Public recordings
Sort by
le="unconfined" name="man_filter" pid=355 comm="apparmor_parser" [ 4.838571] audit: type=1400 audit(1703061908.844:6): apparmor="STATUS" operale="unconfined" name="man_groff" pid=355 comm="apparmor_parser" [ 4.854310] audit: type=1400 audit(1703061908.884:7): apparmor="STATUS" operale="unconfined" name="lsb_release" pid=356 comm="apparmor_parser" [ 4.869891] audit: type=1400 audit(1703061908.892:8): apparmor="STATUS" operale="unconfined" name="tcpdump" pid=357 comm="apparmor_parser" [ 4.885181] audit: type=1400 audit(1703061908.908:9): apparmor="STATUS" operale="unconfined" name="/usr/sbin/chronyd" pid=358 comm="apparmor_parser" [ 56.344814] IPv6: ADDRCONF(NETDEV_CHANGE): ens5: link becomes ready [ 58.685545] device-mapper: uevent: version 1.0.3 [ 58.690960] device-mapper: ioctl: 4.43.0-ioctl (2020-10-01) initialised: dm-dadmin@i-0934faf01c3d7420c:~$ vim /home/admin/kihei root@i-0934faf01c3d7420c:/home/admin# tar czf datafile > /tmp/datafile.tar.gz
kihei/i-0934faf01c3d7420c 04:53
by SadServerstcp ESTAB 0 0 [::ffff:172.31. [::ffff:172.31.16.109]:49770 timer:(keepalive,3.216ms,0) admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$ lsof -i:5000 admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$ lsof -i COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME gotty 558 admin 6u IPv6 10895 0t0 TCP *:http-alt (LISTEN) gotty 558 admin 7u IPv6 12340 0t0 TCP ip-172-31-40-35.us-east-2.co>ip-172-31-16-109.us-east-2.compute.internal:49770 (ESTABLISHED) sadagent 559 admin 7u IPv6 1958 0t0 TCP *:6767 (LISTEN) admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$
paris/i-0bce630416db45b25 03:00
by SadServersroot 685 2 0 23:37 ? 00:00:00 [kworker/0:4-events] admin 687 563 0 23:37 pts/0 00:00:00 bash -l admin 691 687 0 23:37 pts/0 00:00:00 /usr/bin/python3 /usr/bin/asadmin 694 691 0 23:37 pts/0 00:00:00 /usr/bin/python3 /usr/bin/asadmin 695 691 0 23:37 pts/1 00:00:00 sh -c /bin/bash admin 696 695 0 23:37 pts/1 00:00:00 /bin/bash root 704 2 0 23:37 ? 00:00:00 [kworker/u4:4-events_unboundadmin 957 696 0 23:43 pts/1 00:00:00 ps -ef admin@i-0c6e74f29b5339b88:~$ ps -ef | grep web root 580 1 0 23:37 ? 00:00:00 /usr/bin/python3 /home/adminadmin 960 696 0 23:43 pts/1 00:00:00 grep web admin@i-0c6e74f29b5339b88:~$ cat /proc/580/mem cat: /proc/580/mem: Permission denied admin@i-0c6e74f29b5339b88:~$ ^Ct /proc/580/mem admin@i-0c6e74f29b5339b88:~$ cd /
paris/i-0c6e74f29b5339b88 06:10
by SadServers[pid 871] <... futex resumed>) = ? [pid 869] <... futex resumed>) = ? [pid 871] +++ exited with 2 +++ [pid 870] <... futex resumed>) = ? [pid 869] +++ exited with 2 +++ [pid 868] <... nanosleep resumed> <unfinished ...>) = ? [pid 870] +++ exited with 2 +++ [pid 868] +++ exited with 2 +++ +++ exited with 2 +++ admin@i-0b023b3f4c45754c6:~$ ^C admin@i-0b023b3f4c45754c6:~$ ls agent data datafile kihei admin@i-0b023b3f4c45754c6:~$ ll bash: ll: command not found admin@i-0b023b3f4c45754c6:~$
kihei/i-0b023b3f4c45754c6 03:07
by SadServers) = 37 write(2, " -verbose\n \tVerbose mode (pr"..., 48 -verbose Verbose mode (print extra info) ) = 48 exit_group(0) = ? +++ exited with 0 +++ admin@i-031497702ee010c76:~$ ./kihei -h Usage: ./kihei [options] -h Display help -help Display help -v Verbose mode (print extra info) -verbose Verbose mode (print extra info) admin@i-031497702ee010c76:~$ chmod 000 /home/admin/data/newdatafile
kihei/i-031497702ee010c76 04:42
by SadServerswrite(2, "main.main", 9main.main) = 9 write(2, "(", 1() = 1 write(2, ")\n", 2) ) = 2 write(2, "\t", 1 ) = 1 write(2, "./main.go", 9./main.go) = 9 write(2, ":", 1:) = 1 write(2, "64", 264) = 2 write(2, " +", 2 +) = 2 write(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-04be67f0dc8685ea8:~$
kihei/i-04be67f0dc8685ea8 00:34
by SadServersadmin@i-0c469078d13136d60:~$ sudo curl localhost:5000 We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: sudo: a password is required admin@i-0c469078d13136d60:~$ nc localhost5000 nc: missing port number admin@i-0c469078d13136d60:~$ nc localhost 5000 G
paris/i-0c469078d13136d60 01:28
by SadServers#2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: sudo: a password is required admin@i-0b509c48b21df0a47:~$ sudo su - We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin:
paris/i-0b509c48b21df0a47 00:44
by SadServers[ -q|--quiet ] [ -v|--verbose ] [ -y|--yes ] [ -t|--test ] [ --commandprofile String ] [ --config String ] [ --driverloaded y|n ] [ --nolocking ] [ --lockopt String ] [ --longhelp ] [ --profile String ] [ --version ] Use --longhelp to show all options and advanced commands. admin@i-075cf9d9f372e0f42:~$
kihei/i-075cf9d9f372e0f42 07:02
by SadServers2 2023-09-20T15:58:02 exit 3 2023-12-18T23:23:28 ls 4 2023-12-18T23:23:32 vim webserver.py 5 2023-12-18T23:23:35 ls -l 6 2023-12-18T23:23:37 sudo -l 7 2023-12-18T23:23:44 sudo view webserver.py 8 2023-12-18T23:24:00 ls 9 2023-12-18T23:24:02 ls agent 10 2023-12-18T23:24:08 view agent/check.sh 11 2023-12-18T23:24:22 netstat -nl4 12 2023-12-18T23:24:29 curl 127.0.0.1:5000 13 2023-12-18T23:24:40 curl -v 127.0.0.1:5000 14 2023-12-18T23:25:09 history admin@i-091ee8f6864cabf76:~$ view .bash_history admin@i-091ee8f6864cabf76:~$
paris/i-091ee8f6864cabf76 02:11
by SadServerslsof 835 admin mem REG 259,1 61712-linux-gnu/libpcre2-8.so.0.10.1 lsof 835 admin mem REG 259,1 190153-linux-gnu/libc-2.31.so lsof 835 admin mem REG 259,1 16612-linux-gnu/libselinux.so.1 lsof 835 admin mem REG 259,1 17792-linux-gnu/ld-2.31.so lsof 835 admin 4r FIFO 0,11 0tlsof 835 admin 7w FIFO 0,11 0tadmin@i-00d15eebefe1eaf63:~$ lsof -nP -iTCP -sTCP:LISTEN COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME gotty 563 admin 6u IPv6 1900 0t0 TCP *:8080 (LISTEN) sadagent 564 admin 7u IPv6 1875 0t0 TCP *:6767 (LISTEN) admin@i-00d15eebefe1eaf63:~$ lsof -nP -i