HTB BedSide Writeup
Hack The Box BedSide machine overview: PDFMiner path traversal, SSH key theft and PyTorch deserialization. Full walkthrough published after the machine retires.
Due to Hack The Box policies this walkthrough is not publicly served until BedSide retires. See the official HTB writeup guidelines.
Machine profile
- Platform
- Hack The Box
- Machine
- BedSide
- Difficulty
- Medium
- Published
- Status
- active
BedSide is a medium-difficulty Linux machine from Hack The Box set in a clinical environment, and it turns two deceptively mundane pieces of software into a full compromise: a document text-extraction library and a machine-learning inference stack.
The skill areas are path traversal, local file inclusion, insecure deserialization in Python applications, and the privilege escalation patterns that come from services running with more access than they need. Python security is the through-line, and the machine is a good place to meet two of its most common vulnerability classes in the same box.
It suits readers interested in Python security and in the overlap between ordinary file handling and genuinely dangerous behaviour. It is also a useful reminder that machine-learning model files should be treated as executable content rather than inert data. The escalation to root is a writable service rather than a memory-corruption bug, which keeps it realistic and approachable.
What this machine covers
Vulnerabilities
Software, services & tooling
Techniques & attack classes
What the finished writeup contains
When BedSide retires, the complete walkthrough publishes here unchanged — every command, output and screenshot from the actual box, in the order it was solved.
- Reconnaissance Port scanning, service fingerprinting and attack-surface mapping
- Initial foothold The first authenticated or unauthenticated execution path
- Enumeration Deeper inspection of the exposed services and their configuration
- Exploitation Chaining the weaknesses found into a working exploit
- Credential recovery Secrets, keys and hashes, and how they were obtained
- Privilege escalation The route from the foothold account to a root shell
- Flags User and root flag capture
211 views on this machine so far — demand is tracked, and the walkthrough publishes the moment the box retires.
Why is this walkthrough protected right now?
No active-machine solution, flag, credential, exploit chain or private asset appears on this public page. Only the machine's profile, the topics it covers and a description of what the finished writeup will contain are published while the box is live.
Topics: PDFMiner, CVE-2025-64512, Path Traversal, LFI, Python Pickle, Insecure Deserialization, PyTorch torch.load, SSH Key Theft, Rustscan, Nmap, Linux Privilege Escalation
Comments
No comments yet — be the first to share your thoughts.