Start Learning
Vulnerabilities

Metasploitable 2 Vulnerabilities

Metasploitable 2 exposes a fixed, well-documented set of weaknesses across file transfer, remote access, file sharing, databases, and web applications. This page focuses less on "how to break each one" and more on why each weakness exists, how a real assessment would find it, and what a defender does about that class of problem afterward.

Vulnerability Reference Table

Every exposed service, mapped to what it teaches.

ServicePortCategoryWhat Learners StudyRelated Guide
vsftpd 2.3.421/tcpFTPA backdoored package version and why supply-chain trust in software mirrors matters.FTP guide
OpenSSH22/tcpRemote AccessFingerprinting an outdated SSH version and why version disclosure aids attackers.SSH guide
Telnet23/tcpRemote AccessWhy cleartext remote-access protocols expose credentials to anyone on the path.Telnet guide
Apache / DVWA / Mutillidae80/tcpWeb ApplicationsCommon web flaws: SQL injection, XSS, and insecure file handling.Web apps guide
RPCbind111/tcpLegacy ServicesWhy legacy RPC services still linger on unmaintained infrastructure.Legacy services guide
r-services (rlogin/rsh/rexec)512–514/tcpLegacy ServicesTrust-based remote login with no real authentication check.Legacy services guide
Samba (usermap_script)139, 445/tcpSMBCVE-2007-2447 command injection — unauthenticated remote code execution.SMB guide
Java RMI Registry1099/tcpLegacy ServicesAn RMI protocol never designed for an untrusted network.Legacy services guide
ingreslock backdoor1524/tcpLegacy ServicesA root shell bound directly to the port — what a backdoor looks like.Legacy services guide
NFS2049/tcpLegacy ServicesOverly broad filesystem export configuration.Legacy services guide
MySQL3306/tcpDatabasesDatabases reachable with weak or default credentials from the network.Databases guide
distccd3632/tcpLegacy ServicesCVE-2004-2687 — a trust-based compiler daemon turned remote code execution.Legacy services guide
PostgreSQL5432/tcpDatabasesSame lesson as MySQL, applied to a second common database engine.Databases guide
VNC5900/tcpWeak CredentialsRemote desktop access protected by a trivially weak password.Default credentials
UnrealIRCd6667/tcpLegacy ServicesCVE-2010-2075 — a second backdoored-software supply-chain example.Legacy services guide
Apache Tomcat manager8180/tcpMisconfigurationsDefault admin console credentials accepting web app deployment.Misconfigurations guide
Various accounts—MisconfigurationsDefault and blank passwords, and overly permissive file/service settings.Misconfigurations guide

This table is a map, not a checklist — work through the category pages to understand each weakness before testing it.

FTP: The vsftpd 2.3.4 Backdoor

Why it exists: Metasploitable 2 ships a version of vsftpd whose source was tampered with on a public download mirror in 2011, adding a hidden backdoor. Rapid7 kept it deliberately to teach the concept of a compromised software supply chain.

How it's identified: A version banner grab during service enumeration reveals "vsftpd 2.3.4," which is specific enough to recognize immediately once you know what to look for.

The lesson: Software version alone can be a red flag. Real incident responders keep a mental (or tooled) list of package versions with known-bad history, not just known CVEs.

How defenders mitigate it: Verify checksums/signatures on downloaded packages, track vendor security advisories, and patch or replace software with a documented history of tampering.

Telnet and Cleartext Remote Access

Why it exists: Telnet predates encrypted remote-access protocols and was still common on legacy infrastructure long after SSH became standard.

How it's identified: An open port 23 combined with a successful login capture in network traffic shows credentials moving in plain text.

The lesson: Encryption in transit isn't optional for anything handling credentials, even on an internal network — internal doesn't mean trusted.

How defenders mitigate it: Disable Telnet entirely and standardize on SSH with key-based authentication.

SMB/Samba: CVE-2007-2447

Why it exists: Metasploitable 2 ships Samba 3.0.20, vulnerable to a command injection flaw in its "username map script" option that lets an unauthenticated client run arbitrary shell commands.

How it's identified: A version scan flags Samba 3.0.20 as falling in the vulnerable 3.0.20–3.0.25rc3 range; share enumeration is a separate, additional check worth doing on top of that.

The lesson: Unsanitized user input reaching a shell command is a textbook remote-code-execution path, not just a permissions problem.

How defenders mitigate it: Patch beyond 3.0.25rc3 or disable the username map script option, and never pass unsanitized input to a shell invocation. Full breakdown on the SMB vulnerability page.

Database Exposure

Why it exists: MySQL and PostgreSQL are both reachable directly from the network with weak or default credentials, mirroring databases left open during rushed deployments.

How it's identified: A port scan finds the database port open to hosts other than the application server that should be its only client.

The lesson: A database almost never needs to be reachable from anywhere but its application layer.

How defenders mitigate it: Bind databases to internal interfaces only, enforce strong unique credentials, and firewall database ports from general network access.

Web Application Vulnerabilities

Why it exists: Bundled apps like DVWA and Mutillidae are built specifically to demonstrate classic web flaws such as SQL injection and cross-site scripting.

How it's identified: Manual testing and web proxies reveal unsanitized input reflected into queries or page output.

The lesson: Input validation and output encoding are foundational, not optional, at every layer that touches user input.

How defenders mitigate it: Use parameterized queries, framework-level output escaping, and a web application firewall as a secondary control, never a primary one.

Legacy Services: UnrealIRCd, distccd & More

Why it exists: Beyond FTP, Metasploitable 2 bundles a second backdoored package (UnrealIRCd 3.2.8.1, CVE-2010-2075), a trust-based compiler daemon turned RCE (distccd, CVE-2004-2687), a pre-opened root shell on port 1524, an exposed Java RMI registry, and legacy r-services/NFS/RPCbind.

How it's identified: A single scan across ports 111, 512–514, 1099, 1524, 2049, 3632, and 6667 surfaces the whole tier; version detection on 3632 and 6667 names the specific vulnerable builds directly.

The lesson: Two distinct risk patterns live on this one page — software that was actively tampered with, and software that was never designed for an untrusted network at all.

How defenders mitigate it: Maintain an accurate service inventory, replace trust-based protocols with modern authenticated equivalents, and treat any legacy protocol discovery as a prompt to ask why it's still running. Full breakdown on the legacy services page.

!

Only interact with these services inside your own isolated Metasploitable 2 lab. The same techniques used against a real, unauthorized system are illegal in most jurisdictions regardless of intent.