Metasploitable: 1

  • Name: Metasploitable: 1
  • Date release: 19 May 2010

Please remember that VulnHub is a free community resource so we are unable to check the machines that are provided to us. Before you download, please read our FAQs sections dealing with the dangers of running unknown VMs and our suggestions for "protecting yourself and your network. If you understand the risks, please download!

(Size: 545 MB)

One of the questions that we often hear is "What systems can i use to test against?" Based on this, we thought it would be a good idea throw together an exploitable VM that you can use for testing purposes.

Metasploitable is an Ubuntu 8.04 server install on a VMWare 6.5 image. A number of vulnerable packages are included, including an install of tomcat 5.5 (with weak credentials), distcc, tikiwiki, twiki, and an older mysql.

You can use most VMware products to run it, and you'll want to make sure it's configured for Host-only networking unless it's in your lab - no need to throw another vulnerable machine on the corporate network. It's configured in non-persistent-disk mode, so you can simply reset it if you accidentally 'rm -rf' it.


  • Filename:
  • File size: 545 MB
  • MD5: E54089BA72FE0127D06528DECAD9A6AE
  • SHA1: 1F6698611068FAD4D9661C336B5D888A0A880FE9

  • Format: Virtual Machine (VMware)
  • Operating System: Linux

  • DHCP service: Enabled
  • IP address: Automatically assign

  • Apache
  • Apache Jserv
  • Apache Tomcat
  • distccd
  • Linux telnetd
  • MySQL
  • OpenSSH
  • PHP
  • Postfix SMTPd
  • PostgreSQL
  • ProFTPD
  • Samba

  • Multiple Methods
  • Remote Vulnerability
  • Web Application

  • Weak Credentials