Ravindra BagaleCourses & study guides Track your progress

Labs · Cyber Security

Lab: Build an Isolated VirtualBox Lab on a Host-Only Network with Kali Linux and an Intentionally Vulnerable Training VM

Intermediate60 minVirtualBox (free) · Kali Linux VirtualBox image · Metasploitable 2 (training VM) · 7-Zip

Course: Cyber Security · Chapter 18: Ethics, the Law and a Safe Kali Lab

Chapter 18 covers ethics, the law and a safe Kali lab; this lab builds that lab and proves it is isolated.

Chala mitrano! Today we build our own practice ground. Metasploitable is a computer made weak on purpose for learning, so it must never touch the internet or our home Wi-Fi. We put it in a closed room (host-only network) and we test that the door is really locked. Chala, lab banvuya!

Suppose we are…

Suppose we are preparing for a security analyst role at Quick Heal. Their trainers say: "Practise as much as you like, but only in a lab that cannot leak." We build exactly that: VirtualBox (free software that runs computers inside your computer), a host-only network (a private network only the VMs and your laptop can use), Kali Linux as our toolbox, and Metasploitable 2, a training VM that is intentionally vulnerable.

Goal of this lab

By the end you will have:

  • A VirtualBox host-only network 192.168.56.0/24 with DHCP.
  • Kali Linux and Metasploitable 2 running on that network only.
  • Proof that both can reach each other but not the internet, and a clean snapshot of each VM.

What you need (all free)

  • Your own Windows or Intel-Mac laptop with virtualisation enabled and 8 GB+ RAM (Lab 17). Apple-silicon Macs cannot run Metasploitable 2 (it is 32-bit x86); use the Ubuntu Server ARM image as your target instead.
  • VirtualBox from https://www.virtualbox.org/wiki/Downloads.
  • Kali Linux VirtualBox image from https://www.kali.org/get-kali/ → Virtual Machines.
  • Metasploitable 2 from Rapid7's official SourceForge page (metasploitable-linux-2.0.0.zip), and 7-Zip to extract files.
  • Your my-lab-scope.txt from Lab 17. About 60 minutes, mostly downloads.

Safety and ethics

Metasploitable 2 must never be on a Bridged or NAT network and must never be exposed to the internet. Use it only for learning inside your own isolated lab, as written in your scope.

Part 1: the isolated network

  1. Install VirtualBox with default options and open it.
  2. Click File → Tools → Network Manager → Host-only Networks tab → Create.
  3. Select the new network (for example VirtualBox Host-Only Ethernet Adapter or vboxnet0). Check Adapter: 192.168.56.1, mask 255.255.255.0. On the DHCP Server tab tick Enable Server.

    What you should see: server address 192.168.56.100, lower address 192.168.56.101, upper 192.168.56.254.

Part 2: add the VMs

  1. Extract the Kali .7z file with 7-Zip. In VirtualBox click Machine → Add and open the .vbox file.
  2. Extract metasploitable-linux-2.0.0.zip. In VirtualBox click Machine → New: Name Metasploitable2, Type Linux, Version Other Linux (32-bit), memory 512 MB, and under Hard Disk choose Use an Existing Virtual Hard Disk File → add Metasploitable.vmdk → Finish.
  3. For each VM: select it → Settings → Network → Adapter 1 → Attached to: Host-only Adapter, Name: your host-only network. Make sure Adapters 2–4 are not enabled. Click OK.

    What you should see: in the VM's details panel, Network: Adapter 1: Intel PRO/1000 (Host-only Adapter, ...) and nothing else.

Part 3: prove it is isolated

  1. Start Metasploitable2. Log in with msfadmin / msfadmin and run ifconfig eth0.

    What you should see: inet addr:192.168.56.10x. Write it down.

  2. Still on Metasploitable, run ping -c 3 8.8.8.8.

    What you should see: connect: Network is unreachable or 100% packet loss. It cannot reach the internet. Good.

  3. Start Kali, log in (kali / kali is the default for the prebuilt image; change it with passwd). Open a terminal and run:

    ip -br a
    ping -c 3 192.168.56.10x
    ping -c 3 8.8.8.8
    

    What you should see: Kali has a 192.168.56.x address, the Metasploitable ping works, and the 8.8.8.8 ping fails.

  4. From your laptop's Command Prompt or Terminal, run ping 192.168.56.10x. It works, because your laptop is on the host-only network too. Your phone on home Wi-Fi cannot reach it.

  5. Take snapshots so you can always return to a clean state: select each VM → the menu icon next to it → Snapshots → Take → name it clean-install.
  6. Shut down Metasploitable with sudo halt and Kali from its power menu.

Ravindra Bagale's Tip

Kali needs updates and new tools sometimes, so you may switch Kali alone to NAT for a few minutes. Never do that for Metasploitable. And before you switch Kali back to the lab, check ip -br a again. Ek chuk ani lab leak hote!

Common mistakes

Mistake What happens Fix
Leaving Metasploitable on NAT (the default for new VMs) It can reach the internet Set Adapter 1 to Host-only before the first start
DHCP server not enabled VMs get no 192.168.56.x address Enable DHCP in Network Manager
Opening the Kali .7z with Windows' built-in tool Extraction fails or files are missing Use 7-Zip
Two adapters enabled on a VM One of them may be NAT or Bridged Enable only Adapter 1
Not taking snapshots You rebuild the VM after every mistake Take clean-install snapshots now

Self-check checklist

0 of 6 done

Try-at-home challenge

Add your Ubuntu Server VM (or any other VM) to the same lab. Which two settings must you set before its first start, and how do you prove it is isolated?

Check your answer

Before first start: Adapter 1 = Host-only Adapter on your lab network, and no other adapters enabled. (To install packages first, you may install it on NAT, update it, then switch to Host-only before any testing.) Prove isolation: it gets a 192.168.56.x address, can ping Kali, and cannot ping 8.8.8.8.

Samjla ka? A closed room, a weak-on-purpose VM inside it, and proof the door is locked. Aata pudhe jaauya: Chapter 19 takes an inventory of this lab.