl localhost:5000 Unauthorizedadmin@i-0be5d169af42c0cb5:~$ curl localhost:5000? Unauthorizedadmin@i-0be5d169af42c0cb5:~$ curl localhost:5000?/ls Unauthorizedadmin@i-0be5d169af42c0cb5:~$ curl localhost:5000?/'' Unauthorizedadmin@i-0be5d169af42c0cb5:~$ curl localhost:5000?/\\ls Unauthorizedadmin@i-0be5d169af42c0cb5:~$ curl localhost:5000?/
paris/i-0be5d169af42c0cb5 01:02
by SadServersle="unconfined" name="man_filter" pid=355 comm="apparmor_parser" [ 4.838571] audit: type=1400 audit(1703061908.844:6): apparmor="STATUS" operale="unconfined" name="man_groff" pid=355 comm="apparmor_parser" [ 4.854310] audit: type=1400 audit(1703061908.884:7): apparmor="STATUS" operale="unconfined" name="lsb_release" pid=356 comm="apparmor_parser" [ 4.869891] audit: type=1400 audit(1703061908.892:8): apparmor="STATUS" operale="unconfined" name="tcpdump" pid=357 comm="apparmor_parser" [ 4.885181] audit: type=1400 audit(1703061908.908:9): apparmor="STATUS" operale="unconfined" name="/usr/sbin/chronyd" pid=358 comm="apparmor_parser" [ 56.344814] IPv6: ADDRCONF(NETDEV_CHANGE): ens5: link becomes ready [ 58.685545] device-mapper: uevent: version 1.0.3 [ 58.690960] device-mapper: ioctl: 4.43.0-ioctl (2020-10-01) initialised: dm-dadmin@i-0934faf01c3d7420c:~$ vim /home/admin/kihei root@i-0934faf01c3d7420c:/home/admin# tar czf datafile > /tmp/datafile.tar.gz