root 133 2 0 03:43 ? 00:00:00 [jbd2/nvme0n1p1-] root 134 2 0 03:43 ? 00:00:00 [ext4-rsv-conver] root 195 1 0 03:43 ? 00:00:00 /lib/systemd/systemd-journald root 212 1 0 03:43 ? 00:00:00 /lib/systemd/systemd-udevd root 235 2 0 03:43 ? 00:00:00 [cryptd] root 311 2 0 03:43 ? 00:00:00 [kworker/0:3-events] root 395 1 0 03:44 ? 00:00:00 /sbin/dhclient -4 -v -i -pf /run/dhclient.ens5.pid -lf /var/lib/dhcp/dhclient.ens5.leases -I -df /var/lib/dhcp/dhclient6.ens5.leases ens5 root 468 1 0 03:44 ? 00:00:00 /sbin/dhclient -6 -v -pf /run/dhclient6.ens5.pid -lf /var/lib/dhcp/dhclient6.ens5.leases -I -df /var/lib/dhcp/dhclient.ens5.leases -nw ens5 admin 563 1 0 03:44 ? 00:00:00 /usr/local/gotty --permit-write --reconnect --max-connection 5 bash -l admin 564 1 0 03:44 ? 00:00:00 /home/admin/agent/sadagent root 567 1 0 03:44 ? 00:00:00 /usr/sbin/cron -f message+ 568 1 0 03:44 ? 00:00:00 /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only root 570 1 0 03:44 ? 00:00:00 /usr/bin/python3 /home/admin/webserver.py root 573 1 0 03:44 ? 00:00:00 /usr/sbin/rsyslogd -n -iNONE root 583 1 0 03:44 ? 00:00:00 /lib/systemd/systemd-logind root 588 1 0 03:44 tty1 00:00:00 /sbin/agetty -o -p -- \u --noclear tty1 linux root 589 1 0 03:44 ttyS0 00:00:00 /sbin/agetty -o -p -- \u --keep-baud 115200,57600,38400,9600 ttyS0 vt220 root 591 1 0 03:44 ? 00:00:00 sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 startups _chrony 593 1 0 03:44 ? 00:00:00 /usr/sbin/chronyd -F 1 root 600 1 0 03:44 ? 00:00:00 /usr/bin/python3 /usr/share/unattended-upgrades/unattended-upgrade-shutdown --wait-for-signal _chrony 601 593 0 03:44 ? 00:00:00 /usr/sbin/chronyd -F 1 root 684 2 0 03:45 ? 00:00:00 [kworker/u4:4+events_unbound] admin 714 563 0 03:45 pts/0 00:00:00 bash -l admin 718 714 2 03:45 pts/0 00:00:00 /usr/bin/python3 /usr/bin/asciinema rec -t paris/i-0e0901153058fcbfd -q -i 2 /var/log/cast/i-0e0901153058fcbfd admin 721 718 0 03:45 pts/0 00:00:00 /usr/bin/python3 /usr/bin/asciinema rec -t paris/i-0e0901153058fcbfd -q -i 2 /var/log/cast/i-0e0901153058fcbfd admin 722 718 0 03:45 pts/1 00:00:00 sh -c /bin/bash admin 723 722 0 03:45 pts/1 00:00:00 /bin/bash admin 727 723 0 03:45 pts/1 00:00:00 ps -eafww admin@i-0e0901153058fcbfd:~$ curl -v http://localhost:500
paris/i-0e0901153058fcbfd
by SadServersMore by SadServers
-rw------- 1 admin admin 269 Jan 2 11:38 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 2023 .config drwxr-xr-x 3 admin admin 4096 Jan 2 11:37 .local -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 2023 .ssh -rw-r--r-- 1 admin admin 1024 Jan 2 11:37 .webserver.py.swp drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-0f995f369ab3b4d0d:~$ ls .config/ asciinema admin@i-0f995f369ab3b4d0d:~$ less .webserver.py.swp ".webserver.py.swp" may be a binary file. See it anyway? admin@i-0f995f369ab3b4d0d:~$ cat .bashr
paris/i-0f995f369ab3b4d0d 01:44
by SadServersdrwxr-xr-x 2 admin root 4.0K Sep 17 17:28 agent drwxr-xr-x 2 admin root 4.0K Nov 2 17:37 data -rw-r--r-- 1 root root 5.0G Sep 17 17:28 datafile -rwxr-xr-x 1 admin root 2.2M Sep 17 17:28 kihei -rw-r--r-- 1 admin admin 20K Nov 2 17:37 out admin@i-06688559e0cbdf975:~$ df -h Filesystem Size Used Avail Use% Mounted on udev 217M 0 217M 0% /dev tmpfs 46M 368K 46M 1% /run /dev/nvme0n1p1 7.7G 6.1G 1.2G 84% / tmpfs 228M 12K 228M 1% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock /dev/nvme0n1p15 124M 5.9M 118M 5% /boot/efi admin@i-06688559e0cbdf975:~$ vim out (gdb) ck.ain.go: No such file or directory.' to list them.debug_gdb_scriptsl> Go
kihei/i-06688559e0cbdf975 08:13
by SadServers(Not all processes could be identified, non-owned process info will not be shown, you would have to be root to see it all.) Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State tcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN tcp6 0 0 :::6767 :::* LISTEN tcp6 0 0 :::8080 :::* LISTEN tcp6 0 0 :::22 :::* LISTEN udp 0 0 127.0.0.1:323 0.0.0.0:* udp 0 0 0.0.0.0:68 0.0.0.0:* udp6 0 0 fe80::861:81ff:feef:546 :::* udp6 0 0 ::1:323 :::* admin@i-08509f86769b7ad0f:~$ admin@i-08509f86769b7ad0f:~$ n
paris/i-08509f86769b7ad0f 01:22
by SadServersadmin 740 0.0 0.1 2480 512 pts/1 S<s 03:27 0:00 sh -c /bin/baadmin 741 0.0 0.9 6820 4524 pts/1 S< 03:27 0:00 /bin/bash root 744 0.0 0.9 9336 4588 pts/1 S< 03:27 0:00 sudo su root 745 0.0 0.9 8672 4480 pts/1 S< 03:27 0:00 su root 747 0.1 1.6 15048 7636 ? Ss 03:27 0:00 /lib/systemd/root 748 0.0 0.5 101096 2640 ? S 03:27 0:00 (sd-pam) root 753 0.0 0.7 6052 3720 pts/1 S< 03:27 0:00 bash root 760 0.0 0.9 8672 4476 pts/1 S< 03:27 0:00 su admin admin 761 0.0 0.9 6824 4524 pts/1 S< 03:27 0:00 bash admin 770 0.0 0.6 8648 3164 pts/1 R<+ 03:28 0:00 ps aux admin@i-0f837dbf94cba2c30:~$ ls agent data datafile kihei admin@i-0f837dbf94cba2c30:~$ type kihei bash: type: kihei: not found admin@i-0f837dbf94cba2c30:~$ f