Start Learning
Resources

Metasploitable 2 Command Reference

Every command referenced across the tutorials on this site, explained rather than just listed.

Network Discovery

ping -c 4 192.168.56.101

What It Does
Sends four ICMP echo requests to confirm a host responds.
When To Use It
First check after booting both VMs, before attempting any scan.
Expected Output
Four "64 bytes from..." reply lines with no packet loss.
Common Mistake
Assuming no reply means a firewall, when it's almost always a network adapter mismatch on Metasploitable 2.

Related: Connect Kali Linux

arp -a

What It Does
Lists devices your machine has recently communicated with on the local network.
When To Use It
Useful for spotting a target's IP when you haven't set one manually.
Expected Output
A table of IP and MAC address pairs.
Common Mistake
Reading stale entries from a previous session as the current address.

Related: Find IP Address

nmap -sn 192.168.56.0/24

What It Does
Performs a ping sweep across an entire subnet without port scanning.
When To Use It
When you don't know the target's exact address yet.
Expected Output
A short list of hosts that responded, each with an IP and possibly a MAC vendor.
Common Mistake
Scanning the wrong subnet range for your specific host-only network.

Related: Find IP Address

IP Configuration

ifconfig

What It Does
Displays network interfaces and their assigned addresses.
When To Use It
Run inside Metasploitable 2 to read its own IP address.
Expected Output
A block per interface, including an inet line with the IPv4 address.
Common Mistake
Reading the address from the wrong interface (e.g. loopback instead of eth0).

Related: Find IP Address

ip addr show

What It Does
The modern equivalent of ifconfig on newer Linux distributions.
When To Use It
On recent Kali releases, where ifconfig may not be installed by default.
Expected Output
A numbered list of interfaces with their addresses.
Common Mistake
Confusing interface numbering between different VMs.

Port Scanning

nmap 192.168.56.101

What It Does
Scans the 1,000 most common ports with default settings.
When To Use It
Your first look at any new target.
Expected Output
A short table of port, state, and service name.
Common Mistake
Assuming an unscanned port is closed rather than simply outside the default range.

Related: Nmap Tutorial

nmap -sV 192.168.56.101

What It Does
Adds service and version detection to a standard scan.
When To Use It
Once you know which ports are open and want to identify what's running on them.
Expected Output
The same port table, with a version string appended to each service.
Common Mistake
Treating the version string as 100% certain — it's a probe-based guess, usually accurate but not guaranteed.

Related: Nmap Tutorial

nmap -p- 192.168.56.101

What It Does
Scans all 65,535 ports instead of the default top 1,000.
When To Use It
When you want full confidence nothing unusual is running on a high port.
Expected Output
A longer version of the standard port table, takes noticeably more time.
Common Mistake
Running this as your first scan and waiting far longer than necessary.

Related: Nmap Tutorial

Service Identification

nc -nv 192.168.56.101 21

What It Does
Opens a raw connection to a specific port and shows anything the service sends back.
When To Use It
To manually grab a service banner nmap already hinted at.
Expected Output
A line or two of text the service sends immediately on connection, such as an FTP welcome banner.
Common Mistake
Forgetting to close the connection, leaving it open unintentionally.

Related: FTP Vulnerabilities

searchsploit vsftpd 2.3.4

What It Does
Searches a local exploit database by keyword.
When To Use It
After identifying a specific service and version worth researching further.
Expected Output
A list of matching entries with file paths for further reading.
Common Mistake
Assuming every search result applies to your exact configuration without reading it.

Related: FTP Vulnerabilities

Linux Basics

whoami

What It Does
Prints the current user account.
When To Use It
Right after gaining any shell, to confirm what context you're in.
Expected Output
A single username, e.g. msfadmin.
Common Mistake
Assuming a shell has more privilege than the output actually shows.

uname -a

What It Does
Prints kernel and OS version information.
When To Use It
To confirm exactly what system you're working with.
Expected Output
A line including kernel version, architecture, and build date.
Common Mistake
Confusing kernel version with the distribution version.

ls -la

What It Does
Lists all files in a directory, including hidden ones, with permissions.
When To Use It
Whenever you need to check file permissions or ownership.
Expected Output
A table of permission strings, owners, sizes, and filenames.
Common Mistake
Overlooking hidden files (those starting with a dot) by using plain ls.

Related: Misconfigurations