SadServers Joined on September 10, 2023
1656 public recordings by SadServers
23 2024-03-03T21:48:51 sudo cat webserver.py 24 2024-03-03T21:49:07 history admin@i-019de3f6d11f21310:~$ tail /var/log/cast/i-019de3f6d11f21310 [279.597103, "o", "\b\u001b[K"] [279.747432, "o", "\b\u001b[K"] [279.938418, "o", "\b\u001b[K"] [280.087389, "o", "\b\u001b[K"] [280.339197, "o", "\b\u001b[K"] [280.50538, "o", "\b\u001b[K"] [280.685408, "o", "\b\u001b[K"] [280.863917, "o", "\b\u001b[K"] [285.590638, "o", "\u001b[7m/var/log/cast/i-019de3f6d11f21310\u001b[27m"] [286.335788, "o", "\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\e3f6d11f21310\r\n\u001b[?2004l\r"] admin@i-019de3f6d11f21310:~$ tail /var/log/cast/i-019de3f6d11f21310
paris/i-019de3f6d11f21310 04:57
by SadServersdebian_chroot=$(cat /etc/debian_chroot) fi # set a fancy prompt (non-color, unless we know we "want" color) case "$TERM" in xterm-color|*-256color) color_prompt=yes;; esac # uncomment for a colored prompt, if the terminal has the capability; turned # off by default to not distract the user: the focus in a terminal window # should be on the output of commands, not on the prompt #force_color_prompt=yes if [ -n "$force_color_prompt" ]; then .bashrc
paris/i-0b8c64b46be811e03 02:29
by SadServersgoroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0c9554bbe26a61062:~$ mv datafile data admin@i-0c9554bbe26a61062:~$ ls agent data kihei admin@i-0c9554bbe26a61062:~$ ./kihei -v Creating file /home/admin/data/newdatafile with size 1.5GB... panic: exit status 1 goroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0c9554bbe26a61062:~$
kihei/i-0c9554bbe26a61062 06:49
by SadServersadmin 740 0.0 0.1 2480 512 pts/1 S<s 03:27 0:00 sh -c /bin/baadmin 741 0.0 0.9 6820 4524 pts/1 S< 03:27 0:00 /bin/bash root 744 0.0 0.9 9336 4588 pts/1 S< 03:27 0:00 sudo su root 745 0.0 0.9 8672 4480 pts/1 S< 03:27 0:00 su root 747 0.1 1.6 15048 7636 ? Ss 03:27 0:00 /lib/systemd/root 748 0.0 0.5 101096 2640 ? S 03:27 0:00 (sd-pam) root 753 0.0 0.7 6052 3720 pts/1 S< 03:27 0:00 bash root 760 0.0 0.9 8672 4476 pts/1 S< 03:27 0:00 su admin admin 761 0.0 0.9 6824 4524 pts/1 S< 03:27 0:00 bash admin 770 0.0 0.6 8648 3164 pts/1 R<+ 03:28 0:00 ps aux admin@i-0f837dbf94cba2c30:~$ ls agent data datafile kihei admin@i-0f837dbf94cba2c30:~$ type kihei bash: type: kihei: not found admin@i-0f837dbf94cba2c30:~$ f
kihei/i-0f837dbf94cba2c30 01:20
by SadServersadmin@i-01938499a23dd6d8b:~$ curl http://localhost:5000 Unauthorizedadmin@i-01938499a23dd6d8b:~$ curl https://localhost:5000 curl: (35) error:1408F10B:SSL routines:ssl3_get_record:wrong version number admin@i-01938499a23dd6d8b:~$ strace -p 573 strace: attach: ptrace(PTRACE_SEIZE, 573): Operation not permitted admin@i-01938499a23dd6d8b:~$ sudo strace -p 573 We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin:
paris/i-01938499a23dd6d8b 05:03
by SadServerscloud environment hosts lighttpd modules-loaadmin@i-07b1f6f3834fd3ea0:/etc$ cd apache2/ admin@i-07b1f6f3834fd3ea0:/etc/apache2$ ls conf-available admin@i-07b1f6f3834fd3ea0:/etc/apache2$ cd conf-available/ admin@i-07b1f6f3834fd3ea0:/etc/apache2/conf-available$ ls javascript-common.conf admin@i-07b1f6f3834fd3ea0:/etc/apache2/conf-available$ cat javascript-common.conAlias /javascript /usr/share/javascript/ <Directory "/usr/share/javascript/"> Options FollowSymLinks MultiViews </Directory> admin@i-07b1f6f3834fd3ea0:/etc/apache2/conf-available$ cd ~ admin@i-07b1f6f3834fd3ea0:~$ cd conf-available/
paris/i-07b1f6f3834fd3ea0 01:13
by SadServersadmin@i-0649ad53cc05cfe4d:~$ curl localhost:5000 Unauthorizedadmin@i-0649ad53cc05cfe4d:~$ cd /etc/ng bash: cd: /etc/ng: No such file or directory admin@i-0649ad53cc05cfe4d:~$ netstat -tunlp | grep 5000 (Not all processes could be identified, non-owned process info will not be shown, you would have to be root to see it all.) tcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN admin@i-0649ad53cc05cfe4d:~$ ss -ntlp | grep 500
paris/i-0649ad53cc05cfe4d 01:11
by SadServerstmpfs 46636 368 46268 1% /run /dev/nvme0n1p1 8026128 6354944 1241928 84% / tmpfs 233168 12 233156 1% /dev/shm tmpfs 5120 0 5120 0% /run/lock /dev/nvme0n1p15 126678 6016 120662 5% /boot/efi admin@i-012b34261aecbabc6:~$ strace -o xxx -f ./kihei panic: exit status 1 goroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-012b34261aecbabc6:~$ strace strace: must have PROG [ARGS] or -p PID Try 'strace -h' for more information. admin@i-012b34261aecbabc6:~$
kihei/i-012b34261aecbabc6 03:32
by SadServers1 bash
paris/i-0b5bb43a01e54b602 06:10
by SadServers1 bash
paris/i-0f6ee434bf2ef1d8a 06:49
by SadServers-rw-r--r-- 1 admin admin 1024 Feb 29 07:33 .webserver.py.swp drwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-03d33c47959abc794:~$ file webserver.py webserver.py: regular file, no read permission admin@i-03d33c47959abc794:~$ curl localhost:5000 Unauthorizedadmin@i-03d33c47959abc794:~$ curl -I localhost:5000 HTTP/1.1 200 OK Server: Werkzeug/2.3.7 Python/3.9.2 Date: Thu, 29 Feb 2024 07:34:11 GMT Content-Type: text/html; charset=utf-8 Content-Length: 12 Connection: close admin@i-03d33c47959abc794:~$