Start Learning
Cybersecurity Practice Lab

Metasploitable 2: Complete Penetration Testing Lab Guide

Metasploitable 2 (often just called Metasploitable) is an intentionally vulnerable Linux virtual machine (VM) built for practicing penetration testing in a controlled environment. This hub walks you through downloading it, installing it, scanning it, and understanding the security lessons behind every exposed service — step by step, with no assumed experience.

Beginner Friendly•Lab Based•Step-by-Step Guides

kali@lab-vm: ~
root@kali:~# nmap 192.168.56.101

Starting network discovery on host-only lab network...
PORTSTATESERVICE
21/tcpopenftp
22/tcpopenssh
23/tcpopentelnet
80/tcpopenhttp
445/tcpopenmicrosoft-ds

# Scan complete. See the enumeration guide to interpret these results.

What Is Metasploitable 2?

Metasploitable 2 is a deliberately vulnerable Ubuntu Linux virtual machine, distributed as a free VM image for security training. Unlike a production server, every service on it was left intentionally outdated or misconfigured so learners have something safe and legal to scan, enumerate, and exploit inside their own lab — instead of practicing on a system they don't own.

Because the vulnerabilities are known and documented, Metasploitable 2 works as a consistent baseline: the same weak FTP daemon, the same exposed database, and the same web applications appear whether you're following a tutorial today or one written years ago. That makes it one of the most widely used starting points for people learning:

Network Scanning

Discovering live hosts and open ports on an isolated lab network.

Service Enumeration

Identifying what software is running behind each open port and why it matters.

Vulnerability Identification

Recognizing outdated software versions and unsafe default configurations.

Web Application Security

Practicing on bundled vulnerable apps like DVWA and Mutillidae.

Learn About Metasploitable 2 →

Start Your Metasploitable 2 Lab

Four stages take you from a blank VM to your first scan.

01

Download Metasploitable 2

Get the VM image and verify what you're downloading before importing it.

Download Guide →
02

Install the Virtual Machine

Import the disk image into VirtualBox or VMware and boot it for the first time.

Installation Guide →
03

Connect Your Kali Linux Lab

Place both machines on the same isolated, host-only network.

Kali Linux Setup →
04

Start Security Testing

Run your first scan and begin working through the vulnerability guides.

Nmap Guide →

Why Use Metasploitable 2?

Safe Lab Learning

Practice cybersecurity techniques inside an isolated lab environment, with no risk to a real network.

Built for Security Training

Every exposed service was chosen deliberately, so what you find is meant to be found.

Beginner Friendly

Structured, step-by-step tutorials that assume no prior penetration-testing experience.

Multiple Security Topics

Learn networking, Linux security, web security, enumeration, and vulnerability assessment in one place.

Popular Metasploitable 2 Guides

The six guides most learners read first.

How to Install Metasploitable 2

The full path from downloading the image to booting your first lab session.

7 min readRead the Guide →

Metasploitable 2 VirtualBox Setup

Import the disk image and configure a host-only network in VirtualBox.

6 min readRead the Guide →

Metasploitable 2 VMware Setup

Run Metasploitable 2 under VMware Workstation, Player, or Fusion.

6 min readRead the Guide →

Connect Kali Linux to Metasploitable 2

Put both machines on the same isolated network so scans can actually reach the target.

8 min readRead the Guide →

Find the Metasploitable 2 IP Address

Three reliable ways to find the target's IP before you scan it.

4 min readRead the Guide →

Metasploitable 2 Default Login Credentials

The documented default username and password, and why they only belong in a lab.

3 min readRead the Guide →

Learn Metasploitable 2 Step by Step

Every stage pairs an offensive skill with the defensive lesson behind it.

  1. 1

    Setup

    Install the VM and configure isolated networking so your lab can't reach, or be reached by, anything outside it.

  2. 2

    Discovery

    Find the target on the network and confirm it's reachable before scanning further.

  3. 3

    Enumeration

    Identify exactly which services are exposed and what versions they're running.

  4. 4

    Vulnerability Analysis

    Match enumerated services against known weaknesses and insecure configurations.

  5. 5

    Controlled Lab Testing

    Apply what you've found inside your own isolated environment, methodically and safely.

  6. 6

    Security Lessons

    Understand why each vulnerability exists and how defenders reduce that class of risk in production.

Essential Lab Commands

A starting set of discovery commands, each with the context you need before you run it.

ping 192.168.56.101

Confirms the target is reachable on the lab network before you scan it. No response usually means a networking setting, not a firewall.

arp -a

Lists devices your machine has already talked to on the local network — useful for spotting the target's IP when you haven't set a static one.

ifconfig

Run inside Metasploitable 2 itself to read its assigned IP address directly from the guest.

ip addr show

The modern equivalent of ifconfig on newer Kali releases; shows every interface and its address.

nmap -sV 192.168.56.101

Scans common ports and attempts to identify the software version behind each one — the starting point for enumeration.

nmap -p- 192.168.56.101

Scans all 65,535 ports instead of the default top-1000, so nothing unusual is missed.

uname -a

Prints the kernel and OS version once you're inside a shell, useful for confirming what you're working with.

whoami

Confirms which user context a shell is running under after gaining access.

View Command Reference →

New to Ethical Hacking? Start Here.

A ten-step sequence for learners starting from zero.

  1. Understand Virtual Machines
  2. Install Kali Linux
  3. Install Metasploitable 2
  4. Configure an Isolated Network
  5. Learn Basic Linux Commands
  6. Understand TCP/IP and Ports
  7. Learn Nmap
  8. Learn Service Enumeration
  9. Study Vulnerabilities
  10. Practice in the Lab

Start Beginner Path

!

Practice Only in Authorized Environments

The tutorials on this website are intended for cybersecurity education, authorized penetration testing, and isolated lab environments. Never test systems, networks, websites, accounts, or devices without explicit permission.

Latest Tutorials

Metasploitable 2 Nmap Scan Explained, Port by Port

What each open port on Metasploitable 2 tells you, and where to go next.

By M2 Lab Team · Updated Aug 2026

Common Ports and Services in Metasploitable 2

A reference for every service exposed on the VM and what it's used to teach.

By M2 Lab Team · Updated Aug 2026

Metasploitable 2 vs. Metasploitable 3

How the two labs differ, and which one fits your current skill level.

By M2 Lab Team · Updated Aug 2026

How to Build a Safe Penetration Testing Lab at Home

Networking choices that keep an intentionally vulnerable VM contained.

By M2 Lab Team · Updated Aug 2026

Common Metasploitable 2 Setup Problems and Fixes

Networking, boot, and login issues learners hit most often.

By M2 Lab Team · Updated Aug 2026

Metasploitable 2 Command Cheat Sheet

The discovery, enumeration, and Linux commands used across this site, in one place.

By M2 Lab Team · Updated Aug 2026

Browse All Tutorials

Frequently Asked Questions

What is Metasploitable 2?

Metasploitable 2 is an intentionally vulnerable Ubuntu-based virtual machine built for practicing penetration-testing and security-scanning techniques in an isolated lab environment.

What is Metasploitable 2 used for?

It's used to practice network scanning, service enumeration, vulnerability identification, and web application security testing without touching a real production system.

Is Metasploitable 2 safe to use?

It's safe when run entirely inside an isolated virtual network on your own computer. It is not safe to expose to a shared network or the public internet, since it's deliberately full of unpatched vulnerabilities.

Is Metasploitable 2 free?

Yes. Metasploitable 2 is distributed as a free virtual machine image for security education and lab practice.

Can Metasploitable 2 run on VirtualBox?

Yes. VirtualBox is one of the most common ways to run Metasploitable 2, using the VM's existing virtual disk image.

Can Metasploitable 2 run on VMware?

Yes. Metasploitable 2 also runs under VMware Workstation, VMware Player, and Fusion with minor import steps.

What are the default Metasploitable 2 credentials?

The commonly documented default login is username msfadmin with password msfadmin. These credentials are intentionally weak and exist only for lab use.

Do I need Kali Linux for Metasploitable 2?

Kali Linux isn't required, but it's the most common attacking machine used alongside Metasploitable 2 because it ships with the scanning and testing tools learners practice with.

Is Metasploitable 2 suitable for beginners?

Yes. It was designed specifically as an approachable, low-risk target for people learning penetration-testing fundamentals for the first time.

Should Metasploitable 2 be connected directly to the internet?

No. It should only run on a host-only or otherwise isolated virtual network, never bridged to a public or shared network.