Before You Start
You'll need Kali Linux and Metasploitable 2 on the same host-only network, and Metasploitable 2's IP address confirmed — see connecting Kali Linux and finding the IP address if you haven't done that yet. Every command below assumes 192.168.56.101 as the target; replace it with your actual address.
1. Confirm the Host Is Up
ping -c 4 192.168.56.101
Four replies confirm the network path works before you spend time on a full scan.
2. Run a Default Scan
nmap 192.168.56.101
Scans the 1,000 most common ports with no extra options. This is the fastest way to get a first look at what's exposed.
PORT STATE SERVICE
21/tcp open ftp
22/tcp open ssh
23/tcp open telnet
80/tcp open http
445/tcp open microsoft-ds
3. Add Version Detection
nmap -sV 192.168.56.101
Adds an extra round of probing to identify the specific software and version behind each open port — this is the step that would reveal "vsftpd 2.3.4" on port 21, for example.
4. Scan Every Port
nmap -p- 192.168.56.101
Checks all 65,535 ports instead of just the common 1,000, which matters because a couple of Metasploitable 2's services (like the databases) live outside the default range.
Reading the Results
Each line in the output means: the port number and protocol, its state (open, closed, or filtered), and the service nmap associates with that port by convention. With -sV, a version string is appended. Treat the service name as a hint, not a certainty — it's based on the port number and a light probe, not a guarantee.
Security Lesson
Port scanning is almost always the first step of any security assessment, offensive or defensive. Learning to read a scan report accurately — without over- or under-interpreting what it shows — is one of the most transferable skills in this entire lab.
Common Problems
- Scan returns nothing at all: confirm connectivity first with
ping; a scan against an unreachable host looks identical to a scan against a fully filtered one. - Results differ from a tutorial's example output: normal — exact versions and even open ports can vary slightly between Metasploitable 2 releases and hypervisor configurations.
FAQ
Do I need to scan all 65,535 ports every time?
No. A default or top-1000-ports scan is enough for most exploration. A full -p- scan is worth running once to make sure nothing unusual is hiding on a high port.
Why does nmap sometimes show a port as "filtered" instead of open or closed?
Filtered means nmap couldn't determine the state, usually because something (a firewall rule) is dropping packets rather than responding. Metasploitable 2 has no firewall enabled, so this is rare against it.
Is it legal to run nmap against any IP address I want?
No. Only scan systems you own or have explicit written permission to test, such as your own Metasploitable 2 lab. Scanning systems without authorization is illegal in most jurisdictions.