command-line-murders/i-01286e07ebe12b514
by SadServersMore by SadServers
systemd-udev-trigger.service loaded active exited Coldplug All udev Dev systemd-udevd.service loaded active running Rule-based Manager fo systemd-update-utmp.service loaded active exited Update UTMP about Sys systemd-user-sessions.service loaded active exited Permit User Sessions unattended-upgrades.service loaded active running Unattended Upgrades S LOAD = Reflects whether the unit definition was properly loaded. ACTIVE = The high-level unit activation state, i.e. generalization of SUB. admin@i-0de83ec36426f6541:~$ systemctl --type=service | grep kihei admin@i-0de83ec36426f6541:~$ cd /home/admin admin@i-0de83ec36426f6541:~$ ls agent data datafile kihei admin@i-0de83ec36426f6541:~$ kehei bash: kehei: command not found admin@i-0de83ec36426f6541:~$ kehei
kihei/i-0de83ec36426f6541 01:28
by SadServersfind: ‘/var/cache/ldconfig’: Permission denied find: ‘/var/cache/apt/archives/partial’: Permission denied find: ‘/var/cache/apparmor/c08a2770.0’: Permission denied find: ‘/var/spool/rsyslog’: Permission denied find: ‘/var/spool/cron/crontabs’: Permission denied find: ‘/var/tmp/systemd-private-6311f1e23e8b46ab844ee53d9ed1279a-systemd-logind.on denied find: ‘/var/tmp/systemd-private-6311f1e23e8b46ab844ee53d9ed1279a-chrony.service-d find: ‘/var/log/private’: Permission denied find: ‘/var/log/chrony’: Permission denied find: ‘/var/lib/private’: Permission denied find: ‘/var/lib/apt/lists/partial’: Permission denied find: ‘/var/lib/chrony’: Permission denied admin@i-066a44d1b6845fe58:~$
kihei/i-066a44d1b6845fe58 01:35
by SadServers[sudo] password for admin: Sorry, try again. [sudo] password for admin: sudo: 1 incorrect password attempt admin@i-01ce4f2450e9d777d:~$ curl localhost curl: (7) Failed to connect to localhost port 80: Connection refused admin@i-01ce4f2450e9d777d:~$ iptables -L -v -n iptables v1.8.7 (nf_tables): Could not fetch rule set generation id: Permission admin@i-01ce4f2450e9d777d:~$ exec 3<>/dev/tcp/localhost/80 bash: connect: Connection refused bash: /dev/tcp/localhost/80: Connection refused admin@i-01ce4f2450e9d777d:~$ admin@i-01ce4f2450e9d777d:~$ admin@i-01ce4f2450e9d777d:~$ :> /dev/tcp/ya.ru/80 && echo $?
paris/i-01ce4f2450e9d777d 04:53
by SadServersadmin@i-0030ca60c3dfc6307:~$ netstat -tupln (Not all processes could be identified, non-owned process info will not be shown, you would have to be root to see it all.) Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN tcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN tcp6 0 0 :::22 :::* LISTEN tcp6 0 0 :::6767 :::* LISTEN tcp6 0 0 :::8080 :::* LISTEN udp 0 0 127.0.0.1:323 0.0.0.0:* udp 0 0 0.0.0.0:68 0.0.0.0:* udp6 0 0 fe80::841:92ff:fefb:546 :::* udp6 0 0 ::1:323 :::* admin@i-0030ca60c3dfc6307:~$