SadServers Joined on September 10, 2023
2094 public recordings by SadServers
strings: webserver.py: Permission denied admin@i-0eed1c77d78127958:~$ ls -al total 44 drwxr-xr-x 6 admin admin 4096 Sep 24 2023 . drwxr-xr-x 3 root root 4096 Sep 17 2023 .. drwx------ 3 admin admin 4096 Sep 20 2023 .ansible -rw------- 1 admin admin 530 Feb 26 17:43 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 2023 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 2023 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-0eed1c77d78127958:~$
paris/i-0eed1c77d78127958 02:26
by SadServersman:sshd_config(5) Process: 581 ExecStartPre=/usr/sbin/sshd -t (code=exited, status=0/SUCCESS) Main PID: 590 (sshd) Tasks: 1 (limit: 521) Memory: 3.4M CPU: 38ms CGroup: /system.slice/ssh.service └─590 sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 startups Feb 26 15:21:30 i-0543a291e6e295bb0 systemd[1]: Starting OpenBSD Secure Shell seFeb 26 15:21:31 i-0543a291e6e295bb0 sshd[590]: Server listening on 0.0.0.0 port Feb 26 15:21:31 i-0543a291e6e295bb0 sshd[590]: Server listening on :: port 22. Feb 26 15:21:31 i-0543a291e6e295bb0 systemd[1]: Started OpenBSD Secure Shell seradmin@i-0543a291e6e295bb0:~$ lsof -i :22 admin@i-0543a291e6e295bb0:~$ ps aux
paris/i-0543a291e6e295bb0 02:24
by SadServers/dev/nvme0n1p1 7.7G 6.1G 1.2G 84% / admin@i-0cb4275c09b1a51bf:~$ ls -l total 5245048 drwxr-xr-x 2 admin root 4096 Sep 17 2023 agent drwxr-xr-x 2 admin root 4096 Feb 26 13:33 data -rw-r--r-- 1 root root 5368709120 Sep 17 2023 datafile -rwxr-xr-x 1 admin root 2207109 Sep 17 2023 kihei admin@i-0cb4275c09b1a51bf:~$ du -sh . 5.1G . admin@i-0cb4275c09b1a51bf:~$ strings datafile |less bash: strings: command not found admin@i-0cb4275c09b1a51bf:~$ admin@i-0cb4275c09b1a51bf:~$ cd / admin@i-0cb4275c09b1a51bf:/$ cd admin@i-0cb4275c09b1a51bf:~$
kihei/i-0cb4275c09b1a51bf 03:42
by SadServers4.0K /usr/libx32 4.0K /usr/src 36K /usr/libexec 52K /usr/include 13M /usr/local 23M /usr/sbin 105M /usr/bin 231M /usr/share 386M /usr/lib root@i-0f8f92f7d2a80ebe0:~# exit admin@i-0f8f92f7d2a80ebe0:~$ hd datafile | less admin@i-0f8f92f7d2a80ebe0:~$ tr -d '\0' < datafile > bla admin@i-0f8f92f7d2a80ebe0:~$ mv bla datafile mv: replace 'datafile', overriding mode 0644 (rw-r--r--)?
kihei/i-0f8f92f7d2a80ebe0 02:14
by SadServersadmin@i-09ca4fe48eca1e59f:~$ ls agent index.html webserver.py admin@i-09ca4fe48eca1e59f:~$ cat index.html Unauthorizedadmin@i-09ca4fe48eca1e59f:~$ telnet localhost 5000 Trying 127.0.0.1... Connected to localhost. Escape character is '^]'. Connection closed by foreign host. admin@i-09ca4fe48eca1e59f:~$ nc localhost 5000 GET 、 GET / ^C admin@i-09ca4fe48eca1e59f:~$ nc localhost 5000
paris/i-09ca4fe48eca1e59f 01:59
by SadServersadmin@i-01fcc0a2dcfcdf2e2:~$ ll bash: ll: command not found admin@i-01fcc0a2dcfcdf2e2:~$ ls -l total 5245048 drwxr-xr-x 2 admin root 4096 Sep 17 2023 agent drwxr-xr-x 2 admin root 4096 Sep 17 2023 data -rw-r--r-- 1 root root 5368709120 Sep 17 2023 datafile -rwxr-xr-x 1 admin root 2207109 Sep 17 2023 kihei admin@i-01fcc0a2dcfcdf2e2:~$ head ki
kihei/i-01fcc0a2dcfcdf2e2 00:16
by SadServersternal/cpu.maxExtendedFunctionInformationpath..inittaskpath.ErrBadPatterngo.itabuego.itab.*os.File,io.Writergo.itab.*strconv.NumError,errorgo.itab.*reflect.rtypag.durationValue,flag.Valuego.itab.*flag.float64Value,flag.Valuego.itab.*flag.in*flag.int64Value,flag.Valuego.itab.*flag.stringValue,flag.Valuego.itab.*flag.uin*flag.uint64Value,flag.Valuego.itab.*strings.Builder,io.Writergo.itab.*errors.ermt.wrapError,errorgo.itab.*fmt.pp,fmt.Statego.itab.*os.File,io.Readergo.itab.systab.*io/fs.PathError,errorgo.itab.*os.SyscallError,errorgo.itab.syscall.Errno,erio.Writergo.itab.*os.fileStat,io/fs.FileInfogo.itab.*io.LimitedReader,io.Readerggo.itab.*os/exec.ExitError,errorgo.itab.*os/exec.Error,errorgo.itab.*bufio.Reader.UnknownUserIdError,errorgo.itab.*internal/reflectlite.rtype,internal/reflectliizeError,errorgo.itab.*internal/fmtsort.SortedMap,sort.Interfacego.itab.runtime.t_cgo_thread_start_cgo_notify_runtime_init_done_cgo_callers_cgo_yield_cgo_mmap_cntime.mainPCgo.itab.*internal/poll.DeadlineExceededError,errorgo.itab.internal/pntime.defaultGOROOT.strruntime.buildVersion.strruntime.modinfo.strtype.*runtime.be3026ca784072:~$
kihei/i-08bbe3026ca784072 00:15
by SadServerstotal 5245048 drwxr-xr-x 2 admin root 4096 Sep 17 2023 agent drwxr-xr-x 2 admin root 4096 Feb 26 00:50 data -rw-r--r-- 1 admin root 5368709120 Sep 17 2023 datafile -rwxr-xr-x 1 admin root 2207109 Sep 17 2023 kihei admin@i-0f9aeca12a8d8e203:~$ ./kihei datafile panic: exit status 1 goroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0f9aeca12a8d8e203:~$ mv datafile .. mv: cannot move 'datafile' to '../datafile': Permission denied admin@i-0f9aeca12a8d8e203:~$ sudo mv datafile .. admin@i-0f9aeca12a8d8e203:~$
kihei/i-0f9aeca12a8d8e203 08:57
by SadServersH��$�H��H�� u �H H��$�H�H9�r*�v�H��H���1�H��H���H������H��H����H��$�H��$�H���'����D$7H��$�H��$�H�uH��$���Z�����1�H��H���H����H�� uH��$�� �Z���H���H��$���f.�u{ H�������-f.�u{��f.�v H�������f.�v��1�H��H���H�$����H��$���H��u��$���Z��Y�Z������H��$���f.�u{ H�������.f.�u{��f.�v H�������f. ������H�D$hH��$�H��$�H��$������H�T$hH9�w)s�H��H���1�H��H���H������H��H���H��$�H���$�H��$������H��$�H�\$PH��H��H��$�H�\$`�f���H��|MH��$�H�\$`H��$�H�|$P�B���f�H���H���H������H��H���H��$�H���H��$��ѹH��H��1�H����t ���O��H��H��KD��d��H�t$HH�FH�T$$HH9���H��$�H��$�H�L$x���H��$�H��$�H�L$pH�|$HH��$�H��$�H��$��ѹ��H��H��I��H��$�H�1�H��H���H�t$@H�FH�T$xH�D$@H��$�H��H��$��ؽ��H�|$@H9���H��$�H��$�H�L$x�p���H��$�H��HH��$�H�HH��H�:p�5b���H�DH�\$H�L$H�|$ H�t$(L�D$0����H�DH�\$H�L$H�|$ H�t$(L�D$0 H�l$H�l$H�D$(H�\$0H�|$@H�t$H�H�ʃ�H�L$H��wH�y�H��v*H��t�H��vH��u
kihei/i-0f95f6d88bb20f793 00:33
by SadServersdrwxr-xr-x 6 admin admin 4096 Sep 24 2023 . drwxr-xr-x 3 root root 4096 Sep 17 2023 .. drwx------ 3 admin admin 4096 Sep 20 2023 .ansible -rw------- 1 admin admin 363 Feb 25 19:59 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 2023 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 2023 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-05cb6bbf3f4dc2e99:~$ admin@i-05cb6bbf3f4dc2e99:~$ admin@i-05cb6bbf3f4dc2e99:~$ admin@i-05cb6bbf3f4dc2e99:~$ less .bash_
paris/i-05cb6bbf3f4dc2e99 03:31
by SadServersdrwxr-xr-x 7 admin admin 4096 Feb 25 18:58 . drwxr-xr-x 3 root root 4096 Sep 17 2023 .. drwx------ 3 admin admin 4096 Sep 17 2023 .ansible -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Feb 25 18:58 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 2023 .ssh drwxr-xr-x 2 admin root 4096 Sep 17 2023 agent drwxr-xr-x 2 admin root 4096 Sep 17 2023 data -rw-r--r-- 1 root root 5368709120 Sep 17 2023 datafile -rwxr-xr-x 1 admin root 2207109 Sep 17 2023 kihei admin@i-09dfc3938430c3175:~$ admin@i-09dfc3938430c3175:~$ admin@i-09dfc3938430c3175:~$
kihei/i-09dfc3938430c3175 00:42
by SadServersadmin@i-07e7b27bf9af3ef2e:~$ admin@i-07e7b27bf9af3ef2e:~$ admin@i-07e7b27bf9af3ef2e:~$ ls agent data datafile kihei admin@i-07e7b27bf9af3ef2e:~$ ls agent check.sh sadagent sadagent.txt admin@i-07e7b27bf9af3ef2e:~$ ls data admin@i-07e7b27bf9af3ef2e:~$ ^C admin@i-07e7b27bf9af3ef2e:~$ admin@i-07e7b27bf9af3ef2e:~$ admin@i-07e7b27bf9af3ef2e:~$ admin@i-07e7b27bf9af3ef2e:~$ admin@i-07e7b27bf9af3ef2e:~$ kihei -v bash: kihei: command not found admin@i-07e7b27bf9af3ef2e:~$
kihei/i-07e7b27bf9af3ef2e 03:06
by SadServerssystemd-udev-trigger.service loaded active exited Coldplug All udev Dev systemd-udevd.service loaded active running Rule-based Manager fo systemd-update-utmp.service loaded active exited Update UTMP about Sys systemd-user-sessions.service loaded active exited Permit User Sessions unattended-upgrades.service loaded active running Unattended Upgrades S LOAD = Reflects whether the unit definition was properly loaded. ACTIVE = The high-level unit activation state, i.e. generalization of SUB. admin@i-0de83ec36426f6541:~$ systemctl --type=service | grep kihei admin@i-0de83ec36426f6541:~$ cd /home/admin admin@i-0de83ec36426f6541:~$ ls agent data datafile kihei admin@i-0de83ec36426f6541:~$ kehei bash: kehei: command not found admin@i-0de83ec36426f6541:~$ kehei