Start Learning
Metasploitable 2 Basics

Metasploitable 2 Default Credentials

Metasploitable 2 ships with several accounts and services protected by intentionally weak or default credentials. Here's the full documented list, and why none of these should ever appear on a real system.

!

These credentials are public knowledge and exist purely for lab practice. Never reuse any of them — or a pattern like them — on a real account or system.

System Login

UsernamePasswordAccess
msfadminmsfadminPrimary sudo-capable user, used for the console login.
useruserStandard low-privilege account.
postgrespostgresPostgreSQL service account.
serviceserviceAdditional low-privilege account bundled on the image.

Application & Service Credentials

ServiceCredentialsNotes
MySQLroot / (blank)Root account reachable with no password set.
PostgreSQLpostgres / postgresDefault install credentials left unchanged.
VNCpassword: passwordRemote desktop secured with a single weak word.
DVWA (web app)admin / passwordDefault login for the bundled vulnerable web app.
Tomcat managertomcat / tomcatWhere present, default manager console credentials.

Why This Matters Beyond the Lab

Default and weak credentials are consistently one of the most common root causes in real breach reports, precisely because they're this easy to overlook. Practicing on Metasploitable 2 is meant to build the habit of checking for exactly this class of issue — and the mirror-image habit, for defenders, of changing every default credential before a service goes live.

FAQ

What is the Metasploitable 2 login?

The system login is username msfadmin with password msfadmin. This is often searched as "Metasploitable login" or "Metasploitable default login" — all three refer to the same credentials, shown in full above.

Are these credentials the same on every download of Metasploitable 2?

Yes. Because the disk image is fixed and distributed as-is, every copy ships with the same accounts and passwords.

Can I change the default password?

Yes, and it's good practice once you're comfortable with the lab, using the standard Linux passwd command. It won't affect any tutorial, since guides reference the defaults only for the first login.

Is it dangerous that these credentials are public?

Only if the machine is reachable by something you don't control. Inside an isolated host-only lab, publicly known weak credentials are the entire point — they're what you're there to find.