alternatives.log cloud-init-output.log faillog private/ alternatives.log.1 cloud-init.log journal/ runit/ apt/ daemon.log kern.log syslog auth.log daemon.log.1 kern.log.1 syslog.1 auth.log.1 daemon.log.2.gz kern.log.2.gz syslog.2.gz auth.log.2.gz debug lastlog unattended-upgrades/ btmp debug.1 messages user.log btmp.1 debug.2.gz messages.1 user.log.1 cast/ dpkg.log messages.2.gz user.log.2.gz chrony/ dpkg.log.1 minio.log wtmp admin@i-09691d997134773d9:~$ tail -100f /var/log/messages Feb 22 16:10:56 i-09691d997134773d9 ec2: Feb 22 16:10:56 i-09691d997134773d9 ec2: ############################################################# Feb 22 16:10:56 i-09691d997134773d9 ec2: -----BEGIN SSH HOST KEY FINGERPRINTS----- Feb 22 16:10:56 i-09691d997134773d9 ec2: 1024 SHA256:mEubWC+MOvJZCYYFRlJhPUEFvIe48+1ecilq0rPSxWA root@i-09691d997134773d9 (DSA) Feb 22 16:10:56 i-09691d997134773d9 ec2: 256 SHA256:bcW5DEuBPFTexQGeFOJembAwOIjVAP0AxwS76MhBVAU root@i-09691d997134773d9 (ECDSA) Feb 22 16:10:56 i-09691d997134773d9 ec2: 256 SHA256:c5SI2fFWheFLRxuwfZC4s/9pnlE8wUFUcjv81A0Dw9c root@i-09691d997134773d9 (ED25519) Feb 22 16:10:56 i-09691d997134773d9 ec2: 3072 SHA256:8tmyW4udLybw/8oGIMasDpRCPka1fL4gKqd3EKV7PMg root@i-09691d997134773d9 (RSA) Feb 22 16:10:56 i-09691d997134773d9 ec2: -----END SSH HOST KEY FINGERPRINTS----- Feb 22 16:10:56 i-09691d997134773d9 ec2: ############################################################# ^C admin@i-09691d997134773d9:~$ tail -100f /var/log/user.log Feb 22 16:10:56 i-09691d997134773d9 ec2: Feb 22 16:10:56 i-09691d997134773d9 ec2: ############################################################# Feb 22 16:10:56 i-09691d997134773d9 ec2: -----BEGIN SSH HOST KEY FINGERPRINTS----- Feb 22 16:10:56 i-09691d997134773d9 ec2: 1024 SHA256:mEubWC+MOvJZCYYFRlJhPUEFvIe48+1ecilq0rPSxWA root@i-09691d997134773d9 (DSA) Feb 22 16:10:56 i-09691d997134773d9 ec2: 256 SHA256:bcW5DEuBPFTexQGeFOJembAwOIjVAP0AxwS76MhBVAU root@i-09691d997134773d9 (ECDSA) Feb 22 16:10:56 i-09691d997134773d9 ec2: 256 SHA256:c5SI2fFWheFLRxuwfZC4s/9pnlE8wUFUcjv81A0Dw9c root@i-09691d997134773d9 (ED25519) Feb 22 16:10:56 i-09691d997134773d9 ec2: 3072 SHA256:8tmyW4udLybw/8oGIMasDpRCPka1fL4gKqd3EKV7PMg root@i-09691d997134773d9 (RSA) Feb 22 16:10:56 i-09691d997134773d9 ec2: -----END SSH HOST KEY FINGERPRINTS----- Feb 22 16:10:56 i-09691d997134773d9 ec2: ############################################################# ^C admin@i-09691d997134773d9:~$ admin@i-09691d997134773d9:~$ ls -larth total 48K -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile -rw-r--r-- 1 admin admin 3.5K Aug 4 2021 .bashrc -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout drwxr-xr-x 3 root root 4.0K Sep 17 16:44 .. drwx------ 2 admin admin 4.0K Sep 17 16:44 .ssh drwx------ 3 admin admin 4.0K Sep 20 15:52 .ansible drwxr-xr-x 3 admin admin 4.0K Sep 20 15:56 .config -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py drwxr-xr-x 2 admin root 4.0K Sep 24 23:20 agent -rw------- 1 admin admin 684 Feb 22 16:13 .viminfo drwxr-xr-x 6 admin admin 4.0K Feb 22 16:13 . -rw------- 1 admin admin 666 Feb 22 16:14 .bash_history admin@i-09691d997134773d9:~$ sudo cat webserver.py
paris/i-09691d997134773d9
by SadServersMore by SadServers
admin@i-01938499a23dd6d8b:~$ curl http://localhost:5000 Unauthorizedadmin@i-01938499a23dd6d8b:~$ curl https://localhost:5000 curl: (35) error:1408F10B:SSL routines:ssl3_get_record:wrong version number admin@i-01938499a23dd6d8b:~$ strace -p 573 strace: attach: ptrace(PTRACE_SEIZE, 573): Operation not permitted admin@i-01938499a23dd6d8b:~$ sudo strace -p 573 We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin:
paris/i-01938499a23dd6d8b 05:03
by SadServers└─nvme0n1p15 259:5 0 124M 0 part /boot/efi nvme2n1 259:2 0 1G 0 disk admin@i-0ee381b106ee6f241:~$ sudo lvdisplay admin@i-0ee381b106ee6f241:~$ df -hT Filesystem Type Size Used Avail Use% Mounted on udev devtmpfs 217M 0 217M 0% /dev tmpfs tmpfs 46M 368K 46M 1% /run /dev/nvme0n1p1 ext4 7.7G 6.1G 1.2G 84% / tmpfs tmpfs 228M 12K 228M 1% /dev/shm tmpfs tmpfs 5.0M 0 5.0M 0% /run/lock /dev/nvme0n1p15 vfat 124M 5.9M 118M 5% /boot/efi admin@i-0ee381b106ee6f241:~$ sudo mkfs.ext4 /dev/nvme1n1 mke2fs 1.46.2 (28-Feb-2021) /dev/nvme1n1 contains a LVM2_member file system Proceed anyway? (y,N)