command-line-murders/i-0bac1ae74e339024d
by SadServersMore by SadServers
admin@i-08a1941667a15b5b6:/home$ cd /var/log/ admin@i-08a1941667a15b5b6:/var/log$ ls alternatives.log auth.log.2.gz cloud-init-output.log debug faillog te unattended-upgrades alternatives.log.1 btmp cloud-init.log debug.1 journal user.log apt btmp.1 daemon.log debug.2.gz kern.log g user.log.1 auth.log cast daemon.log.1 dpkg.log kern.log.1g.1 user.log.2.gz auth.log.1 chrony daemon.log.2.gz dpkg.log.1 kern.log.2g.2.gz wtmp admin@i-08a1941667a15b5b6:/var/log$ less messages admin@i-08a1941667a15b5b6:/var/log$ less syslog admin@i-08a1941667a15b5b6:/var/log$ c
paris/i-08a1941667a15b5b6 03:08
by SadServersagent webserver.py admin@i-0fcbbedeb8752ba6f:~$ ls -la total 44 drwxr-xr-x 6 admin admin 4096 Sep 24 23:20 . drwxr-xr-x 3 root root 4096 Sep 17 16:44 .. drwx------ 3 admin admin 4096 Sep 20 15:52 .ansible -rw------- 1 admin admin 296 Oct 20 18:46 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 15:56 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-0fcbbedeb8752ba6f:~$ curl X localhost:5000
paris/i-0fcbbedeb8752ba6f 01:50
by SadServers-rw-r--r-- 1 root root 5.0G Sep 17 17:28 datafile -rwxr-xr-x 1 admin root 2.2M Sep 17 17:28 kihei admin@i-0a6e70fd4f94f9e89:~$ du -h 11M ./agent 4.0K ./.ansible/tmp 8.0K ./.ansible 4.0K ./data 8.0K ./.config/asciinema 12K ./.config 8.0K ./.ssh 5.1G . admin@i-0a6e70fd4f94f9e89:~$ chmod 777 datafile chmod: changing permissions of 'datafile': Operation not permitted admin@i-0a6e70fd4f94f9e89:~$ sudo chmod 777 datafile (reverse-i-search)`/': lsof /home/admin/datafile