Before You Start
You'll need VMware installed and the Metasploitable 2 archive already downloaded and extracted — see the download guide if you haven't done that yet. You should have a .vmdk disk file (and possibly a .vmx file) from the extracted folder.
1. Create a New VM
If a .vmx file was included in the download, you can often open it directly with File → Open. Otherwise, choose Create a New Virtual Machine and select "I will install the operating system later" with a guest OS type of Linux → Ubuntu (64-bit).
2. Attach the Existing Disk
When prompted to create a virtual disk, choose "Use an existing virtual disk" and select the .vmdk file from the extracted folder instead of letting VMware create a new one.
If VMware offers to "convert" or "upgrade" the disk format, accept the default — it doesn't change the VM's contents, only the on-disk container format.
3. Configure Host-Only Networking
Open the VM's network adapter settings and set it to Host-Only (in VMware Fusion this may be labeled a custom private network). Configure your attacking VM with the same setting so both machines land on the same isolated segment.
Avoid "Bridged" mode. It places Metasploitable 2 directly on your physical network, where any nearby device could reach its vulnerable services.
4. Boot and Log In
Power on the VM. It boots to a text login prompt. Log in with the default credentials:
Password: msfadmin
Linux metasploitable 2.6.24-16-server ...
msfadmin@metasploitable:~$
Full account list on the default credentials page.
5. Verify the IP Address
ifconfig
Note the address on the host-only interface. You'll use it as the scan target from your attacking machine.
More detail: find the Metasploitable 2 IP address.
Security Lesson
Regardless of hypervisor, the control that keeps this lab safe is the same: network segmentation. The specific menu you clicked to enable it doesn't matter — what matters is that a vulnerable system never shares a broadcast domain with anything you're not prepared to risk.
Common Problems
- VM won't power on: enable Intel VT-x / AMD-V in your host BIOS/UEFI.
- No custom/host-only network listed: open VMware's Virtual Network Editor and add one before assigning it to the VM.
- Kali can't reach Metasploitable 2: confirm both VMs use the identical named virtual network, not two separately created ones.
See the full troubleshooting guide for anything else.
FAQ
Do I need VMware Workstation Pro, or does Player work?
Player or Fusion work fine for this. Metasploitable 2 doesn't need any Pro-only feature — snapshots and basic networking are enough.
Can I convert the .vmdk to a new VM automatically?
In most VMware versions, choosing "Open" on the .vmx file (if included) or creating a new VM and selecting the existing .vmdk when prompted for a disk both work. Either path uses the same disk image.
Does Metasploitable 2 need VMware Tools installed?
No. VMware Tools improve integration (shared folders, better display), but nothing in this lab depends on them.