command-line-murders/i-03fefa660f6993216
by SadServersMore by SadServers
Jan 02 13:55:10 i-05560191eefbc7318 dhclient[471]: XMT: Solicit on ens5, intervaJan 02 13:55:16 i-05560191eefbc7318 python3[583]: 127.0.0.1 - - [02/Jan/2024 13:Jan 02 13:56:19 i-05560191eefbc7318 systemd[1]: Started Hammer Time. Jan 02 13:56:20 i-05560191eefbc7318 systemd[1]: mc.service: Succeeded. Jan 02 13:56:31 i-05560191eefbc7318 su[844]: pam_unix(su:auth): authentication fJan 02 13:56:33 i-05560191eefbc7318 su[844]: FAILED SU (to root) admin on pts/1 Jan 02 13:56:58 i-05560191eefbc7318 dhclient[471]: XMT: Solicit on ens5, intervaJan 02 13:57:07 i-05560191eefbc7318 python3[583]: 127.0.0.1 - - [02/Jan/2024 13:Jan 02 13:57:14 i-05560191eefbc7318 python3[583]: 127.0.0.1 - - [02/Jan/2024 13:Jan 02 13:57:17 i-05560191eefbc7318 systemd[1]: Started Hammer Time. Jan 02 13:57:18 i-05560191eefbc7318 systemd[1]: mc.service: Succeeded. Jan 02 13:58:02 i-05560191eefbc7318 systemd[1]: Started Hammer Time. Jan 02 13:58:03 i-05560191eefbc7318 systemd[1]: mc.service: Succeeded. ^[[6~^[[6~^[[6~^C admin@i-05560191eefbc7318:~$ cd
paris/i-05560191eefbc7318 04:19
by SadServers-r--r--r-- 1 root root 0 Nov 28 20:01 timers -rw-rw-rw- 1 root root 0 Nov 28 20:01 timerslack_ns -rw-r--r-- 1 root root 0 Nov 28 20:01 uid_map -r--r--r-- 1 root root 0 Nov 28 20:01 wchan admin@i-03c3097309a075b56:/proc/576$ cd map_files/ bash: cd: map_files/: Permission denied admin@i-03c3097309a075b56:/proc/576$ ls -l^C admin@i-03c3097309a075b56:/proc/576$ less smaps smaps: Permission denied admin@i-03c3097309a075b56:/proc/576$ cat smaps cat: smaps: Permission denied admin@i-03c3097309a075b56:/proc/576$ stra^C admin@i-03c3097309a075b56:/proc/576$ strace -p 576 strace: attach: ptrace(PTRACE_SEIZE, 576): Operation not permitted admin@i-03c3097309a075b56:/proc/576$
paris/i-03c3097309a075b56 01:47
by SadServersUnauthorizedadmin@i-01f465ecb0e6b6e62:~$ curl localhost:5000 Unauthorizedadmin@i-01f465ecb0e6b6e62:~$ ls agent webserver.py admin@i-01f465ecb0e6b6e62:~$ nano webserver.py admin@i-01f465ecb0e6b6e62:~$ sudo nano webserver.py We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: