command-line-murders/i-06d9a3b708cd2b206
by SadServersMore by SadServers
admin 686 0.0 0.9 6740 4540 pts/0 S<s+ 22:25 0:00 bash -l admin 690 0.8 4.1 98188 19416 pts/0 D<l+ 22:25 0:00 /usr/bin/pyth-t paris/i-07602503257110b80 -q -i 2 /var/log/cast/i-076025032571 admin 693 0.0 3.0 24456 14444 pts/0 R<+ 22:25 0:00 /usr/bin/pyth-t paris/i-07602503257110b80 -q -i 2 /var/log/cast/i-076025032571 admin 694 0.0 0.1 2480 512 pts/1 S<s 22:25 0:00 sh -c /bin/baadmin 695 0.0 0.9 6820 4460 pts/1 S< 22:25 0:00 /bin/bash admin 730 0.0 0.6 8648 3160 pts/1 R<+ 22:26 0:00 ps aux admin@i-07602503257110b80:~$ ps aux | grep nginx admin 732 0.0 0.1 5264 640 pts/1 S<+ 22:26 0:00 grep nginx admin@i-07602503257110b80:~$ ps aux | grep apache admin 734 0.0 0.1 5264 640 pts/1 S<+ 22:26 0:00 grep apache admin@i-07602503257110b80:~$ ls agent webserver.py admin@i-07602503257110b80:~$ cat webserver.py
paris/i-07602503257110b80 01:07
by SadServers-M,--ismountpoint fulfill request only if NAME is a mount point -n,--namespace SPACE search in this name space (file, udp, or tcp) -s,--silent silent operation -SIGNAL send this signal instead of SIGKILL -u,--user display user IDs -v,--verbose verbose output -w,--writeonly kill only processes with write access -V,--version display version information -4,--ipv4 search IPv4 sockets only -6,--ipv6 search IPv6 sockets only - reset options udp/tcp names: [local_port][,[rmt_host][,[rmt_port]]] admin@i-0c38afa742070df59:~$ fuser -a
paris/i-0c38afa742070df59 03:37
by SadServersadmin@i-041e19fae03c7874a:~$ ss -natup | grep 5000 tcp LISTEN 0 128 127.0.0.1:5000 0 admin@i-041e19fae03c7874a:~$ curl localhost:5000 Unauthorizedadmin@i-041e19fae03c7874a:~$ curl http://localhost:5000 Welcome! Password is FDZPmh5AX3oiJtadmin@i-041e19fae03c7874a:~$ nc localhost 500GET /HTTP/1.1