Before You Start
You'll need VirtualBox installed on your host machine and the Metasploitable 2 archive already downloaded and extracted — see the download guide if you haven't done that yet. Extracting the archive gives you a folder containing a .vmdk virtual disk file; that's the file this guide attaches.
1. Create a New VM
In VirtualBox, click New and configure:
- Name:
Metasploitable2(any name works, but this makes it identifiable later) - Type: Linux
- Version: Ubuntu (64-bit)
- Memory: 512–1024 MB is enough
When asked about a hard disk, choose "Do not add a virtual hard disk" — you'll attach the existing one in the next step instead of creating a new one.
2. Attach the Existing Disk
Open the new VM's Settings → Storage, select the controller, and add a hard disk. Choose "Choose an existing disk" and select the .vmdk file from the extracted Metasploitable 2 folder.
If you accidentally created a new virtual disk in step 1, remove it from Storage settings first so the VM doesn't have two disks attached.
3. Configure Host-Only Networking
This is the step most tutorials skip past, and the one that actually determines whether your lab is safe. In Settings → Network, set Adapter 1 to Host-Only Adapter (create a Host-Only Network first in VirtualBox's global Tools menu if none exists yet).
Do not select "Bridged Adapter." Bridged mode puts Metasploitable 2 directly on your real network, where any other device could reach its vulnerable services. Host-only keeps it reachable only from your own machine and other VMs on the same host-only network.
Configure your attacking VM (see the Kali Linux setup guide) with the same host-only adapter so the two machines can reach each other.
4. Boot and Log In
Start the VM. It boots to a text login prompt — there's no graphical desktop. Log in with the default credentials:
Password: msfadmin
Linux metasploitable 2.6.24-16-server ...
msfadmin@metasploitable:~$
See default credentials for the full list of accounts and why they only belong in this lab.
5. Verify the IP Address
Once logged in, run:
ifconfig
Look for the address on the host-only interface (commonly in the 192.168.56.0/24 range). That's the address you'll scan from your attacking machine.
Full walkthrough with alternate methods: find the Metasploitable 2 IP address.
Security Lesson
The networking choice you just made mirrors a real-world control: network segmentation. Production environments isolate sensitive or fragile systems on separate network segments precisely so a compromise in one place can't automatically reach everything else. Host-only mode is a small-scale version of the same principle — it's the reason a vulnerable machine on your laptop never becomes everyone's problem.
Common Problems
- VM won't power on / VT-x error: enable virtualization (Intel VT-x / AMD-V) in your host's BIOS or UEFI settings.
- No host-only network available: create one manually under VirtualBox → Tools → Network → Host-Only Networks before assigning it to the VM.
- Can't reach the VM from Kali: confirm both VMs use the same host-only network, not two different ones.
- Login fails immediately: credentials are case-sensitive; retype rather than assuming a copy-paste issue.
For anything not covered here, see the full troubleshooting guide.
FAQ
How do I install Metasploitable 2 in VirtualBox?
Create a new VM (type Linux, version Ubuntu 64-bit), attach the downloaded .vmdk disk instead of creating a new one, set the network adapter to Host-Only, then boot and log in with msfadmin/msfadmin. See the five detailed steps above.
Do I need to create a new virtual disk in VirtualBox?
No. Metasploitable 2 already includes a pre-built .vmdk disk image. Attach that existing file instead of creating a new virtual hard disk.
Why choose Ubuntu as the guest OS type?
Metasploitable 2 is built on an Ubuntu base, so selecting Linux / Ubuntu (64-bit) gives VirtualBox the closest matching default settings, even though exact OS detection isn't required for it to run.
What if the VM boots but I can't log in?
Use the default credentials username msfadmin and password msfadmin. If that fails, the disk image may not have finished importing correctly — re-check the download guide.