SadServers Joined on September 10, 2023
1947 public recordings by SadServers
nvme0n1 259:0 0 8G 0 disk nvme2n1 259:1 0 1G 0 disk nvme1n1 259:2 0 1G 0 disk nvme0n1p1 259:3 0 7.9G 0 part / nvme0n1p14 259:4 0 3M 0 part nvme0n1p15 259:5 0 124M 0 part /boot/efi admin@i-07811c3a73cb0d954:~$ ./kihei -v Creating file /home/admin/data/newdatafile with size 1.5GB... panic: exit status 1 goroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-07811c3a73cb0d954:~$ sudo mount /dev/vg/lv /home/admin/data admin@i-07811c3a73cb0d954:~$ df
kihei/i-07811c3a73cb0d954 08:40
by SadServers4 ./data 8 ./.config/asciinema 12 ./.config 8 ./.ssh 5256228 . admin@i-0eda2bc33bbba2475:~$ du -h . 11M ./agent 4.0K ./.ansible/tmp 8.0K ./.ansible 4.0K ./data 8.0K ./.config/asciinema 12K ./.config 8.0K ./.ssh 5.1G . admin@i-0eda2bc33bbba2475:~$ lsblk -l
kihei/i-0eda2bc33bbba2475 05:31
by SadServerswrite(2, ":", 1:) = 1 write(2, "64", 264) = 2 write(2, " +", 2 +) = 2 write(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-04e9a940bea99a35d:~$ ls /home/admin/data/newdatafile ls: cannot access '/home/admin/data/newdatafile': No such file or directory admin@i-04e9a940bea99a35d:~$ cd /home/admin/data/ admin@i-04e9a940bea99a35d:~/data$ ls admin@i-04e9a940bea99a35d:~/data$ vi newdatafile admin@i-04e9a940bea99a35d:~/data$ chattr -i newdatafile admin@i-04e9a940bea99a35d:~/data$
kihei/i-04e9a940bea99a35d 06:04
by SadServers20K /var/log/debug 16K /var/log/dpkg.log 8.0K /var/log/faillog 33M /var/log/journal 176K /var/log/kern.log 8.0K /var/log/lastlog 180K /var/log/messages 4.0K /var/log/minio.log 4.0K /var/log/private 8.0K /var/log/runit 316K /var/log/syslog 8.0K /var/log/unattended-upgrades 20K /var/log/user.log 52K /var/log/wtmp admin@i-00c7c0914e0cfbd6f:~$
kihei/i-00c7c0914e0cfbd6f 00:57
by SadServers-rw-r----- 1 root adm 6951 Feb 18 15:31 syslog -rw-r----- 1 root adm 88453 Feb 18 15:26 syslog.1 -rw-r----- 1 root adm 46670 Sep 24 2023 syslog.2.gz drwxr-x--- 2 root adm 4096 Feb 18 15:26 unattended-upgrades -rw-r----- 1 root adm 928 Feb 18 15:26 user.log -rw-r----- 1 root adm 7751 Sep 24 2023 user.log.1 -rw-r----- 1 root adm 2927 Sep 20 2023 user.log.2.gz -rw-rw-r-- 1 root utmp 67968 Feb 18 15:26 wtmp admin@i-08d02c91e01791c90:/var/log$ ll bash: ll: command not found admin@i-08d02c91e01791c90:/var/log$ vi syslog. syslog.1 syslog.2.gz admin@i-08d02c91e01791c90:/var/log$ vi syslog. syslog.1 syslog.2.gz admin@i-08d02c91e01791c90:/var/log$ vi syslog.
paris/i-08d02c91e01791c90 06:30
by SadServersmain.main() ./main.go:64 +0x47d admin@i-04c6f947b4137d4bb:~$ ./kihei -h Usage: ./kihei [options] -h Display help -help Display help -v Verbose mode (print extra info) -verbose Verbose mode (print extra info) admin@i-04c6f947b4137d4bb:~$ free -m total used free shared buff/cache availableMem: 455 90 198 0 167 352Swap: 0 0 0 admin@i-04c6f947b4137d4bb:~$
kihei/i-04c6f947b4137d4bb 02:02
by SadServers_chrony 594 0.0 0.1 10724 556 ? S 10:32 0:00 \_ /usr/sbinroot 602 0.0 3.7 26612 17524 ? Ss 10:32 0:00 /usr/bin/pythadmin@i-0f1eaa7d28ad4d0f3:~$ vim /home/admin/webserver.py admin@i-0f1eaa7d28ad4d0f3:~$ ls -l total 8 drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-0f1eaa7d28ad4d0f3:~$ chown admin:admin webserver.py chown: changing ownership of 'webserver.py': Operation not permitted admin@i-0f1eaa7d28ad4d0f3:~$ lsattr -i webserver.py lsattr: invalid option -- 'i' Usage: lsattr [-RVadlpv] [files...] admin@i-0f1eaa7d28ad4d0f3:~$ lsattr webserver.py lsattr: Permission denied While reading flags on webserver.py admin@i-0f1eaa7d28ad4d0f3:~$ h
paris/i-0f1eaa7d28ad4d0f3 04:44
by SadServersstemd: --nofork --nopidfile --systemd-activation --syslog-only root 573 0.2 5.9 33040 27900 ? Ss 21:18 0:00 /usr/bin/pythroot 575 0.0 0.9 220796 4340 ? Ssl 21:18 0:00 /usr/sbin/rsyroot 586 0.0 1.4 13492 6676 ? Ss 21:18 0:00 /lib/systemd/root 591 0.0 0.3 2872 1728 tty1 Ss+ 21:18 0:00 /sbin/agetty nux root 592 0.0 0.4 4396 2096 ttyS0 Ss+ 21:18 0:00 /sbin/agetty 0,57600,38400,9600 ttyS0 vt220 root 593 0.0 1.5 13352 7292 ? Ss 21:18 0:00 sshd: /usr/sb-100 startups _chrony 595 0.0 0.7 10852 3664 ? S 21:18 0:00 /usr/sbin/chr_chrony 596 0.0 0.1 10724 548 ? S 21:18 0:00 \_ /usr/sbinroot 610 0.0 3.7 26612 17412 ? Ss 21:18 0:00 /usr/bin/pythrades/unattended-upgrade-shutdown --wait-for-signal admin@i-0f11b62e125014253:~$ curl 127
paris/i-0f11b62e125014253 02:50
by SadServersadmin@i-0102423b4d32663a7:~$ curl 127.0.0.1:5000 Unauthorizedadmin@i-0102423b4d32663a7:~$ admin@i-0102423b4d32663a7:~$ admin@i-0102423b4d32663a7:~$ ls agent webserver.py admin@i-0102423b4d32663a7:~$ less webserver.py webserver.py: Permission denied admin@i-0102423b4d32663a7:~$ ll bash: ll: command not found admin@i-0102423b4d32663a7:~$ cat webserver.py cat: webserver.py: Permission denied admin@i-0102423b4d32663a7:~$ cd agent/ admin@i-0102423b4d32663a7:~/agent$ ls check.sh sadagent sadagent.txt admin@i-0102423b4d32663a7:~/agent$ ls
paris/i-0102423b4d32663a7 02:35
by SadServers24 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 netns 25 root 20 0 0 0 0 S 0.0 0.0 0:00.12 kauditd 26 root 20 0 0 0 0 S 0.0 0.0 0:00.00 khungtask 27 root 20 0 0 0 0 S 0.0 0.0 0:00.00 oom_reape 28 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 writeback 29 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kcompactd 30 root 25 5 0 0 0 S 0.0 0.0 0:00.00 ksmd 49 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kintegrit 50 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kblockd 51 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 blkcg_pun 52 root 20 0 0 0 0 I 0.0 0.0 0:00.03 kworker/1 53 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kworker/0 54 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kswapd0 55 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kthrotld admin@i-0bc8be230e1a6d230:~$ lso
paris/i-0bc8be230e1a6d230 01:07
by SadServersgoroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0b280c2a98b3cd4ee:~$ cd /home/admin/ admin@i-0b280c2a98b3cd4ee:~$ ls agent data datafile kihei admin@i-0b280c2a98b3cd4ee:~$ ./kihei panic: exit status 1 goroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0b280c2a98b3cd4ee:~$ kihei bash: kihei: command not found admin@i-0b280c2a98b3cd4ee:~$ kihei