FTP: The vsftpd 2.3.4 Backdoor
Why it exists: Metasploitable 2 ships a version of vsftpd whose source was tampered with on a public download mirror in 2011, adding a hidden backdoor. Rapid7 kept it deliberately to teach the concept of a compromised software supply chain.
How it's identified: A version banner grab during service enumeration reveals "vsftpd 2.3.4," which is specific enough to recognize immediately once you know what to look for.
The lesson: Software version alone can be a red flag. Real incident responders keep a mental (or tooled) list of package versions with known-bad history, not just known CVEs.
How defenders mitigate it: Verify checksums/signatures on downloaded packages, track vendor security advisories, and patch or replace software with a documented history of tampering.
Telnet and Cleartext Remote Access
Why it exists: Telnet predates encrypted remote-access protocols and was still common on legacy infrastructure long after SSH became standard.
How it's identified: An open port 23 combined with a successful login capture in network traffic shows credentials moving in plain text.
The lesson: Encryption in transit isn't optional for anything handling credentials, even on an internal network — internal doesn't mean trusted.
How defenders mitigate it: Disable Telnet entirely and standardize on SSH with key-based authentication.
SMB/Samba: CVE-2007-2447
Why it exists: Metasploitable 2 ships Samba 3.0.20, vulnerable to a command injection flaw in its "username map script" option that lets an unauthenticated client run arbitrary shell commands.
How it's identified: A version scan flags Samba 3.0.20 as falling in the vulnerable 3.0.20–3.0.25rc3 range; share enumeration is a separate, additional check worth doing on top of that.
The lesson: Unsanitized user input reaching a shell command is a textbook remote-code-execution path, not just a permissions problem.
How defenders mitigate it: Patch beyond 3.0.25rc3 or disable the username map script option, and never pass unsanitized input to a shell invocation. Full breakdown on the SMB vulnerability page.
Database Exposure
Why it exists: MySQL and PostgreSQL are both reachable directly from the network with weak or default credentials, mirroring databases left open during rushed deployments.
How it's identified: A port scan finds the database port open to hosts other than the application server that should be its only client.
The lesson: A database almost never needs to be reachable from anywhere but its application layer.
How defenders mitigate it: Bind databases to internal interfaces only, enforce strong unique credentials, and firewall database ports from general network access.
Web Application Vulnerabilities
Why it exists: Bundled apps like DVWA and Mutillidae are built specifically to demonstrate classic web flaws such as SQL injection and cross-site scripting.
How it's identified: Manual testing and web proxies reveal unsanitized input reflected into queries or page output.
The lesson: Input validation and output encoding are foundational, not optional, at every layer that touches user input.
How defenders mitigate it: Use parameterized queries, framework-level output escaping, and a web application firewall as a secondary control, never a primary one.
Legacy Services: UnrealIRCd, distccd & More
Why it exists: Beyond FTP, Metasploitable 2 bundles a second backdoored package (UnrealIRCd 3.2.8.1, CVE-2010-2075), a trust-based compiler daemon turned RCE (distccd, CVE-2004-2687), a pre-opened root shell on port 1524, an exposed Java RMI registry, and legacy r-services/NFS/RPCbind.
How it's identified: A single scan across ports 111, 512–514, 1099, 1524, 2049, 3632, and 6667 surfaces the whole tier; version detection on 3632 and 6667 names the specific vulnerable builds directly.
The lesson: Two distinct risk patterns live on this one page — software that was actively tampered with, and software that was never designed for an untrusted network at all.
How defenders mitigate it: Maintain an accurate service inventory, replace trust-based protocols with modern authenticated equivalents, and treat any legacy protocol discovery as a prompt to ask why it's still running. Full breakdown on the legacy services page.