Resources
Metasploitable 2 Command Reference
Every command referenced across the tutorials on this site, explained rather than just listed.
Network Discovery
ping -c 4 192.168.56.101
- What It Does
- Sends four ICMP echo requests to confirm a host responds.
- When To Use It
- First check after booting both VMs, before attempting any scan.
- Expected Output
- Four "64 bytes from..." reply lines with no packet loss.
- Common Mistake
- Assuming no reply means a firewall, when it's almost always a network adapter mismatch on Metasploitable 2.
Related: Connect Kali Linux
arp -a
- What It Does
- Lists devices your machine has recently communicated with on the local network.
- When To Use It
- Useful for spotting a target's IP when you haven't set one manually.
- Expected Output
- A table of IP and MAC address pairs.
- Common Mistake
- Reading stale entries from a previous session as the current address.
Related: Find IP Address
nmap -sn 192.168.56.0/24
- What It Does
- Performs a ping sweep across an entire subnet without port scanning.
- When To Use It
- When you don't know the target's exact address yet.
- Expected Output
- A short list of hosts that responded, each with an IP and possibly a MAC vendor.
- Common Mistake
- Scanning the wrong subnet range for your specific host-only network.
Related: Find IP Address
IP Configuration
ifconfig
- What It Does
- Displays network interfaces and their assigned addresses.
- When To Use It
- Run inside Metasploitable 2 to read its own IP address.
- Expected Output
- A block per interface, including an
inetline with the IPv4 address. - Common Mistake
- Reading the address from the wrong interface (e.g. loopback instead of eth0).
Related: Find IP Address
ip addr show
- What It Does
- The modern equivalent of ifconfig on newer Linux distributions.
- When To Use It
- On recent Kali releases, where ifconfig may not be installed by default.
- Expected Output
- A numbered list of interfaces with their addresses.
- Common Mistake
- Confusing interface numbering between different VMs.
Port Scanning
nmap 192.168.56.101
- What It Does
- Scans the 1,000 most common ports with default settings.
- When To Use It
- Your first look at any new target.
- Expected Output
- A short table of port, state, and service name.
- Common Mistake
- Assuming an unscanned port is closed rather than simply outside the default range.
Related: Nmap Tutorial
nmap -sV 192.168.56.101
- What It Does
- Adds service and version detection to a standard scan.
- When To Use It
- Once you know which ports are open and want to identify what's running on them.
- Expected Output
- The same port table, with a version string appended to each service.
- Common Mistake
- Treating the version string as 100% certain — it's a probe-based guess, usually accurate but not guaranteed.
Related: Nmap Tutorial
nmap -p- 192.168.56.101
- What It Does
- Scans all 65,535 ports instead of the default top 1,000.
- When To Use It
- When you want full confidence nothing unusual is running on a high port.
- Expected Output
- A longer version of the standard port table, takes noticeably more time.
- Common Mistake
- Running this as your first scan and waiting far longer than necessary.
Related: Nmap Tutorial
Service Identification
nc -nv 192.168.56.101 21
- What It Does
- Opens a raw connection to a specific port and shows anything the service sends back.
- When To Use It
- To manually grab a service banner nmap already hinted at.
- Expected Output
- A line or two of text the service sends immediately on connection, such as an FTP welcome banner.
- Common Mistake
- Forgetting to close the connection, leaving it open unintentionally.
Related: FTP Vulnerabilities
searchsploit vsftpd 2.3.4
- What It Does
- Searches a local exploit database by keyword.
- When To Use It
- After identifying a specific service and version worth researching further.
- Expected Output
- A list of matching entries with file paths for further reading.
- Common Mistake
- Assuming every search result applies to your exact configuration without reading it.
Related: FTP Vulnerabilities
Linux Basics
whoami
- What It Does
- Prints the current user account.
- When To Use It
- Right after gaining any shell, to confirm what context you're in.
- Expected Output
- A single username, e.g.
msfadmin. - Common Mistake
- Assuming a shell has more privilege than the output actually shows.
uname -a
- What It Does
- Prints kernel and OS version information.
- When To Use It
- To confirm exactly what system you're working with.
- Expected Output
- A line including kernel version, architecture, and build date.
- Common Mistake
- Confusing kernel version with the distribution version.
ls -la
- What It Does
- Lists all files in a directory, including hidden ones, with permissions.
- When To Use It
- Whenever you need to check file permissions or ownership.
- Expected Output
- A table of permission strings, owners, sizes, and filenames.
- Common Mistake
- Overlooking hidden files (those starting with a dot) by using plain
ls.
Related: Misconfigurations