Why a Separate Attacking Machine?
Metasploitable 2 has no desktop and none of the scanning or exploitation tools installed by design — it's the target, not the toolkit. Kali Linux ships with that toolkit pre-installed (nmap, Metasploit Framework, and dozens of others), which is why it's the standard companion VM for this lab.
1. Install or Confirm Kali Linux
Download the official Kali Linux virtual machine image for your hypervisor and import it the same way you imported Metasploitable 2. If you already have Kali installed for other work, you can reuse that VM.
2. Attach the Same Host-Only Network
Open Kali's network adapter settings and set it to the identical host-only (VirtualBox) or custom/host-only (VMware) network that Metasploitable 2 uses — see network configuration if you haven't set that network up yet. Two VMs on two different host-only networks cannot reach each other even though both say "host-only."
3. Verify Connectivity
Boot both VMs. Find Metasploitable 2's address (see find the IP address), then from a Kali terminal:
ping -c 4 192.168.56.101
Replace the address with your actual target IP. Four successful replies confirm the network path works before you move on.
No replies almost always means a network adapter mismatch, not a firewall — Metasploitable 2 has no firewall enabled by default.
4. Confirm Your Tools Are Ready
nmap --version
Confirms nmap is installed and ready. It ships with Kali by default, so this should succeed immediately.
5. Run a First Scan
nmap -sV 192.168.56.101
A version-detection scan against your target. If this returns a list of open ports and service names, your lab is fully wired up.
Full walkthrough of reading these results: Nmap scanning tutorial.
Security Lesson
Separating the attacking and target roles onto distinct machines mirrors how real assessments are structured: the tester's toolkit and the environment being tested are kept apart, both to avoid cross-contamination and to keep an accurate record of what tooling produced which finding.
Common Problems
- Ping times out both directions: double-check both VMs list the exact same host-only network name in their adapter settings.
- Ping works, nmap returns nothing: some scan types need promiscuous mode allowed on the virtual adapter; set it to "Allow All" in the host-only network's advanced settings.
- IP address changed since last session: host-only networks typically assign via DHCP, so re-check the address each time you boot the target.
FAQ
Do both VMs need to be from the same hypervisor?
No. Metasploitable 2 in VirtualBox and Kali Linux in VMware (or vice versa) can still reach each other, as long as each hypervisor's host-only network is configured consistently and both VMs land on it.
Why can I ping the VM but nmap shows nothing?
Some hypervisor network settings restrict promiscuous mode or certain scan types by default. Check the adapter's advanced settings, and confirm you're scanning the address you verified with ifconfig, not an assumed one.
Does Kali Linux need internet access to work through these tutorials?
No. Every technique used against Metasploitable 2 runs entirely over the isolated host-only network. Internet access on the Kali VM is optional and unrelated to the lab working.