command-line-murders/i-0c05d8296a1c3592d
by SadServersMore by SadServers
drwxr-xr-x 7 admin admin 1M Mar 13 04:45 . drwxr-xr-x 3 root root 1M Sep 17 2023 .. drwx------ 3 admin admin 1M Sep 17 2023 .ansible -rw-r--r-- 1 admin admin 1M Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 1M Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 1M Mar 13 04:45 .config -rw-r--r-- 1 admin admin 1M Aug 4 2021 .profile drwx------ 2 admin admin 1M Sep 17 2023 .ssh drwxr-xr-x 2 admin root 1M Sep 17 2023 agent drwxr-xr-x 2 admin root 1M Sep 17 2023 data -rw-r--r-- 1 root root 5120M Sep 17 2023 datafile -rwxr-xr-x 1 admin root 3M Sep 17 2023 kihei admin@i-0e3aa73ecb85f9583:~$ ls -al --block-size=b ls: invalid --block-size argument 'b' admin@i-0e3aa73ecb85f9583:~$
kihei/i-0e3aa73ecb85f9583 02:03
by SadServersadmin@i-0215c6153f5619eae:~$ ls -a .ansible/tmp/ . .. admin@i-0215c6153f5619eae:~$ ls -a agent/ . .. check.sh sadagent sadagent.txt admin@i-0215c6153f5619eae:~$ ls -a agent/sadagent agent/sadagent admin@i-0215c6153f5619eae:~$ ls -a agent/sadagent sadagent sadagent.txt admin@i-0215c6153f5619eae:~$ ls -a agent/sadagent sadagent sadagent.txt admin@i-0215c6153f5619eae:~$ less agent/check.sh admin@i-0215c6153f5619eae:~$ less agent/sadagent.txt admin@i-0215c6153f5619eae:~$ less agent/sadagent "agent/sadagent" may be a binary file. See it anyway? admin@i-0215c6153f5619eae:~$ sudo echo '
paris/i-0215c6153f5619eae 05:50
by SadServers> GET / HTTP/1.1 > Host: localhost:5000 > User-Agent: curl/7.74.0 > Accept: */* > * Mark bundle as not supporting multiuse < HTTP/1.1 200 OK < Server: Werkzeug/2.3.7 Python/3.9.2 < Date: Sat, 25 Jan 2025 12:59:58 GMT < Content-Type: text/html; charset=utf-8 < Content-Length: 12 < Connection: close < * Closing connection 0 Unauthorizedadmin@i-07858c807135c8851:~$ curl -vvv localhost:5000
paris/i-07858c807135c8851 05:07
by SadServersadmin 771 697 0 16:53 pts/1 00:00:00 more admin@i-09f185fddd1e81888:~$ history 1 2023-09-20T15:57:57 > /home/admin/.bash_history 2 2023-09-20T15:58:02 exit 3 2025-03-07T16:52:03 sudo su - 4 2025-03-07T16:52:06 ls -l 5 2025-03-07T16:52:14 lsof -i :5000 6 2025-03-07T16:52:18 sudo lsof -i :5000 7 2025-03-07T16:52:22 ps -ef 8 2025-03-07T16:52:38 nstat -tlnp 9 2025-03-07T16:52:44 netstat -tlnp 10 2025-03-07T16:52:56 systemctl status 11 2025-03-07T16:53:15 ps -ef | more 12 2025-03-07T16:54:05 history admin@i-09f185fddd1e81888:~$ ls -l /home/admin/webserver.py