command-line-murders/i-08c814275a620e262
by SadServersMore by SadServers
/home/admin/.ansible/tmp /home/admin/stuff /home/admin/.config /home/admin/.config/asciinema /home/admin/.config/asciinema/install-id /home/admin/.profile /home/admin/.ssh /home/admin/.ssh/authorized_keys /home/admin/.bash_logout /home/admin/.bashrc /home/admin/.bash_history /dev/pts/1 /dev/pts/0 /var/log/cast /var/log/cast/i-088c078b20497e4c0
paris/i-088c078b20497e4c0 04:19
by SadServersadmin@i-08bead324c6bc394c:~$ admin@i-08bead324c6bc394c:~$ admin@i-08bead324c6bc394c:~$ netstat -tnlp (Not all processes could be identified, non-owned process info will not be shown, you would have to be root to see it all.) Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State tcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN tcp6 0 0 :::6767 :::* LISTEN tcp6 0 0 :::8080 :::* LISTEN tcp6 0 0 :::22 :::* LISTEN admin@i-08bead324c6bc394c:~$ admin@i-08bead324c6bc394c:~$ admin@i-08bead324c6bc394c:~$
paris/i-08bead324c6bc394c 01:57
by SadServersfile"] /var/log/cast/i-008b0220d06b61fa7:[297.457658, "o", "\b\b\b\b\b\b\b\b\b\b\b-name/var/log/cast/i-008b0220d06b61fa7:[301.266025, "o", "\b\b\b\b\b\b\b\b\b\b\b\b\b\/var/log -name newdatafile"] /var/log/cast/i-008b0220d06b61fa7:[339.22969, "o", "\b\b\b\b\b\b\b\b\b\b\b\b\b\btafile /var/log"] /var/log/cast/i-008b0220d06b61fa7:[339.527642, "o", "\b\b\b\b\b\b\b\b\b\b\b\b\b\file"] /var/log/cast/i-008b0220d06b61fa7:[340.82254, "o", "\b\b\b\b\b\b\b\b\b\b\b-name /var/log/cast/i-008b0220d06b61fa7:[347.397351, "o", "\b\b\b\b\b\b\b\b\b\b\b\b\b\atafile /var/log"] grep: /var/log/btmp: Permission denied grep: /var/log/private: Permission denied grep: /var/log/chrony: Permission denied admin@i-008b0220d06b61fa7:~$ /home/admin/kihei