Lab Environments
Metasploitable 2/3
Intentionally vulnerable Linux/Windows VMs for exploit practice.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Learning scanning and exploitation safely on disposable VMs.
How
Import VM; isolate network; attack from Kali only on host-only/lab net.
Why
Classic first targets for new pentesters.
Commands & usage
# Run as VM — never expose to the internet
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in Lab Environments
DVWA
Damn Vulnerable Web Application for learning OWASP bugs.
OWASP Juice Shop
Modern insecure web app with gamified challenges.
OWASP WebGoat
Deliberately insecure app teaching common web flaws lesson-by-lesson.
VulnHub
Free downloadable vulnerable machines for offline practice.
Hack The Box
Online pentest labs with machines, challenges, and careers path.
TryHackMe
Guided cybersecurity learning rooms and hands-on labs.