How to Install Metasploitable 2
The full path from downloading the image to booting your first lab session.
Metasploitable 2 (often just called Metasploitable) is an intentionally vulnerable Linux virtual machine (VM) built for practicing penetration testing in a controlled environment. This hub walks you through downloading it, installing it, scanning it, and understanding the security lessons behind every exposed service — step by step, with no assumed experience.
Beginner Friendly•Lab Based•Step-by-Step Guides
| PORT | STATE | SERVICE |
| 21/tcp | open | ftp |
| 22/tcp | open | ssh |
| 23/tcp | open | telnet |
| 80/tcp | open | http |
| 445/tcp | open | microsoft-ds |
Metasploitable 2 is a deliberately vulnerable Ubuntu Linux virtual machine, distributed as a free VM image for security training. Unlike a production server, every service on it was left intentionally outdated or misconfigured so learners have something safe and legal to scan, enumerate, and exploit inside their own lab — instead of practicing on a system they don't own.
Because the vulnerabilities are known and documented, Metasploitable 2 works as a consistent baseline: the same weak FTP daemon, the same exposed database, and the same web applications appear whether you're following a tutorial today or one written years ago. That makes it one of the most widely used starting points for people learning:
Discovering live hosts and open ports on an isolated lab network.
Identifying what software is running behind each open port and why it matters.
Recognizing outdated software versions and unsafe default configurations.
Practicing on bundled vulnerable apps like DVWA and Mutillidae.
Four stages take you from a blank VM to your first scan.
Get the VM image and verify what you're downloading before importing it.
Download Guide →Import the disk image into VirtualBox or VMware and boot it for the first time.
Installation Guide →Place both machines on the same isolated, host-only network.
Kali Linux Setup →Run your first scan and begin working through the vulnerability guides.
Nmap Guide →Practice cybersecurity techniques inside an isolated lab environment, with no risk to a real network.
Every exposed service was chosen deliberately, so what you find is meant to be found.
Structured, step-by-step tutorials that assume no prior penetration-testing experience.
Learn networking, Linux security, web security, enumeration, and vulnerability assessment in one place.
The six guides most learners read first.
The full path from downloading the image to booting your first lab session.
Import the disk image and configure a host-only network in VirtualBox.
Run Metasploitable 2 under VMware Workstation, Player, or Fusion.
Put both machines on the same isolated network so scans can actually reach the target.
Three reliable ways to find the target's IP before you scan it.
The documented default username and password, and why they only belong in a lab.
Every stage pairs an offensive skill with the defensive lesson behind it.
Install the VM and configure isolated networking so your lab can't reach, or be reached by, anything outside it.
Find the target on the network and confirm it's reachable before scanning further.
Identify exactly which services are exposed and what versions they're running.
Match enumerated services against known weaknesses and insecure configurations.
Apply what you've found inside your own isolated environment, methodically and safely.
Understand why each vulnerability exists and how defenders reduce that class of risk in production.
Each category explains why the weakness exists and what it teaches, not just how to trigger it.
Unauthenticated and backdoored file transfer.
Outdated SSH and Telnet configurations.
DVWA, Mutillidae, and legacy WebDAV.
Samba misconfigurations and legacy shares.
Exposed MySQL and PostgreSQL instances.
Old protocols and daemons still found in the wild.
Default and blank passwords across services.
Permissions and settings left unnecessarily open.
A starting set of discovery commands, each with the context you need before you run it.
ping 192.168.56.101
Confirms the target is reachable on the lab network before you scan it. No response usually means a networking setting, not a firewall.
arp -a
Lists devices your machine has already talked to on the local network — useful for spotting the target's IP when you haven't set a static one.
A ten-step sequence for learners starting from zero.
The tutorials on this website are intended for cybersecurity education, authorized penetration testing, and isolated lab environments. Never test systems, networks, websites, accounts, or devices without explicit permission.
What each open port on Metasploitable 2 tells you, and where to go next.
A reference for every service exposed on the VM and what it's used to teach.
How the two labs differ, and which one fits your current skill level.
Networking choices that keep an intentionally vulnerable VM contained.
Networking, boot, and login issues learners hit most often.
The discovery, enumeration, and Linux commands used across this site, in one place.
Metasploitable 2 is an intentionally vulnerable Ubuntu-based virtual machine built for practicing penetration-testing and security-scanning techniques in an isolated lab environment.
It's used to practice network scanning, service enumeration, vulnerability identification, and web application security testing without touching a real production system.
It's safe when run entirely inside an isolated virtual network on your own computer. It is not safe to expose to a shared network or the public internet, since it's deliberately full of unpatched vulnerabilities.
Yes. Metasploitable 2 is distributed as a free virtual machine image for security education and lab practice.
Yes. VirtualBox is one of the most common ways to run Metasploitable 2, using the VM's existing virtual disk image.
Yes. Metasploitable 2 also runs under VMware Workstation, VMware Player, and Fusion with minor import steps.
The commonly documented default login is username msfadmin with password msfadmin. These credentials are intentionally weak and exist only for lab use.
Kali Linux isn't required, but it's the most common attacking machine used alongside Metasploitable 2 because it ships with the scanning and testing tools learners practice with.
Yes. It was designed specifically as an approachable, low-risk target for people learning penetration-testing fundamentals for the first time.
No. It should only run on a host-only or otherwise isolated virtual network, never bridged to a public or shared network.