Start Learning
Metasploitable 2 Basics

Metasploitable 2 Features

Metasploitable 2 isn't a single vulnerability — it's a small collection of real, once-common services bundled onto one Ubuntu image. Here's exactly what's on it and why each piece was chosen.

Base Operating System

Metasploitable 2 runs a minimal Ubuntu 8.04 (Hardy Heron) server install. There's no desktop environment — everything is accessed either over a terminal login or through the network services it exposes. Choosing an older, unpatched base was deliberate: it guarantees the bundled software has known, well-documented weaknesses.

Network Services

  • vsftpd 2.3.4 — an FTP daemon with a well-known backdoor added to a compromised source distribution in 2011.
  • OpenSSH — an outdated build, useful for practicing version fingerprinting.
  • Telnet — cleartext remote login, still found on legacy network gear today.
  • Samba (SMB) — file sharing with permissive share configuration.
  • RPCbind / NFS — legacy remote procedure call services.
  • MySQL and PostgreSQL — both reachable over the network with weak credentials.
  • VNC — remote desktop protocol secured with a trivially weak password.

Web Applications

An Apache server hosts several intentionally vulnerable PHP applications, including DVWA (Damn Vulnerable Web Application) and Mutillidae, plus a legacy WebDAV directory. These exist specifically to teach SQL injection, cross-site scripting, and insecure file handling in a browser-based context rather than a network-service context.

What's Deliberately Missing

There's no automatic patching, no intrusion detection, no firewall rules beyond the defaults, and no logging tuned for security monitoring. That absence is itself a teaching point — it's what a genuinely neglected server looks like.

i

For port numbers and the specific lesson behind each service, see the vulnerabilities overview.