kihei/i-04ccb8cd2e0947f89
by SadServersMore by SadServers
inary_Operatorunicode.IDS_Trinary_Operatorunicode.Ideographicunicode.Join_Controcunicode.Other_Default_Ignorable_Code_Pointunicode.Other_Grapheme_Extendunicode.e.Other_Uppercaseunicode.Pattern_Syntaxunicode.Pattern_White_Spaceunicode.Prepennicode.Sentence_Terminalunicode.Soft_Dottedunicode.Terminal_Punctuationunicode.U.FoldCategoryunicode.foldLunicode.foldLlunicode.foldLtunicode.foldLuunicode.foldtedinternal/cpu.DebugOptionsinternal/cpu.CacheLineSizeinternal/cpu.X86internal/co.itab.*flag.boolValue,flag.Valuego.itab.*os.File,io.Writergo.itab.*strconv.NumEitab.*flag.float64Value,flag.Valuego.itab.*flag.intValue,flag.Valuego.itab.*flag.Valuego.itab.*flag.uint64Value,flag.Valuego.itab.*strings.Builder,io.Writergo.itab.*os.File,io.Readergo.itab.syscall.Signal,os.Signalgo.itab.*io/fs.PathError,eWritergo.itab.*os.fileStat,io/fs.FileInfogo.itab.*io.LimitedReader,io.Readergo.itab.*bufio.Reader,io.Readergo.itab.os/user.UnknownUserIdError,errorgo.itab.*inteb.*internal/fmtsort.SortedMap,sort.Interfacego.itab.runtime.errorString,error_cgo_munmap_cgo_sigactionruntime.mainPCgo.itab.*internal/poll.DeadlineExceededErrorersion.strruntime.modinfo.strtype.*runtime.textsectionmapadmin@i-08c990dcb570e62
i-08c990dcb570e6294 00:10
by SadServers./main.go:64 +0x47d admin@i-012a3c759519cd682:~$ cd /home/admin/ admin@i-012a3c759519cd682:~$ ls agent data datafile kihei admin@i-012a3c759519cd682:~$ ls -li total 5245048 264663 drwxr-xr-x 2 admin root 4096 Sep 17 17:28 agent 278531 drwxr-xr-x 2 admin root 4096 Dec 11 16:09 data 264701 -rw-r--r-- 1 root root 5368709120 Sep 17 17:28 datafile 264672 -rwxr-xr-x 1 admin root 2207109 Sep 17 17:28 kihei admin@i-012a3c759519cd682:~$ sudo chown admin.root datafile admin@i-012a3c759519cd682:~$ ls -li^C admin@i-012a3c759519cd682:~$ ./kh bash: ./kh: No such file or directory admin@i-012a3c759519cd682:~$ ./kh
kihei/i-012a3c759519cd682 01:42
by SadServers> GET / HTTP/1.1 > Host: localhost:5000 > User-Agent: curl/7.74.0 > Accept: */* > * Mark bundle as not supporting multiuse < HTTP/1.1 200 OK < Server: Werkzeug/2.3.7 Python/3.9.2 < Date: Wed, 12 Mar 2025 13:17:34 GMT < Content-Type: text/html; charset=utf-8 < Content-Length: 12 < Connection: close < * Closing connection 0 Unauthorizedadmin@i-0e37dc7950bbca2c9:~$ curl -vvv localhost:5000
paris/i-0e37dc7950bbca2c9 02:11
by SadServers83 -q -i 2 /var/log/cast/i-0df1765d3 admin 681 0.0 3.0 24456 14444 pts/0 R<+ 02:55 0:00 /usr/bin/pyth83 -q -i 2 /var/log/cast/i-0df1765d3 admin 682 0.0 0.1 2480 572 pts/1 S<s 02:55 0:00 sh -c /bin/baadmin 683 0.0 0.9 6820 4536 pts/1 S< 02:55 0:00 /bin/bash admin 716 0.0 0.6 8648 3136 pts/1 R<+ 02:56 0:00 ps -aux admin@i-0df1765d381c3a083:~$ ps -aux | grep kihei admin 678 0.4 4.1 98188 19260 pts/0 S<l+ 02:55 0:00 /usr/bin/pyth83 -q -i 2 /var/log/cast/i-0df1765d381c3a083 admin 681 0.0 3.0 24456 14444 pts/0 S<+ 02:55 0:00 /usr/bin/pyth83 -q -i 2 /var/log/cast/i-0df1765d381c3a083 admin 718 0.0 0.1 5264 704 pts/1 S<+ 02:56 0:00 grep kihei admin@i-0df1765d381c3a083:~$ ls agent data datafile kihei admin@i-0df1765d381c3a083:~$