command-line-murders/i-0d8a629e22c382dff
by SadServersMore by SadServers
-rw------- 1 admin admin 338 Nov 6 22:15 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 2023 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 2023 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-0e8108e3a59a33ce2:~$ cat /etc/sudoers cat: /etc/sudoers: Permission denied admin@i-0e8108e3a59a33ce2:~$ cat /etc/sudoers.d/ cat: /etc/sudoers.d/: Permission denied admin@i-0e8108e3a59a33ce2:~$ cat /etc/sudo sudo.conf sudo_logsrvd.conf sudoers sudoers.d/ admin@i-0e8108e3a59a33ce2:~$ cat /etc/sudo
paris/i-0e8108e3a59a33ce2 02:59
by SadServersmain.main() ./main.go:64 +0x47d admin@i-052ffdd8c0d9d9e66:~$ rm data data/ datafile admin@i-052ffdd8c0d9d9e66:~$ rm data data/ datafile admin@i-052ffdd8c0d9d9e66:~$ rm data data/ datafile admin@i-052ffdd8c0d9d9e66:~$ ls data admin@i-052ffdd8c0d9d9e66:~$ ls agent data datafile kihei admin@i-052ffdd8c0d9d9e66:~$ admin@i-052ffdd8c0d9d9e66:~$ admin@i-052ffdd8c0d9d9e66:~$ admin@i-052ffdd8c0d9d9e66:~$
kihei/i-052ffdd8c0d9d9e66 01:43
by SadServersroot 584 0.0 0.4 4396 2104 ttyS0 Ss+ 15:59 0:00 /sbin/agetty root 585 0.0 1.5 13352 7136 ? Ss 15:59 0:00 sshd: /usr/sb_chrony 587 0.0 0.7 10852 3716 ? S 15:59 0:00 /usr/sbin/chr_chrony 588 0.0 0.1 10724 552 ? S 15:59 0:00 /usr/sbin/chrroot 607 0.0 3.7 26612 17324 ? Ss 15:59 0:00 /usr/bin/pythroot 681 0.0 0.0 0 0 ? I 15:59 0:00 [kworker/0:3-root 682 0.0 0.0 0 0 ? I 15:59 0:00 [kworker/0:4-admin 685 0.0 0.9 6740 4500 pts/0 S<s+ 15:59 0:00 bash -l admin 689 0.2 4.1 98188 19260 pts/0 R<l+ 15:59 0:00 /usr/bin/pythadmin 692 0.0 3.2 24456 14960 pts/0 S<+ 15:59 0:00 /usr/bin/pythadmin 693 0.0 0.1 2480 512 pts/1 S<s 15:59 0:00 sh -c /bin/baadmin 694 0.0 1.0 6952 4812 pts/1 S< 15:59 0:00 /bin/bash root 763 0.0 0.0 0 0 ? R 16:00 0:00 [kworker/u4:4admin 808 0.0 0.6 8648 3140 pts/1 R<+ 16:01 0:00 ps -aux admin@i-08415f3e4b883b5b6:/etc/apache2/conf-available$