Hack The Box - HTB BedSide Writeup - Medium - Weekly - July 19th, 2026
July 18, 2026

Add the vhosts to your hosts file before starting: echo " bedside.htb research.bedside.htb" | sudo tee -a /etc/hosts # HTB VPN frequently black-holes large outbound requests; lower the tunnel MTU to be safe sudo ip link set dev tun0 mtu 1300 1. Recon nmap -Pn -sT -p- --min-rate 1500 --max-retries 3 nmap -Pn -sCV -p22,80,3000 22/tcp open ssh OpenSSH 10.0p2 Debian 7+deb13u4 (Debian 13 "trixie") 80/tcp open http Apache/2.4.68 (Debian) → redirects to http://bedside.htb 3000/tcp filtered Port 80 redirects to bedside.htb, a static "clinic" site. Fuzz for vhosts: ffuf -u http://bedside.htb/ -H…