command-line-murders/i-0c746f7fa8176bf1c
by SadServersMore by SadServers
usage: knock [options] <host> <port[:proto]> [port[:proto]] ... options: -u, --udp make all ports hits use UDP (default is TCP) -d, --delay <t> wait <t> milliseconds between port hits -v, --verbose be verbose -V, --version display version -h, --help this help example: knock myserver.example.com 123:tcp 456:udp 789:tcp admin@i-061b09841336bd6c6:~$ knock localhost 5000 admin@i-061b09841336bd6c6:~$ curl localhost curl: (7) Failed to connect to localhost port 80: Connection refused admin@i-061b09841336bd6c6:~$ nano enum.sh admin@i-061b09841336bd6c6:~$ chmod +x enum.sh nd
taipei/i-061b09841336bd6c6 04:44
by SadServers-rw-r----- 1 root adm 928 Dec 6 07:51 user.log -rw-r----- 1 root adm 7751 Sep 24 23:20 user.log.1 -rw-r----- 1 root adm 2927 Sep 20 15:56 user.log.2.gz -rw-rw-r-- 1 root utmp 67968 Dec 6 07:51 wtmp admin@i-0e05d284027a30782:/var/log$ cd journal/ admin@i-0e05d284027a30782:/var/log/journal$ ls -la total 12 drwxr-sr-x+ 3 root systemd-journal 4096 Sep 17 16:44 . drwxr-xr-x 9 root root 4096 Dec 6 07:51 .. drwxr-sr-x+ 2 root systemd-journal 4096 Dec 6 07:51 ec26942be8219bc22967aa0256120fca admin@i-0e05d284027a30782:/var/log/journal$ cat ec26942be8219bc22967aa0256120fca/ cat: ec26942be8219bc22967aa0256120fca/: Is a directory admin@i-0e05d284027a30782:/var/log/journal$
paris/i-0e05d284027a30782 04:37
by SadServersadmin@i-0dc1e7b02108a472f:~$ curl localhost:5000 Unauthorizedadmin@i-0dc1e7b02108a472f:~$ curl localhost:5000 GET / Unauthorizedcurl: (6) Could not resolve host: GET curl: (3) URL using bad/illegal format or missing URL admin@i-0dc1e7b02108a472f:~$ admin@i-0dc1e7b02108a472f:~$ curl localhost:5000 GET / Unauthorizedcurl: (6) Could not resolve host: GET curl: (3) URL using bad/illegal format or missing URL admin@i-0dc1e7b02108a472f:~$ admin@i-0dc1e7b02108a472f:~$ curl --user-agent "whatever" localhost:5000 Welcome! Password is FDZPmh5AX3oiJtadmin@i-0dc1e7b02108a472f:~$ cd /home/
paris/i-0dc1e7b02108a472f 02:06
by SadServersfind: ‘/var/cache/private’: Permission denied find: ‘/var/cache/ldconfig’: Permission denied find: ‘/var/cache/apt/archives/partial’: Permission denied find: ‘/var/cache/apparmor/c08a2770.0’: Permission denied find: ‘/var/spool/rsyslog’: Permission denied find: ‘/var/spool/cron/crontabs’: Permission denied find: ‘/var/tmp/systemd-private-9f2badbbb91d448495163a36e0cc284b-chrony.service-find: ‘/var/tmp/systemd-private-9f2badbbb91d448495163a36e0cc284b-systemd-logind.enied find: ‘/var/log/private’: Permission denied find: ‘/var/log/chrony’: Permission denied find: ‘/var/lib/private’: Permission denied find: ‘/var/lib/apt/lists/partial’: Permission denied find: ‘/var/lib/chrony’: Permission denied admin@i-0f010295ecb30725e:~$ find / -type f | grep webse