command-line-murders/i-0070dd52ad137101e
by SadServersMore by SadServers
# The program is typically sudo, sudoers.so, sudoreplay or visudo. # # Subsystems vary based on the program; "all" matches all subsystems. # Priority may be crit, err, warn, notice, diag, info, trace or debug. # Multiple subsystem@priority may be specified, separated by a comma. # #Debug sudo /var/log/sudo_debug all@debug #Debug sudoers.so /var/log/sudoers_debug all@debug admin@i-020f08eb573cc1e85:~$ ls agent webserver.py admin@i-020f08eb573cc1e85:~$ cat /etc/sudo sudo.conf sudo_logsrvd.conf sudoers sudoers.d/ admin@i-020f08eb573cc1e85:~$ cat /etc/sudoers cat: /etc/sudoers: Permission denied admin@i-020f08eb573cc1e85:~$
paris/i-020f08eb573cc1e85 06:02
by SadServersroot 574 0.0 0.3 2872 1672 tty1 Ss+ 10:17 0:00 /sbin/agetty root 575 0.0 0.4 4396 2040 ttyS0 Ss+ 10:17 0:00 /sbin/agetty _chrony 577 0.0 0.7 10852 3668 ? S 10:17 0:00 /usr/sbin/chr_chrony 578 0.0 0.1 10724 556 ? S 10:17 0:00 /usr/sbin/chrroot 579 0.0 1.5 13352 7084 ? Ss 10:17 0:00 sshd: /usr/sbroot 583 0.0 3.7 26612 17396 ? Ss 10:17 0:00 /usr/bin/pythroot 662 0.0 0.0 0 0 ? I 10:17 0:00 [kworker/1:4-admin 664 0.0 0.9 6740 4464 pts/0 S<s+ 10:17 0:00 bash -l admin 668 0.1 4.1 98320 19236 pts/0 D<l+ 10:17 0:00 /usr/bin/pythadmin 671 0.0 3.1 24456 14924 pts/0 R<+ 10:17 0:00 /usr/bin/pythadmin 672 0.0 0.1 2480 568 pts/1 S<s 10:17 0:00 sh -c /bin/baadmin 673 0.0 1.0 6952 4792 pts/1 S< 10:17 0:00 /bin/bash root 717 0.0 0.0 0 0 ? R 10:18 0:00 [kworker/u4:4admin 762 0.0 0.6 8648 3212 pts/1 R<+ 10:19 0:00 ps aux admin@i-0cace07c960fab3ec:/etc$ ps aux
paris/i-0cace07c960fab3ec 03:17
by SadServersCreating file /home/admin/data/newdatafile with size 1.5GB... panic: exit status 1 goroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-09e737df09b9a9897:~$ df -h Filesystem Size Used Avail Use% Mounted on udev 217M 0 217M 0% /dev tmpfs 46M 368K 46M 1% /run /dev/nvme0n1p1 7.7G 6.1G 1.2G 84% / tmpfs 228M 12K 228M 1% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock /dev/nvme0n1p15 124M 5.9M 118M 5% /boot/efi admin@i-09e737df09b9a9897:~$ l