What Is Metasploitable 2?
If you landed here just searching "download Metasploitable" without much context: Metasploitable 2 is a free, intentionally vulnerable Ubuntu Linux virtual machine (VM), built for practicing penetration testing and security scanning in a safe, isolated lab. It isn't software you install onto your existing operating system — it's an entire pre-configured computer that runs inside a hypervisor like VirtualBox or VMware. Every service on it, from its FTP daemon to its bundled web applications, was left deliberately outdated or misconfigured so learners have something legal and consistent to scan, enumerate, and study. For the full explanation of what it is and why it's used, see What Is Metasploitable 2?
A Brief History of the Release
Metasploitable 2 was built by Rapid7 as a companion training target for the Metasploit Framework, so people learning the framework would have a legal, predictable system to point it at. It's based on a minimal Ubuntu 8.04 server install and hasn't changed since its release, which is precisely what makes it useful: a tutorial written years ago still describes the same vulnerable services you'll find today. It has no relationship to your operating system's version or update history — downloading and running it doesn't affect your host machine in any way, provided it stays inside an isolated VM.
What You're Actually Downloading
The Metasploitable 2 release is a single compressed archive, typically between 800 MB and 1 GB, containing a virtual disk file in .vmdk format along with a handful of supporting virtual-machine configuration files. Older mirrors sometimes label the same file "Metasploitable Linux 2.0" — it's the identical image under a slightly different name.
There's nothing to run or install from inside the archive itself. The disk image already contains a fully configured, bootable Ubuntu 8.04 system with every vulnerable service pre-installed. Your only job is to extract the archive and point a hypervisor at the disk file inside it.
| Detail | Value |
|---|---|
| Archive format | .zip |
| Disk format | .vmdk (read natively by both VirtualBox and VMware) |
| Approximate download size | 800 MB–1 GB compressed |
| Extracted size | ~8 GB |
| Free disk space needed | At least 10 GB to extract and run comfortably |
| Cost | Free |
Where to Download Metasploitable 2
Get it from a well-known, reputable distribution point rather than a random forum link or unfamiliar third-party mirror — the same due diligence you'd apply to any disk image you plan to boot. The Metasploitable project distribution page on SourceForge has hosted the Metasploitable 2 release for years:
Metasploitable 2 (.zip)
~870 MB · Hosted on SourceForge · Free
This link leaves metasploitable2.com. Confirm you're on the Metasploitable project page (URL starts with sourceforge.net/projects/metasploitable) before downloading, and verify the archive as described in Security Precautions below.
Primary Sources
Use the original project and vendor documentation to verify the image's purpose and safe lab setup:
- Metasploitable 2 project distribution on SourceForge
- Rapid7: Metasploitable 2 Exploitability Guide
- OWASP Vulnerable Web Applications Directory: Metasploitable 2
This site doesn't host or mirror the file itself. If a checksum is published alongside the download, verify it after downloading and before importing.
Metasploitable 2 Download for VirtualBox vs. VMware
There's no separate "VirtualBox version" or "VMware version" to choose between — it's the same single .zip archive either way. The disk image is stored in .vmdk format, which both hypervisors read natively. Once you've downloaded and extracted it:
- For VirtualBox, follow the Metasploitable 2 VirtualBox setup guide to create a new VM and attach the existing disk.
- For VMware Workstation, Player, or Fusion, follow the Metasploitable 2 VMware setup guide instead.
Both guides cover the one step that actually matters after import: configuring isolated host-only networking before you ever boot the machine.
Downloading Metasploitable 2 in Other Languages
The download and setup process is identical no matter what language you read in, including for learners searching descargar Metasploitable 2. The file itself has no language setting — it's a Linux command-line environment, and every command used across this site (ifconfig, nmap, and so on) works the same regardless of your system's display language. There's no separate localized build to look for, and no need to find a "Spanish version" or any other translated release; the archive, the disk image, and the vulnerable services inside it are exactly the same file everyone downloads.
After You Download: Next Steps
Once the archive is extracted, the remaining steps are the same regardless of which hypervisor you chose. Each one links to a full walkthrough if you want more detail than the summary below:
- Extract the
.ziparchive to a folder on your host machine that you control. - Import the
.vmdkfile into VirtualBox or VMware — you're attaching an existing disk, not building a new VM from scratch. - Set the network adapter to host-only before the first boot — see network configuration for why this matters and exactly how to configure it.
- Boot the VM and log in using the default credentials.
- Confirm its IP address and run your first scan — see the Nmap scanning tutorial to start reading real results instead of just following steps.
From there, the beginner learning path lays out the fuller sequence, from basic networking concepts through your first documented vulnerability finding.
Common Download Problems
- Download is very slow: file sizes around 800 MB–1 GB can take a while on a slow connection; a mirror closer to your region (where offered) usually helps. There's no faster "lite" version to look for — the size comes from the disk image itself, not from bundled extras.
- Archive won't extract / reports corruption: the download likely didn't complete fully — clear it and download again rather than retrying the same partial file. Extraction tools generally fail loudly on a truncated archive rather than silently producing a broken VM, so this is usually easy to catch early.
- Antivirus or browser flags the file: expected behavior, covered in the FAQ below — it does not mean the download is malicious.
- Can't find a "VirtualBox" or "VMware" specific download: there isn't one; see VirtualBox vs. VMware Download above.
- Browser blocks the download or warns about the file type: a normal reaction to a large, unfamiliar .zip. Confirm the download source is the Metasploitable project page, then allow it — the warning is generic, not specific evidence of a problem with this particular file.
Security Precautions Before Importing
None of these steps are unique to Metasploitable 2 — they're the same due diligence worth applying to any virtual machine image you download from the internet, vulnerable-by-design or not.
- Verify the checksum. If one is published alongside the file, compare it after downloading and before extracting, so you know the archive wasn't corrupted or tampered with in transit.
- Control where it lands. Extract it into a location on your host you control, not a shared or network drive other users or processes can reach.
- Isolate the network before first boot. Only ever boot it with a host-only or internal network adapter — see network configuration — configured before you power the VM on for the first time, not after.
- Treat the VM as untrusted by design. It's supposed to be vulnerable, so isolate it accordingly, and never run it on a host connected to a network segment with sensitive data or other production systems.
FAQ
Where can I download Metasploitable 2?
From a reputable, well-known distribution point such as SourceForge, where the Metasploitable project has been hosted for years. Avoid random forum links or third-party mirrors of unknown origin.
Is the Metasploitable 2 download free?
Yes. Metasploitable 2 is, and always has been, a free virtual machine image released for security education and lab practice.
What file format is the Metasploitable 2 download?
A compressed .zip archive of roughly 800 MB to 1 GB, containing a .vmdk virtual disk file plus a small set of supporting VM configuration files.
Is there a separate Metasploitable 2 download for VirtualBox?
No. It's the same archive either way. VirtualBox and VMware both read the same .vmdk disk format, so there's nothing VirtualBox-specific to download separately.
Can I download Metasploitable 2 for VMware instead?
Yes, using that same single download. See the VMware setup guide for the import steps once you have the file.
How do I download Metasploitable 2 if I don't read English? (Cómo descargar Metasploitable 2)
The download process is identical regardless of language, since the file itself has no language setting, only a Linux command-line interface. The steps on this page apply the same way to Spanish-speaking learners searching descargar Metasploitable 2, or any other language.
Why does my antivirus flag the Metasploitable 2 download?
This is expected and not a sign of a bad download. Metasploitable 2 intentionally contains outdated, vulnerable software, which antivirus and endpoint tools are designed to flag. Extract and run it only inside an isolated VM, never on your host filesystem directly.
Is "Metasploitable Linux 2.0" the same file as Metasploitable 2?
Yes. Metasploitable 2 is sometimes labeled Metasploitable Linux 2.0 in older archive names or mirror listings, but it refers to the same virtual machine image.
What do I do after downloading Metasploitable 2?
Extract the archive, then import the .vmdk file into VirtualBox or VMware and configure host-only networking before booting it for the first time.
Is it safe to download Metasploitable 2?
Downloading it is safe from a reputable source. Running it is only safe inside an isolated host-only virtual network, never on a shared network or exposed to the internet, since the machine is intentionally full of unpatched vulnerabilities.