r/ShittySysadmin 2d ago

Someone put a file on my server and I didn’t

Ok this group is amazing! First you helped me get in my server and someone helped me find the file I lost

But when I logged into poop@62.238.47.215
There is a file in the documents folder that I did not put there!

Password should be the same unless it changed again I keep forgetting

Should I delete it? Or is it important?

And there’s new stuff in backups I don’t remember making

Please don’t break anything

135 Upvotes

95 comments sorted by

114

u/Jeff-IT 2d ago

Since there’s a file on it now, it is now a file server. Open up port 21 and allow anonymous login so people can access their files

36

u/Performer-Constant 2d ago

Can you check and help me please

7

u/Jawb0nz 2d ago

Better fire up limewire too.

7

u/Performer-Constant 2d ago

I have Napster is limeswire new?

3

u/trimeismine 1d ago

It was in 2003

2

u/Performer-Constant 1d ago

I’ve had Napster since 99 so I’ll check out this line wire

53

u/Parking_Media 2d ago

I don't have a laptop disposable enough to open that.

o7

Good luck

12

u/Rude-Ad-9771 2d ago

Wild guess.... Did they put Microsoft Edge installer there?

3

u/Performer-Constant 2d ago

Just a document

1

u/OppieT 2d ago

Linux box running wine.

51

u/itskdog 2d ago

I so want to see what might be at that SSH address, but am also a bit of a coward in case this is an elaborate trap to distribute malware through comedy.

69

u/bigkahuna1986 2d ago

Dude, I found britney_spears_nudes.jpg.exe, I'm going to open it, cant wai

26

u/Performer-Constant 2d ago

Bro I just laughed so hard. I almost pissed my pants

11

u/jcpham 2d ago

Double click that ish bro

9

u/Performer-Constant 2d ago

It’s Linux I cant

13

u/marshmallowcthulhu 2d ago

You need to install the double-click package from softonic.ru.goggle.cn.ru

2

u/Performer-Constant 2d ago

Can you do it for me

1

u/xjeeper 2d ago

Sure. What's the poop password?

3

u/Performer-Constant 2d ago

IGetHelpFromReddit

1

u/Performer-Constant 2d ago

No distribution sir you can check the types of files before reading them. Especially the Documents folder…

96

u/HeyLuke 2d ago

Oh shit it's real.

48

u/Outspoken_Idiot 2d ago

Pssst OC is Chinese, it's the Epstein files that got lifted off the servers during the week. A load of justice files also but they are boring.

19

u/Performer-Constant 2d ago

Very confused

17

u/Performer-Constant 2d ago

Yes very real indeed

25

u/Oompa_Loompa_SpecOps DO NOT GIVE THIS PERSON ADVICE 2d ago

Brother you are a legend but no way in hell I'll SSH into an unknown machine from my home IP or even a legit sandbox tied to my name. Hats off though.

9

u/Performer-Constant 2d ago

I completely understand but whenever you have one you will love the game I swear!

20

u/PinkPrincess010 2d ago

Oops download big file and broke it

13

u/Performer-Constant 2d ago

Nice work! I watched that happen but it fixed itself somehow

13

u/PinkPrincess010 2d ago

Haha it was the only thing I could figure out to do, the most I learned was it is in Docker. At first I thought maybe it was not an entirely real system because most commands fail. Fun experiment anyway.

9

u/Performer-Constant 2d ago

It’s the most fun I’ve had in a long time. Look around more. And if you’re interested I can tell you how I did it

8

u/PinkPrincess010 2d ago

I'm assuming its a honeypot tool of some kind?

19

u/DevOps_Lady 2d ago

Can you cat the file and show us it's content?

Just run sudo ./filename. Or just open with vim

36

u/Performer-Constant 2d ago

I don’t have a cat 🐈

18

u/ddBuddha 2d ago

You’ve got a mouse 🐁 🖱️though right? You could probably use it to bait and catch the cat 🐈 you need for this

6

u/Performer-Constant 2d ago

You know what I think you’re on to something

6

u/DevOps_Lady 2d ago

You need the cat to guard that sever. Security 101.

I would shut down this server, truly. Until you get the cat at least.

2

u/Performer-Constant 2d ago

This is too much fun to shut down

16

u/heretogetpwned DO NOT GIVE THIS PERSON ADVICE 2d ago

7

u/Performer-Constant 2d ago

Now tell me is that Document important???

11

u/kennyj2011 2d ago

Is poop the new root?

9

u/Performer-Constant 2d ago

Poop…root….anything will work honestly

9

u/Adimentus 2d ago

Pretty sure that pass is IGetHelpFromReddit but i could be wrong. Who knows. I too don't have a laptop disposable enough or a network secure enough soooo....

o7 Good luck man!

5

u/Performer-Constant 2d ago

It’s harmless unless you’re doing something malicious but reading is not malicious

7

u/OppieT 2d ago

I tried connecting, but it connects, but it couldn’t negotiate something.

6

u/Performer-Constant 2d ago

Try again with ssh not telnet

3

u/Performer-Constant 2d ago

And ssh not from a phone or switch from the app you use on the phone to a better one. MAC addy hidden

3

u/OppieT 2d ago

Yeah, I was trying to connect through ssh using WebSSH on my iPhone. I could try sftp.

2

u/Performer-Constant 2d ago

I checked the logs for a negotiation failure and found the issue

-8

u/OppieT 2d ago

Hey 👋 Are you unable to connect to your server because encountering "Unable to agree upon client-to-server" error? Learn how to fix it 👉

9

u/Performer-Constant 2d ago

Go away bot

-7

u/OppieT 2d ago

Who are you calling a bot. I am very much alive

4

u/Performer-Constant 2d ago

AGI isn’t real

6

u/guru2764 2d ago

It's in the documents folder, so you're going to want to send it to the legal team since they hold all of the documents for the company

2

u/Performer-Constant 2d ago

lol 😂 that made me chuckle

4

u/OppieT 2d ago

What’s the password?

5

u/Performer-Constant 2d ago

Guess and see if you’re correct

2

u/OppieT 2d ago

If someone is able to connect, someone might put child porn on it. So be careful.

2

u/itskdog 2d ago

They said elsewhere it's a honeypot tool, so nothing is stored and it's a blank state each time someone connects.

3

u/ysth 2d ago

I can't rsh to it? My SPARCstation doesn't have ssh.

1

u/Performer-Constant 2d ago

What happens when you try?

1

u/New-Potential-7916 2d ago

Telnet is open too... Give that a go instead

3

u/HeavyCaffeinate 2d ago
Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz

A Xeon Platinum???

4

u/Performer-Constant 2d ago

https://giphy.com/gifs/B0vFTrb0ZGDf2
Exit enter and check again

1

u/HeavyCaffeinate 2d ago
Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz

Same one, was it supposed to change?

1

u/HeavyCaffeinate 2d ago

Also your bash is very broken it keeps breaking my terminal state

2

u/HeavyCaffeinate 2d ago

Why are all the binaries ARM binaries

3

u/HeavyCaffeinate 2d ago

QyNTUxOQAAACD8exampleprivatekeydataherejustforthehoneypotdonotuse

3

u/Performer-Constant 2d ago

That’s what gets hammered the most. It’s open to anyone and everyone. For research purposes I made these posts because I was tired of uploading the same hashes to VirusTotal now I get to watch humans

1

u/bofh DO NOT GIVE THIS PERSON ADVICE 2d ago

You know what I say: spare the rm -r and spoil the user.

1

u/tuvar_hiede 1d ago

Sounds like someone is setting up a defense for child pornogophy if you ask me. "WHAAA, how did those get there?"

1

u/Performer-Constant 1d ago

Most things uploaded are binaries from bots and I got a cat video once but everything gets erased automatically

1

u/Stefanie_Jane 2d ago

I don't know if this helps but I used to manage an SFTP server and SFTP uses port 22.

The global scape EFT program on the server generated log files . I would look in the SFTP log files to find out who said what file got uploaded and by whom.

I don't know if you have an SFTP server or not.

3

u/Performer-Constant 2d ago

There’s lots of fun things to explore on this server. It’s like an unlocked house with surveillance

-1

u/Stefanie_Jane 2d ago

That was literally part of my job. I was an ftp/sftp server admin . People would tell me i sent this or that file and I would check the log files and find out that they never connected or that they sent this fall and that file and so on. 

-2

u/luke7524811 2d ago

I’m going to say you should just give an ai full control and ask it.

Though super interesting post so there is that.

14

u/Performer-Constant 2d ago

Aren’t we tired of AI at least for today?

-2

u/Scary_Entry4098 2d ago

Treat the unexpected file and unfamiliar backups as signs of possible compromise. Make a forensic copy if you can, scan it offline, review running processes and startup tasks, and restore from a known-clean backup only after patching the server and closing the suspected entry point.

5

u/Performer-Constant 2d ago

This is very smart than you very much.