command-line-murders/i-063d5b2343519e70e
by SadServersMore by SadServers
linux-gnu/libpthread-2.31.so lsof 769 admin mem REG 259,1 1868linux-gnu/libdl-2.31.so lsof 769 admin mem REG 259,1 61712linux-gnu/libpcre2-8.so.0.10.1 lsof 769 admin mem REG 259,1 190153linux-gnu/libc-2.31.so lsof 769 admin mem REG 259,1 16612linux-gnu/libselinux.so.1 lsof 769 admin mem REG 259,1 17792linux-gnu/ld-2.31.so lsof 769 admin 4r FIFO 0,11 0tlsof 769 admin 7w FIFO 0,11 0tadmin@i-059fb7e158508f014:~$ lsof |grep webserver admin@i-059fb7e158508f014:~$ lsof |grep .pyu
paris/i-059fb7e158508f014 01:33
by SadServersapparmor.d cron.daily e2scrub.conf gshadow iptab modprobe.d os-release rc0.d rsyslog.conf skel sysctl.conapt cron.hourly environment gshadow- issue modules pam.conf rc1.d rsyslog.d ssh sysctl.d bash.bashrc cron.monthly ethertypes gss issue modules-load.d pam.d rc2.d runit ssl systemd bash_completion cron.weekly fonts host.conf kerne motd passwd rc3.d sadscenario subgid terminfo bindresvport.blacklist crontab fstab hostname kerne mtab passwd- rc4.d screenrc subgid- timezone binfmt.d dbus-1 fstab.old hosts knock nanorc pm rc5.d security subuid tmpfiles.dca-certificates debconf.conf gai.conf hosts.allow ld.so netconfig ppp rc6.d selinux subuid- ucf.conf admin@i-0f38fefa3d5eb7b9e:~$
taipei/i-0f38fefa3d5eb7b9e 02:46
by SadServersunix 3 [ ] STREAM CONNECTED 11366 unix 3 [ ] STREAM CONNECTED 11352 unix 3 [ ] STREAM CONNECTED 11353 /run/systemd/journal/unix 3 [ ] STREAM CONNECTED 11367 /run/dbus/system_bus_admin@i-04e9b3dc5974733a8:~$ netstat -nptl (Not all processes could be identified, non-owned process info will not be shown, you would have to be root to see it all.) Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State tcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN tcp6 0 0 :::6767 :::* LISTEN tcp6 0 0 :::8080 :::* LISTEN tcp6 0 0 :::22 :::* LISTEN admin@i-04e9b3dc5974733a8:~$ telnet
paris/i-04e9b3dc5974733a8 01:25
by SadServersWelcome! Password is FDZPmh5AX3oiJt^C admin@i-06cc86bd8a997be11:~$ echo FDZP^C admin@i-06cc86bd8a997be11:~$ echo GET / |nc -v localhost 5000 Connection to localhost (127.0.0.1) 5000 port [tcp/*] succeeded! ^C admin@i-06cc86bd8a997be11:~$ nc -v localhost 5000 <<< echo GET / nc: port number invalid: GET admin@i-06cc86bd8a997be11:~$ nc -v localhost 5000 <<< echo GET /