SadServers Joined on September 10, 2023
1964 public recordings by SadServers
-rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 2023 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-049d7de41c1f65c5b:~$ python webserver.py bash: python: command not found admin@i-049d7de41c1f65c5b:~$ python3 webserver.py python3: can't open file '/home/admin/webserver.py': [Errno 13] Permission denieadmin@i-049d7de41c1f65c5b:~$ systemctl status | grep nginx └─838 grep nginx admin@i-049d7de41c1f65c5b:~$ ls agent webserver.py admin@i-049d7de41c1f65c5b:~$ ls agent check.sh sadagent sadagent.txt admin@i-049d7de41c1f65c5b:~$ curl localhost:50000
paris/i-049d7de41c1f65c5b 04:07
by SadServers*flag.int64Value,flag.Valuego.itab.*flag.stringValue,flag.Valuego.itab.*flag.uin*flag.uint64Value,flag.Valuego.itab.*strings.Builder,io.Writergo.itab.*errors.ermt.wrapError,errorgo.itab.*fmt.pp,fmt.Statego.itab.*os.File,io.Readergo.itab.systab.*io/fs.PathError,errorgo.itab.*os.SyscallError,errorgo.itab.syscall.Errno,erio.Writergo.itab.*os.fileStat,io/fs.FileInfogo.itab.*io.LimitedReader,io.Readerggo.itab.*os/exec.ExitError,errorgo.itab.*os/exec.Error,errorgo.itab.*bufio.Reader.UnknownUserIdError,errorgo.itab.*internal/reflectlite.rtype,internal/reflectliizeError,errorgo.itab.*internal/fmtsort.SortedMap,sort.Interfacego.itab.runtime.t_cgo_thread_start_cgo_notify_runtime_init_done_cgo_callers_cgo_yield_cgo_mmap_cntime.mainPCgo.itab.*internal/poll.DeadlineExceededError,errorgo.itab.internal/pntime.defaultGOROOT.strruntime.buildVersion.strruntime.modinfo.strtype.*runtime.7ca6b7f6d7f0fe:~$ ^C admin@i-08b7ca6b7f6d7f0fe:~$ ^C admin@i-08b7ca6b7f6d7f0fe:~$ ^C admin@i-08b7ca6b7f6d7f0fe:~$
kihei/i-08b7ca6b7f6d7f0fe 00:41
by SadServerschar hugepages null nvme2n1 sdc tty10 tty2 tt vcsa6 vhost-net console initctl nvme0 nvme2n1p1 sdc1 tty11 tty20 tt vcsu vhost-vsock core input nvme0n1 nvram shm tty12 tty21 tt vcsu1 xvda cpu_dma_latency kmsg nvme0n1p1 ptmx snapshot tty13 tty22 tt vcsu2 xvda1 cuse log nvme0n1p14 pts stderr tty14 tty23 tt vcsu3 xvda14 disk loop-control nvme0n1p15 random stdin tty15 tty24 tt1 vcsu4 xvda15 fd mapper nvme1 rtc stdout tty16 tty25 tt2 vcsu5 zero admin@i-017a05d8d0b9fbe51:~$ lvcreate merged -n merged
kihei/i-017a05d8d0b9fbe51 03:32
by SadServersadmin@i-02c1058de6fadf063:/dev$ pvcreate /dev/nvme1n1 WARNING: Running as a non-root user. Functionality may be unavailable. /run/lock/lvm/P_global:aux: open failed: Permission denied admin@i-02c1058de6fadf063:/dev$ sudo pvcreate /dev/nvme1n1 WARNING: dos signature detected on /dev/nvme1n1 at offset 510. Wipe it? [y/n]: n Aborted wiping of dos. 1 existing signature left on the device. admin@i-02c1058de6fadf063:/dev$ vgcreate merger /dev/nvme1n1p1 /dev/nvme2n1p1 WARNING: Running as a non-root user. Functionality may be unavailable. /run/lock/lvm/P_global:aux: open failed: Permission denied admin@i-02c1058de6fadf063:/dev$ sudo vgcreate merger /dev/nvme1n1p1 /dev/nvme2n1 Physical volume "/dev/nvme1n1p1" successfully created. Physical volume "/dev/nvme2n1p1" successfully created. Volume group "merger" successfully created admin@i-02c1058de6fadf063:/dev$ d
kihei/i-02c1058de6fadf063 05:31
by SadServersalternatives.log btmp cloud-init-output.log debug journal messages apt cast cloud-init.log dpkg.log kern.log minio.log auth.log chrony daemon.log faillog lastlog private admin@i-04f72e0d6e94a8af3:~$ vim /var/log/syslog admin@i-04f72e0d6e94a8af3:~$ grep kihei . grep: .: Is a directory admin@i-04f72e0d6e94a8af3:~$ grep kihei ./** grep: ./agent: Is a directory grep: ./data: Is a directory admin@i-04f72e0d6e94a8af3:~$ cd ../ admin@i-04f72e0d6e94a8af3:/home$ ls admin admin@i-04f72e0d6e94a8af3:/home$ cd ~ admin@i-04f72e0d6e94a8af3:~$ cd /var/log admin@i-04f72e0d6e94a8af3:/var/log$ grep kihei
kihei/i-04f72e0d6e94a8af3 04:31
by SadServers● dev-disk-by\x2did-nvme\x2dnvme.1d0f\x2d766f6c30643761656162326266306464323336374696320426c6f636b2053746f7265\x2d00000001\x2dpart15.device - Am> Follow: unit currently follows state of sys-devices-pci0000:00-0000:00:04.0-n5.device Loaded: loaded Active: active (plugged) since Thu 2025-01-09 08:45:00 UTC; 3min 46s ago Device: /sys/devices/pci0000:00/0000:00:04.0/nvme/nvme0/nvme0n1/nvme0n1p15 ● dev-disk-by\x2did-nvme\x2dnvme.1d0f\x2d766f6c30656264646166373565646663343634674696320426c6f636b2053746f7265\x2d00000001.device - Amazon Elast> Follow: unit currently follows state of sys-devices-pci0000:00-0000:00:1f.0-n Loaded: loaded Active: active (plugged) since Thu 2025-01-09 08:45:00 UTC; 3min 46s ago admin@i-0f77a0fc12ab41adb:~$ systemctl status |
kihei/i-0f77a0fc12ab41adb 02:44
by SadServerslrwxrwxrwx 1 root root 10 Sep 28 2021 libx32 -> usr/libx32 drwx------ 2 root root 16384 Sep 28 2021 lost+found drwxr-xr-x 2 root root 4096 Sep 28 2021 media drwxr-xr-x 2 root root 4096 Sep 28 2021 mnt drwxr-xr-x 2 root root 4096 Sep 28 2021 opt dr-xr-xr-x 137 root root 0 Jan 8 20:37 proc drwx------ 4 root root 4096 Jan 8 20:38 root drwxr-xr-x 23 root root 680 Jan 8 20:38 run lrwxrwxrwx 1 root root 8 Sep 28 2021 sbin -> usr/sbin drwxr-xr-x 2 root root 4096 Sep 28 2021 srv dr-xr-xr-x 13 root root 0 Jan 8 20:37 sys drwxrwxrwt 9 root root 4096 Jan 8 20:38 tmp drwxr-xr-x 14 root root 4096 Sep 28 2021 usr drwxr-xr-x 11 root root 4096 Sep 28 2021 var admin@i-02c2ff6f34069647e:/$ df -h
kihei/i-02c2ff6f34069647e 00:48
by SadServers0 0 0 220520 13520 155424 0 0 0 0 23 40 0 0 100 0 0 0 0 220520 13520 155424 0 0 0 0 30 51 0 0 100 0 0 0 0 220520 13520 155428 0 0 0 0 22 31 0 0 100 0 ^C admin@i-02cb6555f73735420:~$ mpstat 1 bash: mpstat: command not found admin@i-02cb6555f73735420:~$ free -m total used free shared buff/cache availableMem: 455 75 214 0 165 367Swap: 0 0 0 admin@i-02cb6555f73735420:~$ iostat -xz 1 bash: iostat: command not found admin@i-02cb6555f73735420:~$ pidstat 1 bash: pidstat: command not found admin@i-02cb6555f73735420:~$
kihei/i-02cb6555f73735420 01:31
by SadServersWe trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: Sorry, try again. [sudo] password for admin: sudo: 1 incorrect password attempt admin@i-066efd15b3da3bd70:~$ lsof -n -i:5000 admin@i-066efd15b3da3bd70:~$ ls agent webserver.py admin@i-066efd15b3da3bd70:~$ ls
paris/i-066efd15b3da3bd70 01:23
by SadServerswrite(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-0a4bdd0d1b31892c2:~$ ./kihei -v Creating file /home/admin/data/newdatafile with size 1.5GB... panic: exit status 1 goroutine 1 [running]: main.main() ./main.go:64 +0x47d admin@i-0a4bdd0d1b31892c2:~$ ls agent data datafile kihei admin@i-0a4bdd0d1b31892c2:~$
kihei/i-0a4bdd0d1b31892c2 01:18
by SadServers_chrony:x:104:104:Chrony daemon,,,:/var/lib/chrony:/usr/sbin/nologin systemd-network:x:105:106:systemd Network Management,,,:/run/systemd:/usr/sbin/nsystemd-resolve:x:106:107:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin sshd:x:107:65534::/run/sshd:/usr/sbin/nologin systemd-timesync:x:999:999:systemd Time Synchronization:/:/usr/sbin/nologin systemd-coredump:x:998:998:systemd Core Dumper:/:/usr/sbin/nologin admin:x:1000:1000:Debian:/home/admin:/bin/bash admin@i-0a733800c5258249a:~$ admin@i-0a733800c5258249a:~$ admin@i-0a733800c5258249a:~$ admin@i-0a733800c5258249a:~$ admin@i-0a733800c5258249a:~$ admin@i-0a733800c5258249a:~$ admin@i-0a733800c5258249a:~$ admin@i-0a733800c5258249a:~$ cat /etc/sha
paris/i-0a733800c5258249a 02:07
by SadServers[sudo] password for admin: sudo: a password is required admin@i-01559a1821be431fc:~$ sudo netstat -tunapl | grep 5000 We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for admin: sudo: a password is required admin@i-01559a1821be431fc:~$ top
paris/i-01559a1821be431fc 02:21
by SadServers"http://www.w3.org/TR/html4/strict.dtd"> <html> <head> <meta http-equiv="Content-Type" content="text/html;charset=utf-8"> <title>Error response</title> </head> <body> <h1>Error response</h1> <p>Error code: 400</p> <p>Message: Bad request syntax ('localhost').</p> <p>Error code explanation: HTTPStatus.BAD_REQUEST - Bad request syntax o </body> </html> admin@i-0db6723bda441af16:~$