Discussion — Any questions? Ask and discuss freely in the community.
Hack The Box active 211 views

HTB BedSide Writeup

Hack The Box BedSide machine overview: PDFMiner path traversal, SSH key theft and PyTorch deserialization. Full walkthrough published after the machine retires.

BedSide
Medium active Hack The Box
BedSide completion
Protected while the machine is active

Due to Hack The Box policies this walkthrough is not publicly served until BedSide retires. See the official HTB writeup guidelines.

Machine profile

Platform
Hack The Box
Machine
BedSide
Difficulty
Medium
Published
Status
active

BedSide is a medium-difficulty Linux machine from Hack The Box set in a clinical environment, and it turns two deceptively mundane pieces of software into a full compromise: a document text-extraction library and a machine-learning inference stack.

The skill areas are path traversal, local file inclusion, insecure deserialization in Python applications, and the privilege escalation patterns that come from services running with more access than they need. Python security is the through-line, and the machine is a good place to meet two of its most common vulnerability classes in the same box.

It suits readers interested in Python security and in the overlap between ordinary file handling and genuinely dangerous behaviour. It is also a useful reminder that machine-learning model files should be treated as executable content rather than inert data. The escalation to root is a writable service rather than a memory-corruption bug, which keeps it realistic and approachable.

What this machine covers

Vulnerabilities

Software, services & tooling

PDFMiner Python Pickle PyTorch torch.load Rustscan Nmap

Techniques & attack classes

Path Traversal LFI Insecure Deserialization SSH Key Theft Linux Privilege Escalation

What the finished writeup contains

When BedSide retires, the complete walkthrough publishes here unchanged — every command, output and screenshot from the actual box, in the order it was solved.

  1. Reconnaissance Port scanning, service fingerprinting and attack-surface mapping
  2. Initial foothold The first authenticated or unauthenticated execution path
  3. Enumeration Deeper inspection of the exposed services and their configuration
  4. Exploitation Chaining the weaknesses found into a working exploit
  5. Credential recovery Secrets, keys and hashes, and how they were obtained
  6. Privilege escalation The route from the foothold account to a root shell
  7. Flags User and root flag capture

211 views on this machine so far — demand is tracked, and the walkthrough publishes the moment the box retires.

Why is this walkthrough protected right now?

No active-machine solution, flag, credential, exploit chain or private asset appears on this public page. Only the machine's profile, the topics it covers and a description of what the finished writeup will contain are published while the box is live.

Topics: PDFMiner, CVE-2025-64512, Path Traversal, LFI, Python Pickle, Insecure Deserialization, PyTorch torch.load, SSH Key Theft, Rustscan, Nmap, Linux Privilege Escalation

Comments