SadServers Joined on September 10, 2023
2111 public recordings by SadServers
We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: Sorry, try again. [sudo] password for admin: Sorry, try again. [sudo] password for admin: sudo: 3 incorrect password attempts admin@i-040ec55e8e002101c:~$ find / -name webserver
paris/i-040ec55e8e002101c 02:48
by SadServersWARNING: Running as a non-root user. Functionality may be unavailable. /run/lock/lvm/P_global:aux: open failed: Permission denied admin@i-0a1d4ad6b6fe16108:~$ ыгвщ ыг bash: ыгвщ: command not found admin@i-0a1d4ad6b6fe16108:~$ sudo su root@i-0a1d4ad6b6fe16108:/home/admin# pvcreate /dev/nvme1n1 /dev/nvme2n1 Physical volume "/dev/nvme1n1" successfully created. Physical volume "/dev/nvme2n1" successfully created. root@i-0a1d4ad6b6fe16108:/home/admin# lvcreate -n lv -L1600 vg Volume group "vg" not found Cannot process volume group vg root@i-0a1d4ad6b6fe16108:/home/admin# vgcreate vg ^C root@i-0a1d4ad6b6fe16108:/home/admin# vfcreate lvcreate -n lv -L1600 vg bash: vfcreate: command not found root@i-0a1d4ad6b6fe16108:/home/admin# vfcreate lvcreate -n lv -L1600 vg
kihei/i-0a1d4ad6b6fe16108 01:54
by SadServerstmpfs 228M 12K 228M 1% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock /dev/nvme0n1p15 124M 5.9M 118M 5% /boot/efi admin@i-032d3ffe9fedd91fa:~$ sudo df -h Filesystem Size Used Avail Use% Mounted on udev 217M 0 217M 0% /dev tmpfs 46M 368K 46M 1% /run /dev/nvme0n1p1 7.7G 6.1G 1.2G 84% / tmpfs 228M 12K 228M 1% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock /dev/nvme0n1p15 124M 5.9M 118M 5% /boot/efi admin@i-032d3ffe9fedd91fa:~$ cd /usr admin@i-032d3ffe9fedd91fa:/usr$ ls bin games include lib lib32 lib64 libexec libx32 local sbin share srcadmin@i-032d3ffe9fedd91fa:/usr$ c
kihei/i-032d3ffe9fedd91fa 01:31
by SadServers64 bytes from 127.0.0.1: icmp_seq=1 ttl=64 time=0.020 ms 64 bytes from 127.0.0.1: icmp_seq=2 ttl=64 time=0.033 ms 64 bytes from 127.0.0.1: icmp_seq=3 ttl=64 time=0.033 ms ^C --- 127.0.0.1 ping statistics --- 3 packets transmitted, 3 received, 0% packet loss, time 2029ms rtt min/avg/max/mdev = 0.020/0.028/0.033/0.006 ms admin@i-07e8450481f52abd6:~$ ssh 127.0.0.1 The authenticity of host '127.0.0.1 (127.0.0.1)' can't be established. ECDSA key fingerprint is SHA256:MaQ1ByNhlAiN8nHi+ywSTGpSLwVjOTmxS8w3ktrOQ9A. Are you sure you want to continue connecting (yes/no/[fingerprint])? y Please type 'yes', 'no' or the fingerprint: yes Warning: Permanently added '127.0.0.1' (ECDSA) to the list of known hosts. [email protected]: Permission denied (publickey). admin@i-07e8450481f52abd6:~$ ssh --
paris/i-07e8450481f52abd6 02:11
by SadServersadmin@i-0ff8052777bfebd18:~$ du -sh /home/admin/* 11M /home/admin/agent 4.0K /home/admin/data 5.1G /home/admin/datafile 2.2M /home/admin/kihei admin@i-0ff8052777bfebd18:~$ cd /home/admin/ admin@i-0ff8052777bfebd18:~$ ls -ll total 5245048 drwxr-xr-x 2 admin root 4096 Sep 17 2023 agent drwxr-xr-x 2 admin root 4096 Feb 13 13:20 data -rw-r--r-- 1 root root 5368709120 Sep 17 2023 datafile -rwxr-xr-x 1 admin root 2207109 Sep 17 2023 kihei admin@i-0ff8052777bfebd18:~$ mv /home/admin/datafile /opt/ mv: cannot move '/home/admin/datafile' to '/opt/datafile': Permission denied admin@i-0ff8052777bfebd18:~$ mv /home/admin
kihei/i-0ff8052777bfebd18 03:35
by SadServersThe partition table has been altered. Calling ioctl() to re-read partition table. Syncing disks. admin@i-0d87227a67f8b769e:~$ lsblk -f NAME FSTYPE FSVER LABEL UUID FSAVAIL FSUnvme0n1 ├─nvme0n1p1 ext4 1.0 811e12d8-f542-4650-9330-8d96633bd90c 1.2G ├─nvme0n1p14 └─nvme0n1p15 vfat FAT16 8690-F844 117.8M nvme2n1 └─nvme2n1p1 nvme1n1 └─nvme1n1p1 admin@i-0d87227a67f8b769e:~$ sudo vgcreate VG01
kihei/i-0d87227a67f8b769e 02:45
by SadServers-rw-r--r-- 1 root root 0 Feb 10 16:15 setgroups -r--r--r-- 1 root root 0 Feb 10 16:15 smaps -r--r--r-- 1 root root 0 Feb 10 16:15 smaps_rollup -r-------- 1 root root 0 Feb 10 16:15 stack -r--r--r-- 1 root root 0 Feb 10 16:10 stat -r--r--r-- 1 root root 0 Feb 10 16:15 statm -r--r--r-- 1 root root 0 Feb 10 16:10 status -r-------- 1 root root 0 Feb 10 16:15 syscall dr-xr-xr-x 3 root root 0 Feb 10 16:13 task -rw-r--r-- 1 root root 0 Feb 10 16:15 timens_offsets -r--r--r-- 1 root root 0 Feb 10 16:15 timers -rw-rw-rw- 1 root root 0 Feb 10 16:15 timerslack_ns -rw-r--r-- 1 root root 0 Feb 10 16:15 uid_map -r--r--r-- 1 root root 0 Feb 10 16:15 wchan admin@i-09ee8de58a0c22547:/proc/579$
paris/i-09ee8de58a0c22547 06:11
by SadServersile="unconfined" name="/usr/bin/man" pid=336 comm="apparmor_parser" [ 4.839178] audit: type=1400 audit(1739149489.855:5): apparmor="STATUS" operaile="unconfined" name="man_filter" pid=336 comm="apparmor_parser" [ 4.853673] audit: type=1400 audit(1739149489.855:6): apparmor="STATUS" operaile="unconfined" name="man_groff" pid=336 comm="apparmor_parser" [ 4.870219] audit: type=1400 audit(1739149489.891:7): apparmor="STATUS" operaile="unconfined" name="tcpdump" pid=338 comm="apparmor_parser" [ 4.884118] audit: type=1400 audit(1739149489.907:8): apparmor="STATUS" operaile="unconfined" name="/usr/sbin/chronyd" pid=339 comm="apparmor_parser" [ 4.884121] audit: type=1400 audit(1739149489.927:9): apparmor="STATUS" operaile="unconfined" name="lsb_release" pid=337 comm="apparmor_parser" [ 56.427427] IPv6: ADDRCONF(NETDEV_CHANGE): ens5: link becomes ready [ 58.862552] device-mapper: uevent: version 1.0.3 [ 58.867273] device-mapper: ioctl: 4.43.0-ioctl (2020-10-01) initialised: dm-dadmin@i-0db84b7794affbe97:~$
kihei/i-0db84b7794affbe97 02:31
by SadServers0ef35856b482e3494 (DSA) Feb 10 00:54:59 i-0ef35856b482e3494 ec2: 256 SHA256:P94uHIGmD/z2viiScrIibozGKOmOef35856b482e3494 (ECDSA) Feb 10 00:54:59 i-0ef35856b482e3494 ec2: 256 SHA256:REyM2XPzJ0VEVV14EXpOZazaTWasef35856b482e3494 (ED25519) Feb 10 00:54:59 i-0ef35856b482e3494 ec2: 3072 SHA256:vMSIjLcN3qaIfiUsZDlz3u1dhOS0ef35856b482e3494 (RSA) Feb 10 00:54:59 i-0ef35856b482e3494 ec2: -----END SSH HOST KEY FINGERPRINTS-----Feb 10 00:54:59 i-0ef35856b482e3494 ec2: #######################################admin@i-0ef35856b482e3494:/var/log$ su - Password: admin@i-0ef35856b482e3494:/var/log$ su - Password: ^C admin@i-0ef35856b482e3494:/var/log$ cd /proc/
paris/i-0ef35856b482e3494 02:44
by SadServerschrony.service loade cloud-config.service loade cloud-final.service loade cloud-init-local.service loade cloud-init.service loade cron.service loade dbus.service loade flaskapp.service loade [email protected] loade gotty.service loade [email protected] loade ifupdown-pre.service loade kmod-static-nodes.service loade networking.service loadeadmin@i-0494d9b5fd1c92c57:~$ s
paris/i-0494d9b5fd1c92c57 05:20
by SadServerswrite(2, ")\n", 2) ) = 2 write(2, "\t", 1 ) = 1 write(2, "./main.go", 9./main.go) = 9 write(2, ":", 1:) = 1 write(2, "64", 264) = 2 write(2, " +", 2 +) = 2 write(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-0133da7c108576538:~$ cd /home/admin/data/newdatafile bash: cd: /home/admin/data/newdatafile: No such file or directory admin@i-0133da7c108576538:~$ mkdir
kihei/i-0133da7c108576538 00:32
by SadServersadmin@i-05ea6cc0264e6ce20:~$ admin@i-05ea6cc0264e6ce20:~$ admin@i-05ea6cc0264e6ce20:~$ admin@i-05ea6cc0264e6ce20:~$ admin@i-05ea6cc0264e6ce20:~$ lsof +D lsof: +d not followed by a directory path lsof 4.93.2 latest revision: https://github.com/lsof-org/lsof latest FAQ: https://github.com/lsof-org/lsof/blob/master/00FAQ latest (non-formatted) man page: https://github.com/lsof-org/lsof/blob/master/L usage: [-?abhKlnNoOPRtUvVX] [+|-c c] [+|-d s] [+D D] [+|-E] [+|-e s] [+|-f[gG]] [-F [f]] [-g [s]] [-i [i]] [+|-L [l]] [+m [m]] [+|-M] [-o [o]] [-p s] [+|-r [t]] [-s [p:s]] [-S [t]] [-T [t]] [-u s] [+|-w] [-x [fl]] [--] [names] Use the ``-h'' option to get more help information. admin@i-05ea6cc0264e6ce20:~$ lsof +D
kihei/i-05ea6cc0264e6ce20 00:25
by SadServersWe trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: Sorry, try again. [sudo] password for admin: Sorry, try again. [sudo] password for admin: sudo: 2 incorrect password attempts admin@i-0cf55633730360868:~$