root 78 2 0 23:36 ? 00:00:00 [kworker/u5:0] root 112 2 0 23:36 ? 00:00:00 [ena] root 133 2 0 23:36 ? 00:00:00 [jbd2/nvme0n1p1-] root 134 2 0 23:36 ? 00:00:00 [ext4-rsv-conver] root 195 2 0 23:36 ? 00:00:00 [kworker/1:2-mm_percpu_wq] root 196 1 0 23:36 ? 00:00:00 /lib/systemd/systemd-journald root 213 1 0 23:36 ? 00:00:00 /lib/systemd/systemd-udevd root 233 2 0 23:36 ? 00:00:00 [cryptd] root 397 1 0 23:37 ? 00:00:00 /sbin/dhclient -4 -v -i -pf /run/dhclient.ens5.pid -lroot 468 1 0 23:37 ? 00:00:00 /sbin/dhclient -6 -v -pf /run/dhclient6.ens5.pid -lf admin 563 1 0 23:37 ? 00:00:00 /usr/local/gotty --permit-write --reconnect --max-conadmin 564 1 0 23:37 ? 00:00:00 /home/admin/agent/sadagent root 577 1 0 23:37 ? 00:00:00 /usr/sbin/cron -f message+ 578 1 0 23:37 ? 00:00:00 /usr/bin/dbus-daemon --system --address=systemd: --noroot 580 1 0 23:37 ? 00:00:00 /usr/bin/python3 /home/admin/webserver.py root 581 1 0 23:37 ? 00:00:00 /usr/sbin/rsyslogd -n -iNONE root 585 1 0 23:37 ? 00:00:00 /lib/systemd/systemd-logind _chrony 586 1 0 23:37 ? 00:00:00 /usr/sbin/chronyd -F 1 _chrony 591 586 0 23:37 ? 00:00:00 /usr/sbin/chronyd -F 1 root 592 1 0 23:37 tty1 00:00:00 /sbin/agetty -o -p -- \u --noclear tty1 linux root 594 1 0 23:37 ttyS0 00:00:00 /sbin/agetty -o -p -- \u --keep-baud 115200,57600,384root 597 1 0 23:37 ? 00:00:00 sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 starturoot 616 1 0 23:37 ? 00:00:00 /usr/bin/python3 /usr/share/unattended-upgrades/unattroot 685 2 0 23:37 ? 00:00:00 [kworker/0:4-events] admin 687 563 0 23:37 pts/0 00:00:00 bash -l admin 691 687 0 23:37 pts/0 00:00:00 /usr/bin/python3 /usr/bin/asciinema rec -t paris/i-0cadmin 694 691 0 23:37 pts/0 00:00:00 /usr/bin/python3 /usr/bin/asciinema rec -t paris/i-0cadmin 695 691 0 23:37 pts/1 00:00:00 sh -c /bin/bash admin 696 695 0 23:37 pts/1 00:00:00 /bin/bash root 704 2 0 23:37 ? 00:00:00 [kworker/u4:4-events_unbound] admin 957 696 0 23:43 pts/1 00:00:00 ps -ef admin@i-0c6e74f29b5339b88:~$ ps -ef | grep web root 580 1 0 23:37 ? 00:00:00 /usr/bin/python3 /home/admin/webserver.py admin 960 696 0 23:43 pts/1 00:00:00 grep web admin@i-0c6e74f29b5339b88:~$ cat /proc/580/mem cat: /proc/580/mem: Permission denied admin@i-0c6e74f29b5339b88:~$ ^Ct /proc/580/mem admin@i-0c6e74f29b5339b88:~$ cd /
paris/i-0c6e74f29b5339b88
by SadServersMore by SadServers
alternatives.log auth.log cast cloud-init-output.log daemon.log dpkg.log log runit unattended-upgrades wtmp apt btmp chrony cloud-init.log debug faillog e syslog user.log admin@i-0f97ad3dff720d3cf:/var/log$ cd /home/admin admin@i-0f97ad3dff720d3cf:~$ ls agent data datafile kihei admin@i-0f97ad3dff720d3cf:~$ tail datafile ^C admin@i-0f97ad3dff720d3cf:~$ cd data admin@i-0f97ad3dff720d3cf:~/data$ ls admin@i-0f97ad3dff720d3cf:~/data$ cd .. admin@i-0f97ad3dff720d3cf:~$ tail minio.log tail: cannot open 'minio.log' for reading: No such file or directory admin@i-0f97ad3dff720d3cf:~$ cd /var/log
kihei/i-0f97ad3dff720d3cf 06:39
by SadServersgoroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0f6d76d4e64ebbaa3:~$ less /home/admin/kihei "/home/admin/kihei" may be a binary file. See it anyway? admin@i-0f6d76d4e64ebbaa3:~$ admin@i-0f6d76d4e64ebbaa3:~$ df -h Filesystem Size Used Avail Use% Mounted on udev 217M 0 217M 0% /dev tmpfs 46M 368K 46M 1% /run /dev/nvme0n1p1 7.7G 6.1G 1.2G 84% / tmpfs 228M 12K 228M 1% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock /dev/nvme0n1p15 124M 5.9M 118M 5% /boot/efi admin@i-0f6d76d4e64ebbaa3:~$
kihei/i-0f6d76d4e64ebbaa3 00:29
by SadServers[sudo] password for admin: sudo: 1 incorrect password attempt admin@i-04a84196af5c95871:~$ ^C admin@i-04a84196af5c95871:~$ ^C admin@i-04a84196af5c95871:~$ ls agent index.html mysolution webserver.py admin@i-04a84196af5c95871:~$ su root Password: su: Authentication failure admin@i-04a84196af5c95871:~$ su root Password: su: Authentication failure admin@i-04a84196af5c95871:~$ ls agent index.html mysolution webserver.py admin@i-04a84196af5c95871:~$ cat /var/ww
paris/i-04a84196af5c95871 07:17
by SadServerscast/ dpkg.log messages.2.gz user.log.2.chrony/ dpkg.log.1 minio.log wtmp admin@i-069e102734ffdd250:~$ less /var/log/messages admin@i-069e102734ffdd250:~$ cd /var/log/ admin@i-069e102734ffdd250:/var/log$ ls alternatives.log cast debug.1 kern.log.2.gz syslog alternatives.log.1 chrony debug.2.gz lastlog syslog.1 apt cloud-init-output.log dpkg.log messages syslog.2.gauth.log cloud-init.log dpkg.log.1 messages.1 unattendedauth.log.1 daemon.log faillog messages.2.gz user.log auth.log.2.gz daemon.log.1 journal minio.log user.log.1btmp daemon.log.2.gz kern.log private user.log.2btmp.1 debug kern.log.1 runit wtmp admin@i-069e102734ffdd250:/var/log$ less auth.log admin@i-069e102734ffdd250:/var/log$ less