Start Learning
Metasploitable 2 Basics

Metasploitable 2 FAQ

The questions learners ask most often, answered directly, with links to the full guide for anything that needs more depth.

What is Metasploitable?

"Metasploitable" almost always refers to Metasploitable 2 today — the original Metasploitable 1 is no longer distributed, and Metasploitable 3 is a separate, newer project with a different build process. You may also see it misspelled as "Metasplotable," "Metaspoitable," or "Metaexploitable" — all of these refer to the same virtual machine. See What Is Metasploitable 2? for the full explanation.

What is Metasploitable 2?

Metasploitable 2 is an intentionally vulnerable Ubuntu-based virtual machine built for practicing penetration-testing and security-scanning techniques in an isolated lab environment.

What is a Metasploitable VM?

It's a full virtual machine (VM) — a complete, self-contained computer running inside a hypervisor like VirtualBox or VMware — rather than an application you install on your existing operating system. See system requirements for what it takes to run one.

Where can I download Metasploitable 2?

From a reputable, well-known distribution point such as SourceForge. See the full download guide for the file format, size, and verification steps.

What is the default Metasploitable login?

The commonly documented default is username msfadmin with password msfadmin. See the full default credentials list, which also covers the database and web-app logins.

How do I install Metasploitable 2 in VirtualBox?

Create a new VM, attach the downloaded .vmdk disk instead of creating a new one, and set the network adapter to host-only before booting. Full walkthrough: Metasploitable 2 VirtualBox setup.

Is there a Metasploitable 2 walkthrough available?

Yes — see the tutorials hub for the full list, or jump straight to the Nmap scanning walkthrough for a hands-on first session.

Is Metasploitable 2 free?

Yes. It's distributed as a free virtual machine image for security education and lab practice.

Is Metasploitable 2 safe to use?

It's safe when run entirely inside an isolated virtual network on your own computer. It should never be exposed to a shared network or the public internet.

Do I need Kali Linux for Metasploitable 2?

It isn't required, but it's the most common attacking machine used alongside it because it ships with the scanning and testing tools learners practice with. See Kali Linux setup.

Can Metasploitable 2 run on VirtualBox and VMware?

Yes, on both, from the same downloaded file. See the VirtualBox guide or the VMware guide.

Why can't I connect to Metasploitable 2 from my attacking VM?

This is almost always a networking mismatch — both VMs need to be on the exact same host-only network. See network configuration and troubleshooting.

What's the difference between Metasploitable 2 and Metasploitable 3?

Metasploitable 3 is a newer, more complex project built from a provisioning template with both Linux and Windows targets. Metasploitable 2 is a single fixed image, which makes it easier for beginners to get running.

Is Metasploitable 2 suitable for complete beginners?

Yes. It was purpose-built as an approachable, low-risk target for people learning penetration-testing fundamentals for the first time.

What should I learn before using Metasploitable 2?

Basic familiarity with virtual machines and the Linux command line helps. Beyond that, the beginner learning path assumes no prior experience.

Does Metasploitable 2 get security updates?

No, and that's intentional. Its vulnerabilities stay fixed and documented for consistent learning, which is exactly why it must stay isolated from any real or shared network.

What tools do I need besides Metasploitable 2 itself?

A hypervisor (VirtualBox or VMware) and, eventually, an attacking VM like Kali Linux. See the command reference for the tools used throughout this site.