Start Learning
Installation · VirtualBox

Metasploitable 2 VirtualBox Setup

Metasploitable 2 doesn't need a traditional install — you import its pre-built virtual disk into a new VirtualBox VM and boot it. The two things that actually determine whether the rest of your lab works are picking the right disk-attach option and setting host-only networking correctly, both covered below.

Difficulty
Beginner
Estimated Time
15 minutes
Tools
VirtualBox 7.x
Prerequisites
Metasploitable 2 image downloaded
Tested Environment
Windows, macOS, and Linux hosts
Learning Objective
A booted, network-isolated Metasploitable 2 VM
On This Page

Before You Start

You'll need VirtualBox installed on your host machine and the Metasploitable 2 archive already downloaded and extracted — see the download guide if you haven't done that yet. Extracting the archive gives you a folder containing a .vmdk virtual disk file; that's the file this guide attaches.

1. Create a New VM

In VirtualBox, click New and configure:

  • Name: Metasploitable2 (any name works, but this makes it identifiable later)
  • Type: Linux
  • Version: Ubuntu (64-bit)
  • Memory: 512–1024 MB is enough

When asked about a hard disk, choose "Do not add a virtual hard disk" — you'll attach the existing one in the next step instead of creating a new one.

2. Attach the Existing Disk

Open the new VM's Settings → Storage, select the controller, and add a hard disk. Choose "Choose an existing disk" and select the .vmdk file from the extracted Metasploitable 2 folder.

i

If you accidentally created a new virtual disk in step 1, remove it from Storage settings first so the VM doesn't have two disks attached.

3. Configure Host-Only Networking

This is the step most tutorials skip past, and the one that actually determines whether your lab is safe. In Settings → Network, set Adapter 1 to Host-Only Adapter (create a Host-Only Network first in VirtualBox's global Tools menu if none exists yet).

!

Do not select "Bridged Adapter." Bridged mode puts Metasploitable 2 directly on your real network, where any other device could reach its vulnerable services. Host-only keeps it reachable only from your own machine and other VMs on the same host-only network.

Configure your attacking VM (see the Kali Linux setup guide) with the same host-only adapter so the two machines can reach each other.

4. Boot and Log In

Start the VM. It boots to a text login prompt — there's no graphical desktop. Log in with the default credentials:

metasploitable2 login
metasploitable2 login: msfadmin
Password: msfadmin
Linux metasploitable 2.6.24-16-server ...
msfadmin@metasploitable:~$

See default credentials for the full list of accounts and why they only belong in this lab.

5. Verify the IP Address

Once logged in, run:

ifconfig

Look for the address on the host-only interface (commonly in the 192.168.56.0/24 range). That's the address you'll scan from your attacking machine.

Full walkthrough with alternate methods: find the Metasploitable 2 IP address.

Security Lesson

The networking choice you just made mirrors a real-world control: network segmentation. Production environments isolate sensitive or fragile systems on separate network segments precisely so a compromise in one place can't automatically reach everything else. Host-only mode is a small-scale version of the same principle — it's the reason a vulnerable machine on your laptop never becomes everyone's problem.

Common Problems

  • VM won't power on / VT-x error: enable virtualization (Intel VT-x / AMD-V) in your host's BIOS or UEFI settings.
  • No host-only network available: create one manually under VirtualBox → Tools → Network → Host-Only Networks before assigning it to the VM.
  • Can't reach the VM from Kali: confirm both VMs use the same host-only network, not two different ones.
  • Login fails immediately: credentials are case-sensitive; retype rather than assuming a copy-paste issue.

For anything not covered here, see the full troubleshooting guide.

FAQ

How do I install Metasploitable 2 in VirtualBox?

Create a new VM (type Linux, version Ubuntu 64-bit), attach the downloaded .vmdk disk instead of creating a new one, set the network adapter to Host-Only, then boot and log in with msfadmin/msfadmin. See the five detailed steps above.

Do I need to create a new virtual disk in VirtualBox?

No. Metasploitable 2 already includes a pre-built .vmdk disk image. Attach that existing file instead of creating a new virtual hard disk.

Why choose Ubuntu as the guest OS type?

Metasploitable 2 is built on an Ubuntu base, so selecting Linux / Ubuntu (64-bit) gives VirtualBox the closest matching default settings, even though exact OS detection isn't required for it to run.

What if the VM boots but I can't log in?

Use the default credentials username msfadmin and password msfadmin. If that fails, the disk image may not have finished importing correctly — re-check the download guide.