Base Operating System
Metasploitable 2 runs a minimal Ubuntu 8.04 (Hardy Heron) server install. There's no desktop environment — everything is accessed either over a terminal login or through the network services it exposes. Choosing an older, unpatched base was deliberate: it guarantees the bundled software has known, well-documented weaknesses.
Network Services
- vsftpd 2.3.4 — an FTP daemon with a well-known backdoor added to a compromised source distribution in 2011.
- OpenSSH — an outdated build, useful for practicing version fingerprinting.
- Telnet — cleartext remote login, still found on legacy network gear today.
- Samba (SMB) — file sharing with permissive share configuration.
- RPCbind / NFS — legacy remote procedure call services.
- MySQL and PostgreSQL — both reachable over the network with weak credentials.
- VNC — remote desktop protocol secured with a trivially weak password.
Web Applications
An Apache server hosts several intentionally vulnerable PHP applications, including DVWA (Damn Vulnerable Web Application) and Mutillidae, plus a legacy WebDAV directory. These exist specifically to teach SQL injection, cross-site scripting, and insecure file handling in a browser-based context rather than a network-service context.
What's Deliberately Missing
There's no automatic patching, no intrusion detection, no firewall rules beyond the defaults, and no logging tuned for security monitoring. That absence is itself a teaching point — it's what a genuinely neglected server looks like.
For port numbers and the specific lesson behind each service, see the vulnerabilities overview.