Hello everybody and welcome back.
And we have officially started our intermediate section, and we are starting it off with the download of
the virtual machine called Metasploitable.
Now, as you can see, I am downloading it right now from the rapid7 website.
Now it might ask you, let me just show you.
If you go and type here, in your Google search bar, if you type here Metasploitable, and click on the first
link,
it will ask you before you can download the Metasploitable to make an account.
So, basically, you need to submit some of this information in order to download
Metasploitable
from the rapid7 website.
Now if you do not want to specify any information you can just go on to these other websites, which
basically I just clicked on this one, and you can download it from here.
So just click here on download,
and in a few seconds your download will start.
Now the Metasploitable zip file is around 800 megabytes large.
Let me just close this one since I don't need to download it two times.
As you can see, I am here already downloading it.
So we will wait until that finishes and then we will build the virtual machine into our VirtualBox.
Now, if you are asking, what is Metasploitable?
Well, basically, Metasploitable is an intentionally vulnerable virtual machine which we will use in
order to further test our attacks and scans.
Now we use this machine because scanning any website you do not have permission to scan can be illegal
and you shouldn't be doing it.
So this is also a dangerous machine so you shouldn't expose it to any network
you do not trust.
For example, you should only keep it over net or host only. Don't connect it to a bridged adapter and connect
it to a local network, since it is purposely made vulnerable and there is a bunch of holes in this machine.
Now we will not be explaining all of the vulnerabilities that this machine has but we will cover some of them.
And, basically, I will just wait for this to finish,
and once it finishes I will show you how to install the virtual machine
And my download has finished.
So what you want to do right now is basically this zip file just copy and paste it onto your desktop.
So once you got it on your desktop, which is right here, what you want to do is basically extract this
file since it is a zip file.
We want to extract it.
I will use winrar to do that.
So this will take a few seconds. And after it is finished, we can we can proceed with the making of our
Metasploitable. You will notice, once it is done, that we will get five files, I believe, in this folder,
and we're only interested in one which is the .vmdk file which we will use as a hard disk
for this virtual machine.
Now this is finished and you can see right here, if we open it, there are five files and we will use this
one.
I will show you right here how to put it into a virtual machine.
So basically, for the sake of the making, just click on the new virtual machine, and here you can
type here any name you want.
So I will just call it vulnerable, and here you want to pick, as the type of operating system, you want
to choose Linux. In the version type you want to go scroll down, let me just find it, and scroll down and pick other
Linux.
Once you have these options picked you just click on the next option.
And here we have the memory size.
Now the memory size for the Metasploitable should be at least 512 megabytes. And it will work
fine on the 512, but I would advise you to, if you have the spare RAM memory, you can just put here one
gigabyte and it will work better.
But if you do not have it, you just leave it on 512 and it will also work fine.
Now keep in mind that you will be running two virtual machines. One is Kali Linux and one is Metasploitable,
once we run our tests. So, be aware that you will need,
also, RAM memory in order to run your main machine. So if you do not have enough memory just leave here
512.
Now once you picked your memory size Just click here
on next. And under this option, you want to go to the use an existing virtual hard disk. Here
you just want to go on the choose a virtual hard disk file, and you basically just want to find the
Metasploitable, which in my case is right here.
Let me just see why it won't work.
Does not match the value in the media registry.
What do you mean it does not match the value?
Well it doesn't even matter.
#ethicalhackingcourse #codingmaster