command-line-murders/i-00e5882501666dffe
by SadServersMore by SadServers
brk(NULL) = 0x56054d8f4000 brk(0x56054d915000) = 0x56054d915000 openat(AT_FDCWD, "/usr/lib/locale/locale-archive", O_RDONLY|O_CLOEXEC) = -1 ENOEopenat(AT_FDCWD, "/usr/share/locale/locale.alias", O_RDONLY|O_CLOEXEC) = 3 fstat(3, {st_mode=S_IFREG|0644, st_size=2996, ...}) = 0 read(3, "# Locale name alias data base.\n#"..., 4096) = 2996 read(3, "", 4096) = 0 close(3) = 0 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_IDENTIFICATION", O_RDONLY|O_CLOEXECfstat(3, {st_mode=S_IFREG|0644, st_size=252, ...}) = 0 mmap(NULL, 252, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7fbe8c59a000 close(3) = 0 openat(AT_FDCWD, "/usr/lib/x86_64-linux-gnu/gconv/gconv-modules.cache", O_RDONLYfstat(3, {st_mode=S_IFREG|0644, st_size=27002, ...}) = 0 :
kihei/i-0a59bab7c4f4d5558 03:21
by SadServerslsof 1008 1000 mem REG 259,1 149520inux-gnu/libpthread-2.31.so lsof 1008 1000 mem REG 259,1 18688inux-gnu/libdl-2.31.so lsof 1008 1000 mem REG 259,1 617128inux-gnu/libpcre2-8.so.0.10.1 lsof 1008 1000 mem REG 259,1 1901536inux-gnu/libc-2.31.so lsof 1008 1000 mem REG 259,1 166120inux-gnu/libselinux.so.1 lsof 1008 1000 mem REG 259,1 177928inux-gnu/ld-2.31.so lsof 1008 1000 4r FIFO 0,11 0t0lsof 1008 1000 7w FIFO 0,11 0t0admin@i-096a29f104e7847fe:~$ lsof -i
paris/i-096a29f104e7847fe 07:14
by SadServers[-m minttl] [-O length] [-P proxy_username] [-p source_port] [-q seconds] [-s sourceaddr] [-T keyword] [-V rtable] [-W recvlimit] [-w timeout] [-X proxy_protocol] [-x proxy_address[:port]] [destination] [port] admin@i-0b0edb32d26a5502b:~$ nc localhost 5000 admin@i-0b0edb32d26a5502b:~$ nc localhost 5000 GET / nc: port number invalid: GET admin@i-0b0edb32d26a5502b:~$ nc localhost 5000 admin@i-0b0edb32d26a5502b:~$ GET / bash: GET: command not found admin@i-0b0edb32d26a5502b:~$ GET / curl --user-agent "whatever"
paris/i-0b0edb32d26a5502b 02:31
by SadServersudp UNCONN 0 0 127.0.0.1:323 0.0.udp UNCONN 0 0 0.0.0.0:68 0.0.udp UNCONN 0 0 [fe80::8a8:d3ff:fe19:c113]%ens5:546 [udp UNCONN 0 0 [::1]:323 [tcp LISTEN 0 511 0.0.0.0:80 0.0.tcp LISTEN 0 128 0.0.0.0:22 0.0.tcp LISTEN 0 4096 *:6767 tcp LISTEN 0 511 [::]:80 [tcp LISTEN 0 4096 *:8080 tcp LISTEN 0 128 [::]:22 [admin@i-0fe60fd5038ba7352:/etc$ ls -l /proc/511/cmd ls: cannot access '/proc/511/cmd': No such file or directory admin@i-0fe60fd5038ba7352:/etc$ curl http://localhost:80 curl: (7) Failed to connect to localhost port 80: Connection refused admin@i-0fe60fd5038ba7352:/etc$ echonc -u