These credentials are public knowledge and exist purely for lab practice. Never reuse any of them — or a pattern like them — on a real account or system.
System Login
| Username | Password | Access |
|---|---|---|
msfadmin | msfadmin | Primary sudo-capable user, used for the console login. |
user | user | Standard low-privilege account. |
postgres | postgres | PostgreSQL service account. |
service | service | Additional low-privilege account bundled on the image. |
Application & Service Credentials
| Service | Credentials | Notes |
|---|---|---|
| MySQL | root / (blank) | Root account reachable with no password set. |
| PostgreSQL | postgres / postgres | Default install credentials left unchanged. |
| VNC | password: password | Remote desktop secured with a single weak word. |
| DVWA (web app) | admin / password | Default login for the bundled vulnerable web app. |
| Tomcat manager | tomcat / tomcat | Where present, default manager console credentials. |
Why This Matters Beyond the Lab
Default and weak credentials are consistently one of the most common root causes in real breach reports, precisely because they're this easy to overlook. Practicing on Metasploitable 2 is meant to build the habit of checking for exactly this class of issue — and the mirror-image habit, for defenders, of changing every default credential before a service goes live.
FAQ
What is the Metasploitable 2 login?
The system login is username msfadmin with password msfadmin. This is often searched as "Metasploitable login" or "Metasploitable default login" — all three refer to the same credentials, shown in full above.
Are these credentials the same on every download of Metasploitable 2?
Yes. Because the disk image is fixed and distributed as-is, every copy ships with the same accounts and passwords.
Can I change the default password?
Yes, and it's good practice once you're comfortable with the lab, using the standard Linux passwd command. It won't affect any tutorial, since guides reference the defaults only for the first login.
Is it dangerous that these credentials are public?
Only if the machine is reachable by something you don't control. Inside an isolated host-only lab, publicly known weak credentials are the entire point — they're what you're there to find.