- Kali Linux Network Scanning Cookbook
- Justin Hutchens
- 374字
- 2021-09-03 09:58:02
Installing Metasploitable2
Metasploitable2 is an intentionally vulnerable Linux distribution and is also a highly effective security training tool. It comes fully loaded with a large number of vulnerable network services and also includes several vulnerable web applications.
Getting ready
Prior to installing Metasploitable2 in your virtual security lab, you will first need to download it from the Web. There are many mirrors and torrents available for this. One relatively easy method to acquire Metasploitable is to download it from SourceForge at the following URL: http://sourceforge.net/projects/metasploitable/files/Metasploitable2/.
How to do it…
Installing Metasploitable2 is likely to be one of the easiest installations that you will perform in your security lab. This is because it is already prepared as a VMware virtual machine when it is downloaded from SourceForge. Once the ZIP file has been downloaded, you can easily extract the contents of this file in Windows or Mac OS X by double-clicking on it in Explorer
or Finder
respectively. Have a look at the following screenshot:

Once extracted, the ZIP file will return a directory with five additional files inside. Included among these files is the VMware VMX file. To use Metasploitable in VMware, just click on the File drop-down menu and click on Open. Then, browse to the directory created from the ZIP extraction process and open Metasploitable.vmx
as shown in the following screenshot:

Once the VMX file has been opened, it should be included in your virtual machine library. Select it from the library and click on Run to start the VM and get the following screen:

After the VM loads, the splash screen will appear and request login credentials. The default credential to log in is msfadmin
for both the username and password. This machine can also be accessed via SSH, as addressed in the Configuring and using SSH recipe later in this section.
How it works…
Metasploitable was built with the idea of security testing education in mind. This is a highly effective tool, but it must be handled with care. The Metasploitable system should never be exposed to any untrusted networks. It should never be assigned a publicly routable IP address, and port forwarding should not be used to make services accessible over the Network Address Translation (NAT) interface.
- INSTANT Metasploit Starter
- 反黑命令與攻防從新手到高手(微課超值版)
- 計(jì)算機(jī)病毒原理與防范(第2版)
- 數(shù)據(jù)安全實(shí)踐指南
- ARM匯編與逆向工程:藍(lán)狐卷·基礎(chǔ)知識(shí)
- Digital Forensics with Kali Linux
- 可信計(jì)算3.0工程初步(第二版)
- CTF那些事兒
- Web安全之深度學(xué)習(xí)實(shí)戰(zhàn)
- 網(wǎng)絡(luò)用戶(hù)行為的安全可信分析與控制
- Cybersecurity Threats,Malware Trends,and Strategies
- 網(wǎng)絡(luò)空間安全:拒絕服務(wù)攻擊檢測(cè)與防御
- Android Application Security Essentials
- 黑客攻防從入門(mén)到精通:命令版
- 信息系統(tǒng)安全等級(jí)化保護(hù)原理與實(shí)踐