Start Learning
Installation · VMware

Metasploitable 2 VMware Setup

VMware Workstation, Player, and Fusion all run Metasploitable 2 the same way: create a VM, attach the existing disk image instead of a new one, and lock the network adapter to a host-only or custom internal network.

Difficulty
Beginner
Estimated Time
15 minutes
Tools
VMware Workstation, Player, or Fusion
Prerequisites
Metasploitable 2 image downloaded
Tested Environment
Windows, macOS, and Linux hosts
Learning Objective
A booted, network-isolated Metasploitable 2 VM
On This Page

Before You Start

You'll need VMware installed and the Metasploitable 2 archive already downloaded and extracted — see the download guide if you haven't done that yet. You should have a .vmdk disk file (and possibly a .vmx file) from the extracted folder.

1. Create a New VM

If a .vmx file was included in the download, you can often open it directly with File → Open. Otherwise, choose Create a New Virtual Machine and select "I will install the operating system later" with a guest OS type of Linux → Ubuntu (64-bit).

2. Attach the Existing Disk

When prompted to create a virtual disk, choose "Use an existing virtual disk" and select the .vmdk file from the extracted folder instead of letting VMware create a new one.

i

If VMware offers to "convert" or "upgrade" the disk format, accept the default — it doesn't change the VM's contents, only the on-disk container format.

3. Configure Host-Only Networking

Open the VM's network adapter settings and set it to Host-Only (in VMware Fusion this may be labeled a custom private network). Configure your attacking VM with the same setting so both machines land on the same isolated segment.

!

Avoid "Bridged" mode. It places Metasploitable 2 directly on your physical network, where any nearby device could reach its vulnerable services.

4. Boot and Log In

Power on the VM. It boots to a text login prompt. Log in with the default credentials:

metasploitable2 login
metasploitable2 login: msfadmin
Password: msfadmin
Linux metasploitable 2.6.24-16-server ...
msfadmin@metasploitable:~$

Full account list on the default credentials page.

5. Verify the IP Address

ifconfig

Note the address on the host-only interface. You'll use it as the scan target from your attacking machine.

More detail: find the Metasploitable 2 IP address.

Security Lesson

Regardless of hypervisor, the control that keeps this lab safe is the same: network segmentation. The specific menu you clicked to enable it doesn't matter — what matters is that a vulnerable system never shares a broadcast domain with anything you're not prepared to risk.

Common Problems

  • VM won't power on: enable Intel VT-x / AMD-V in your host BIOS/UEFI.
  • No custom/host-only network listed: open VMware's Virtual Network Editor and add one before assigning it to the VM.
  • Kali can't reach Metasploitable 2: confirm both VMs use the identical named virtual network, not two separately created ones.

See the full troubleshooting guide for anything else.

FAQ

Do I need VMware Workstation Pro, or does Player work?

Player or Fusion work fine for this. Metasploitable 2 doesn't need any Pro-only feature — snapshots and basic networking are enough.

Can I convert the .vmdk to a new VM automatically?

In most VMware versions, choosing "Open" on the .vmx file (if included) or creating a new VM and selecting the existing .vmdk when prompted for a disk both work. Either path uses the same disk image.

Does Metasploitable 2 need VMware Tools installed?

No. VMware Tools improve integration (shared folders, better display), but nothing in this lab depends on them.