paris/i-0592aa918bacc14b6
by SadServersMore by SadServers
-upgrades/unattended-upgrade-shutdown -- root 685 0.0 0.0 0 0 ? I 04:20 0:00 [kworker/1:4-admin 687 0.0 0.9 6740 4512 pts/0 S<s+ 04:20 0:00 bash -l admin 691 0.5 4.1 98188 19348 pts/0 S<l+ 04:20 0:00 /usr/bin/pythc -t paris/i-0cea73f15d68f034f -q -i 2 / admin 694 0.0 3.0 24456 14436 pts/0 S<+ 04:20 0:00 /usr/bin/pythc -t paris/i-0cea73f15d68f034f -q -i 2 / admin 695 0.0 0.1 2480 572 pts/1 S<s 04:20 0:00 sh -c /bin/baadmin 696 0.0 1.0 6952 4724 pts/1 S< 04:20 0:00 /bin/bash admin 709 0.0 0.6 8648 3240 pts/1 R<+ 04:20 0:00 ps aux admin@i-0cea73f15d68f034f:~$ ps aux|grep -i web root 574 0.5 6.0 107132 28320 ? Ss 04:20 0:00 /usr/bin/pyth.py admin 712 0.0 0.1 5132 640 pts/1 S<+ 04:20 0:00 grep -i web admin@i-0cea73f15d68f034f:~$
paris/i-0cea73f15d68f034f 00:54
by SadServersle="unconfined" name="man_filter" pid=355 comm="apparmor_parser" [ 4.838571] audit: type=1400 audit(1703061908.844:6): apparmor="STATUS" operale="unconfined" name="man_groff" pid=355 comm="apparmor_parser" [ 4.854310] audit: type=1400 audit(1703061908.884:7): apparmor="STATUS" operale="unconfined" name="lsb_release" pid=356 comm="apparmor_parser" [ 4.869891] audit: type=1400 audit(1703061908.892:8): apparmor="STATUS" operale="unconfined" name="tcpdump" pid=357 comm="apparmor_parser" [ 4.885181] audit: type=1400 audit(1703061908.908:9): apparmor="STATUS" operale="unconfined" name="/usr/sbin/chronyd" pid=358 comm="apparmor_parser" [ 56.344814] IPv6: ADDRCONF(NETDEV_CHANGE): ens5: link becomes ready [ 58.685545] device-mapper: uevent: version 1.0.3 [ 58.690960] device-mapper: ioctl: 4.43.0-ioctl (2020-10-01) initialised: dm-dadmin@i-0934faf01c3d7420c:~$ vim /home/admin/kihei root@i-0934faf01c3d7420c:/home/admin# tar czf datafile > /tmp/datafile.tar.gz
kihei/i-0934faf01c3d7420c 04:53
by SadServersadmin@i-08be9ae6ca86822e0:~$ curl localhost:5000 Unauthorizedadmin@i-08be9ae6ca86822e0:~$ id uid=1000(admin) gid=1000(admin) groups=1000(admin),4(adm),20(dialout),24(cdrom),),30(dip),44(video),46(plugdev),109(netdev) admin@i-08be9ae6ca86822e0:~$ nc nc nc.openbsd admin@i-08be9ae6ca86822e0:~$ man nc admin@i-08be9ae6ca86822e0:~$ nc localhost 5000
paris/i-08be9ae6ca86822e0 00:50
by SadServersUser admin may run the following commands on i-08be8007cddf7ce4c: (ALL : ALL) ALL (ALL) NOPASSWD: /sbin/shutdown admin@i-08be8007cddf7ce4c:~$ sudo nmap -sS 172.31.43.117 -p- We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: