Public recordings
Sort by
admin@i-04f9b68ba2ba71eb9:~$ pwd /home/admin admin@i-04f9b68ba2ba71eb9:~$ admin@i-04f9b68ba2ba71eb9:~$ ls agent data datafile kihei admin@i-04f9b68ba2ba71eb9:~$ cd agent/ admin@i-04f9b68ba2ba71eb9:~/agent$ ls check.sh sadagent sadagent.txt admin@i-04f9b68ba2ba71eb9:~/agent$ cat c
kihei/i-04f9b68ba2ba71eb9 00:18
by SadServersnvme0n1 ├─nvme0n1p1 ext4 1.0 811e12d8-f542-4650-9330-8d96633bd90c 1.2G ├─nvme0n1p14 └─nvme0n1p15 vfat FAT16 8690-F844 117.8M nvme1n1 nvme2n1 admin@i-03e8621f09ba2ba4e:~$ lvs WARNING: Running as a non-root user. Functionality may be unavailable. /run/lock/lvm/P_global:aux: open failed: Permission denied admin@i-03e8621f09ba2ba4e:~$ sudo lvs admin@i-03e8621f09ba2ba4e:~$ ls -la data total 8 drwxr-xr-x 2 admin root 4096 Oct 26 07:02 . drwxr-xr-x 7 admin admin 4096 Oct 26 07:02 .. admin@i-03e8621f09ba2ba4e:~$ sudo
kihei/i-03e8621f09ba2ba4e 03:40
by SadServersInitialization time-set.target loade Time Set time-sync.target loade Time Synchronized timers.target loade > apt-daily-upgrade.timer loadeapt upgrade and clean activities apt-daily.timer loadeapt download activities e2scrub_all.timer loadeic ext4 Online Metadata Check for > fstrim.timer loadeadmin@i-0d2e19b6ed1ee3727:~$ ps -aux
paris/i-0d2e19b6ed1ee3727 02:14
by SadServersadmin@i-0453bb76f89d6d1e6:~$ curl localhost:5000 Unauthorizedadmin@i-0453bb76f89d6d1e6:~$ admin@i-0453bb76f89d6d1e6:~$ sudo curl localhost:5000 We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: sudo: a password is required admin@i-0453bb76f89d6d1e6:~$ ^C admin@i-0453bb76f89d6d1e6:~$ nestat | grep
paris/i-0453bb76f89d6d1e6 01:18
by SadServersadmin@i-0ae89bce1453c6828:~$ ls -l total 5245048 drwxr-xr-x 2 admin root 4096 Sep 17 2023 agent drwxr-xr-x 2 admin root 4096 Oct 25 16:29 data -rw-r--r-- 1 root root 5368709120 Sep 17 2023 datafile -rwxr-xr-x 1 admin root 2207109 Sep 17 2023 kihei admin@i-0ae89bce1453c6828:~$ ls data appdiskmnt admin@i-0ae89bce1453c6828:~$ rm data/appdiskmnt admin@i-0ae89bce1453c6828:~$ rmdir data/ admin@i-0ae89bce1453c6828:~$ sudo ln -s /mnt/appdiskmnt/ /home/admin/data/ ln: failed to create symbolic link '/home/admin/data/': No such file or directoradmin@i-0ae89bce1453c6828:~$ ls agent datafile kihei admin@i-0ae89bce1453c6828:~$ sudo ln -s /mnt/appdiskmnt/ /home/admin/data/
kihei/i-0ae89bce1453c6828 10:59
by SadServers988 pts/1 R<+ 0:00 ps ax admin@i-0748faed17a21b9f5:~/agent$ ls check.sh sadagent sadagent.txt admin@i-0748faed17a21b9f5:~/agent$ cd .. admin@i-0748faed17a21b9f5:~$ ls agent webserver.py admin@i-0748faed17a21b9f5:~$ ls -l total 8 drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-0748faed17a21b9f5:~$ cd /var/lib/ admin@i-0748faed17a21b9f5:/var/lib$ ls apt cloud dhcp grub man-db pam private sgml-base systemd uchrony dbus dpkg logrotate misc polkit-1 python sudo ucf vadmin@i-0748faed17a21b9f5:/var/lib$ cd
paris/i-0748faed17a21b9f5 04:08
by SadServerswrite(2, "64", 264) = 2 write(2, " +", 2 +) = 2 write(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-0815e829d95ab34ca:~$ ./kihei -v Creating file /home/admin/data/newdatafile with size 1.5GB... panic: exit status 1 goroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0815e829d95ab34ca:~$
kihei/i-0815e829d95ab34ca 01:57
by SadServersnvme0n1p14 259:3 0 3M 0 part nvme0n1p15 259:4 0 124M 0 part /boot/efi nvme2n1 259:5 0 1G 0 disk admin@i-04f920394c7614a59:~$ lsblk NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT nvme1n1 259:0 0 1G 0 disk nvme0n1 259:1 0 8G 0 disk ├─nvme0n1p1 259:2 0 7.9G 0 part / ├─nvme0n1p14 259:3 0 3M 0 part └─nvme0n1p15 259:4 0 124M 0 part /boot/efi nvme2n1 259:5 0 1G 0 disk admin@i-04f920394c7614a59:~$ df / Filesystem 1K-blocks Used Available Use% Mounted on /dev/nvme0n1p1 8026128 6354520 1242352 84% / admin@i-04f920394c7614a59:~$ lsblk -
kihei/i-04f920394c7614a59 01:59
by SadServerslsof 791 admin mem REG 259,1 149524-linux-gnu/libpthread-2.31.so lsof 791 admin mem REG 259,1 18684-linux-gnu/libdl-2.31.so lsof 791 admin mem REG 259,1 617124-linux-gnu/libpcre2-8.so.0.10.1 lsof 791 admin mem REG 259,1 1901534-linux-gnu/libc-2.31.so lsof 791 admin mem REG 259,1 166124-linux-gnu/libselinux.so.1 lsof 791 admin mem REG 259,1 177924-linux-gnu/ld-2.31.so lsof 791 admin 4r FIFO 0,11 0tlsof 791 admin 7w FIFO 0,11 0tadmin@i-08470b485bf6eb405:~$ ss -tulnp
paris/i-08470b485bf6eb405 02:03
by SadServersadmin@i-0139974abc9a432af:~$ ls -lah total 5.1G drwxr-xr-x 7 admin admin 4.0K Oct 24 12:11 . drwxr-xr-x 3 root root 4.0K Sep 17 2023 .. drwx------ 3 admin admin 4.0K Sep 17 2023 .ansible -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3.5K Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4.0K Oct 24 12:11 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4.0K Sep 17 2023 .ssh drwxr-xr-x 2 admin root 4.0K Sep 17 2023 agent drwxr-xr-x 2 admin root 4.0K Oct 24 12:19 data -rw-r--r-- 1 admin admin 5.0G Sep 17 2023 datafile -rwxr-xr-x 1 admin root 2.2M Sep 17 2023 kihei admin@i-0139974abc9a432af:~$ ls -lah
kihei/i-0139974abc9a432af 04:15
by SadServers> GET / HTTP/1.1 > Host: localhost:5000 > User-Agent: curl/7.74.0 > Accept: */* > * Mark bundle as not supporting multiuse < HTTP/1.1 200 OK < Server: Werkzeug/2.3.7 Python/3.9.2 < Date: Wed, 23 Oct 2024 22:33:37 GMT < Content-Type: text/html; charset=utf-8 < Content-Length: 12 < Connection: close < * Closing connection 0 Unauthorizedadmin@i-02901696405e883e3:~$ systemctl l
paris/i-02901696405e883e3 01:25
by SadServerscat: /home/admin/webserver.py: Permission denied admin@i-041ba6e4c2ebedf78:~$ sudo su We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: sudo: a password is required admin@i-041ba6e4c2ebedf78:~$ admin@i-041ba6e4c2ebedf78:~$ admin@i-041ba6e4c2ebedf78:~$
paris/i-041ba6e4c2ebedf78 02:33
by SadServersadmin@i-0346e20b3ceb89391:~$ nmap -v -O localhost -P 5000 Warning: The -P option is deprecated. Please use -PE Warning: You are not root -- using TCP pingscan rather than ICMP TCP/IP fingerprinting (for OS scan) requires root privileges. QUITTING! admin@i-0346e20b3ceb89391:~$