Where Metasploitable 2 Came From
Metasploitable 2 was built by Rapid7 as a companion target for the Metasploit Framework, so people learning the framework would have something legal to point it at. Rather than hardening the machine, the team did the opposite: they installed older package versions, left default credentials in place, and enabled services that a real sysadmin would normally lock down.
That's the entire premise. It's not a broken system that happened to end up insecure — it's a deliberately staged one, which is exactly what makes it useful for teaching. When a tutorial says "this port is vulnerable," it stays true for every reader, on every install, indefinitely.
What's Inside the Virtual Machine
Metasploitable 2 ships as a single virtual disk image built on a minimal Ubuntu 8.04 base. Once it boots, it's running a stack of services that were common on real servers at the time and are still found, misconfigured, on real networks today:
- File transfer: a vulnerable FTP daemon (vsftpd 2.3.4) with a known backdoor.
- Remote access: an outdated SSH server and an open Telnet service transmitting in cleartext.
- File sharing: a misconfigured Samba/SMB installation.
- Databases: MySQL and PostgreSQL instances reachable with weak or default credentials.
- Web applications: DVWA, Mutillidae, and a handful of other intentionally vulnerable PHP apps served over Apache.
See the vulnerabilities overview for a full breakdown of what each service teaches.
What You Can Learn With It
Metasploitable 2 is a practice target, not a course by itself — the learning happens in how you approach it. Most learners work through it in roughly this order:
- Network scanning — finding the machine and confirming it's reachable.
- Service enumeration — identifying exactly what's running behind each open port.
- Vulnerability research — matching a service and version against known weaknesses.
- Controlled exploitation — validating a finding inside the isolated lab.
- Defensive reasoning — understanding what a real administrator would change to close the gap.
The full sequence is laid out in the beginner learning path.
Learning objective: by the end of a first session, you should be able to explain why each open port on Metasploitable 2 is considered a weakness, not just how to trigger it.
Is Metasploitable 2 Safe to Run?
Yes, as long as it stays inside an isolated lab network. The machine has no hardening at all, which means any device that can reach it on the network can potentially interact with its vulnerable services — including your own host or other devices on a shared Wi-Fi network if it's misconfigured.
Never bridge Metasploitable 2 to a public or shared network, and never expose it to the internet. Run it on a host-only or internal virtual network reachable only by your attacking VM. See network configuration for the exact settings.
System Requirements
Metasploitable 2 is lightweight by modern standards, since it was built for hardware from over a decade ago:
| Resource | Minimum | Notes |
|---|---|---|
| RAM | 512 MB | Allocate 1 GB if your host has room. |
| Disk | 8 GB | The virtual disk image itself is a few GB. |
| Virtualization | VirtualBox or VMware | Any recent release works. |
| Network | Host-only adapter | Required to keep the lab isolated. |
Default Credentials
Metasploitable 2's documented default login is username msfadmin with password msfadmin. Several other accounts and services also use weak or blank credentials by design. Full details, plus why you should never reuse these anywhere else, are on the default credentials page.
Metasploitable 2 vs. Metasploitable 3
Metasploitable 3 is a separate, newer project built from a provisioning template rather than a fixed disk image, with a Windows target in addition to Linux. It's more realistic and more complex to set up. Most beginners still start with Metasploitable 2 because a single downloadable image is easier to get running on the first try, and its vulnerabilities are simpler to reason about one at a time.
FAQ
Is Metasploitable 2 still maintained?
No. Metasploitable 2 hasn't received updates in years. That's intentional for learners — the vulnerabilities stay fixed and documented — but it also means the image should never run outside an isolated lab.
Why is it called Metasploitable 2 specifically?
It's the second release in the Metasploitable line, built as a companion target for the Metasploit Framework. A separate, more modern Metasploitable 3 also exists and uses a different build approach.
Does Metasploitable 2 include a graphical desktop?
No. It boots to a command-line login. All of its vulnerable services and web applications are reached over the network from another machine, not from a local desktop session.