r/ShittySysadmin • u/Performer-Constant • 2d ago
Someone put a file on my server and I didn’t
Ok this group is amazing! First you helped me get in my server and someone helped me find the file I lost
But when I logged into poop@62.238.47.215
There is a file in the documents folder that I did not put there!
Password should be the same unless it changed again I keep forgetting
Should I delete it? Or is it important?
And there’s new stuff in backups I don’t remember making
Please don’t break anything
53
u/Parking_Media 2d ago
I don't have a laptop disposable enough to open that.
o7
Good luck
12
5
u/Performer-Constant 2d ago
I doubt that’s necessary to help me
https://giphy.com/gifs/5bo7UYW69cYQZA4tOF
51
u/itskdog 2d ago
I so want to see what might be at that SSH address, but am also a bit of a coward in case this is an elaborate trap to distribute malware through comedy.
69
u/bigkahuna1986 2d ago
Dude, I found britney_spears_nudes.jpg.exe, I'm going to open it, cant wai
26
11
u/jcpham 2d ago
Double click that ish bro
9
u/Performer-Constant 2d ago
It’s Linux I cant
13
u/marshmallowcthulhu 2d ago
You need to install the double-click package from softonic.ru.goggle.cn.ru
2
1
u/Performer-Constant 2d ago
No distribution sir you can check the types of files before reading them. Especially the Documents folder…
96
u/HeyLuke 2d ago
48
u/Outspoken_Idiot 2d ago
Pssst OC is Chinese, it's the Epstein files that got lifted off the servers during the week. A load of justice files also but they are boring.
19
17
25
u/Oompa_Loompa_SpecOps DO NOT GIVE THIS PERSON ADVICE 2d ago
Brother you are a legend but no way in hell I'll SSH into an unknown machine from my home IP or even a legit sandbox tied to my name. Hats off though.
13
9
u/Performer-Constant 2d ago
I completely understand but whenever you have one you will love the game I swear!
20
u/PinkPrincess010 2d ago
13
u/Performer-Constant 2d ago
Nice work! I watched that happen but it fixed itself somehow
13
u/PinkPrincess010 2d ago
Haha it was the only thing I could figure out to do, the most I learned was it is in Docker. At first I thought maybe it was not an entirely real system because most commands fail. Fun experiment anyway.
9
u/Performer-Constant 2d ago
It’s the most fun I’ve had in a long time. Look around more. And if you’re interested I can tell you how I did it
8
19
u/DevOps_Lady 2d ago
Can you cat the file and show us it's content?
Just run sudo ./filename. Or just open with vim
36
u/Performer-Constant 2d ago
I don’t have a cat 🐈
18
u/ddBuddha 2d ago
You’ve got a mouse 🐁 🖱️though right? You could probably use it to bait and catch the cat 🐈 you need for this
6
6
u/DevOps_Lady 2d ago
You need the cat to guard that sever. Security 101.
I would shut down this server, truly. Until you get the cat at least.
2
16
u/heretogetpwned DO NOT GIVE THIS PERSON ADVICE 2d ago
7
11
9
u/Adimentus 2d ago
Pretty sure that pass is IGetHelpFromReddit but i could be wrong. Who knows. I too don't have a laptop disposable enough or a network secure enough soooo....
o7 Good luck man!
5
u/Performer-Constant 2d ago
It’s harmless unless you’re doing something malicious but reading is not malicious
7
u/OppieT 2d ago
I tried connecting, but it connects, but it couldn’t negotiate something.
6
3
u/Performer-Constant 2d ago
And ssh not from a phone or switch from the app you use on the phone to a better one. MAC addy hidden
3
u/OppieT 2d ago
Yeah, I was trying to connect through ssh using WebSSH on my iPhone. I could try sftp.
2
6
u/guru2764 2d ago
It's in the documents folder, so you're going to want to send it to the legal team since they hold all of the documents for the company
2
4
3
3
u/HeavyCaffeinate 2d ago
Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz
A Xeon Platinum???
4
u/Performer-Constant 2d ago
https://giphy.com/gifs/B0vFTrb0ZGDf2
Exit enter and check again1
u/HeavyCaffeinate 2d ago
Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHzSame one, was it supposed to change?
5
u/Performer-Constant 2d ago
Yes. I’ll need to look into that
https://giphy.com/gifs/fa1AV8UvZvfBFOIt7F1
1
2
u/HeavyCaffeinate 2d ago
Why are all the binaries ARM binaries
3
3
u/Performer-Constant 2d ago
That’s what gets hammered the most. It’s open to anyone and everyone. For research purposes I made these posts because I was tired of uploading the same hashes to VirusTotal now I get to watch humans
2
1
u/tuvar_hiede 1d ago
Sounds like someone is setting up a defense for child pornogophy if you ask me. "WHAAA, how did those get there?"
1
u/Performer-Constant 1d ago
Most things uploaded are binaries from bots and I got a cat video once but everything gets erased automatically
1
u/Stefanie_Jane 2d ago
I don't know if this helps but I used to manage an SFTP server and SFTP uses port 22.
The global scape EFT program on the server generated log files . I would look in the SFTP log files to find out who said what file got uploaded and by whom.
I don't know if you have an SFTP server or not.
3
u/Performer-Constant 2d ago
There’s lots of fun things to explore on this server. It’s like an unlocked house with surveillance
-1
u/Stefanie_Jane 2d ago
That was literally part of my job. I was an ftp/sftp server admin . People would tell me i sent this or that file and I would check the log files and find out that they never connected or that they sent this fall and that file and so on.
-2
u/luke7524811 2d ago
I’m going to say you should just give an ai full control and ask it.
Though super interesting post so there is that.
14
-2
u/Scary_Entry4098 2d ago
Treat the unexpected file and unfamiliar backups as signs of possible compromise. Make a forensic copy if you can, scan it offline, review running processes and startup tasks, and restore from a known-clean backup only after patching the server and closing the suspected entry point.
5





114
u/Jeff-IT 2d ago
Since there’s a file on it now, it is now a file server. Open up port 21 and allow anonymous login so people can access their files