Labs · Cyber Security
Lab: Build an Isolated VirtualBox Lab on a Host-Only Network with Kali Linux and an Intentionally Vulnerable Training VM
Course: Cyber Security · Chapter 18: Ethics, the Law and a Safe Kali Lab
Chapter 18 covers ethics, the law and a safe Kali lab; this lab builds that lab and proves it is isolated.
Chala mitrano! Today we build our own practice ground. Metasploitable is a computer made weak on purpose for learning, so it must never touch the internet or our home Wi-Fi. We put it in a closed room (host-only network) and we test that the door is really locked. Chala, lab banvuya!
चला मित्रांनो! आज आपण आपलं स्वतःचं practice ground बनवणार. Metasploitable हा शिकण्यासाठी मुद्दाम कमकुवत बनवलेला computer आहे, म्हणून त्याने internet ला किंवा घरच्या Wi-Fi ला कधीच हात लावू नये. आपण त्याला बंद खोलीत (host-only network) ठेवणार आणि दरवाजा खरंच बंद आहे का ते test करणार. चला, lab बनवूया!
चलो दोस्तों! आज हम अपना practice ground बनाएँगे। Metasploitable सीखने के लिए जानबूझकर कमज़ोर बनाया गया computer है, इसलिए उसे कभी internet या घर के Wi-Fi को नहीं छूना चाहिए। हम उसे बंद कमरे (host-only network) में रखेंगे और test करेंगे कि दरवाज़ा सच में बंद है। चलो, lab बनाते हैं!
Suppose we are…
Suppose we are preparing for a security analyst role at Quick Heal. Their trainers say: "Practise as much as you like, but only in a lab that cannot leak." We build exactly that: VirtualBox (free software that runs computers inside your computer), a host-only network (a private network only the VMs and your laptop can use), Kali Linux as our toolbox, and Metasploitable 2, a training VM that is intentionally vulnerable.
Goal of this lab
By the end you will have:
- A VirtualBox host-only network
192.168.56.0/24with DHCP. - Kali Linux and Metasploitable 2 running on that network only.
- Proof that both can reach each other but not the internet, and a clean snapshot of each VM.
What you need (all free)
- Your own Windows or Intel-Mac laptop with virtualisation enabled and 8 GB+ RAM (Lab 17). Apple-silicon Macs cannot run Metasploitable 2 (it is 32-bit x86); use the Ubuntu Server ARM image as your target instead.
- VirtualBox from
https://www.virtualbox.org/wiki/Downloads. - Kali Linux VirtualBox image from
https://www.kali.org/get-kali/→ Virtual Machines. - Metasploitable 2 from Rapid7's official SourceForge page (
metasploitable-linux-2.0.0.zip), and 7-Zip to extract files. - Your
my-lab-scope.txtfrom Lab 17. About 60 minutes, mostly downloads.
Safety and ethics
Metasploitable 2 must never be on a Bridged or NAT network and must never be exposed to the internet. Use it only for learning inside your own isolated lab, as written in your scope.
Part 1: the isolated network
- Install VirtualBox with default options and open it.
- Click File → Tools → Network Manager → Host-only Networks tab → Create.
-
Select the new network (for example VirtualBox Host-Only Ethernet Adapter or
vboxnet0). Check Adapter:192.168.56.1, mask255.255.255.0. On the DHCP Server tab tick Enable Server.What you should see: server address
192.168.56.100, lower address192.168.56.101, upper192.168.56.254.
Part 2: add the VMs
- Extract the Kali
.7zfile with 7-Zip. In VirtualBox click Machine → Add and open the.vboxfile. - Extract
metasploitable-linux-2.0.0.zip. In VirtualBox click Machine → New: NameMetasploitable2, Type Linux, Version Other Linux (32-bit), memory 512 MB, and under Hard Disk choose Use an Existing Virtual Hard Disk File → addMetasploitable.vmdk→ Finish. -
For each VM: select it → Settings → Network → Adapter 1 → Attached to: Host-only Adapter, Name: your host-only network. Make sure Adapters 2–4 are not enabled. Click OK.
What you should see: in the VM's details panel, Network: Adapter 1: Intel PRO/1000 (Host-only Adapter, ...) and nothing else.
Part 3: prove it is isolated
-
Start Metasploitable2. Log in with
msfadmin/msfadminand runifconfig eth0.What you should see:
inet addr:192.168.56.10x. Write it down. -
Still on Metasploitable, run
ping -c 3 8.8.8.8.What you should see:
connect: Network is unreachableor 100% packet loss. It cannot reach the internet. Good. -
Start Kali, log in (
kali/kaliis the default for the prebuilt image; change it withpasswd). Open a terminal and run:ip -br a ping -c 3 192.168.56.10x ping -c 3 8.8.8.8What you should see: Kali has a
192.168.56.xaddress, the Metasploitable ping works, and the8.8.8.8ping fails. -
From your laptop's Command Prompt or Terminal, run
ping 192.168.56.10x. It works, because your laptop is on the host-only network too. Your phone on home Wi-Fi cannot reach it. - Take snapshots so you can always return to a clean state: select each VM → the menu icon next to it → Snapshots → Take → name it
clean-install. - Shut down Metasploitable with
sudo haltand Kali from its power menu.
Ravindra Bagale's Tip
Kali needs updates and new tools sometimes, so you may switch Kali alone to NAT for a few minutes. Never do that for Metasploitable. And before you switch Kali back to the lab, check ip -br a again. Ek chuk ani lab leak hote!
Ravindra Bagale's Tip – मराठी
Kali ला कधी कधी updates आणि नवीन tools लागतात, म्हणून फक्त Kali काही मिनिटांसाठी NAT वर टाकू शकता. Metasploitable साठी हे कधीच करू नका. आणि Kali परत lab मध्ये टाकण्याआधी ip -br a परत check करा. एक चूक आणि lab leak होते!
Ravindra Bagale's Tip – हिंदी
Kali को कभी-कभी updates और नए tools चाहिए होते हैं, इसलिए सिर्फ Kali को कुछ मिनट के लिए NAT पर डाल सकते हो। Metasploitable के लिए ये कभी मत करो। और Kali को वापस lab में डालने से पहले ip -br a फिर से check करो। एक गलती और lab leak हो जाती है!
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
| Leaving Metasploitable on NAT (the default for new VMs) | It can reach the internet | Set Adapter 1 to Host-only before the first start |
| DHCP server not enabled | VMs get no 192.168.56.x address |
Enable DHCP in Network Manager |
Opening the Kali .7z with Windows' built-in tool |
Extraction fails or files are missing | Use 7-Zip |
| Two adapters enabled on a VM | One of them may be NAT or Bridged | Enable only Adapter 1 |
| Not taking snapshots | You rebuild the VM after every mistake | Take clean-install snapshots now |
Self-check checklist
0 of 6 done
Try-at-home challenge
Add your Ubuntu Server VM (or any other VM) to the same lab. Which two settings must you set before its first start, and how do you prove it is isolated?
Check your answer
Before first start: Adapter 1 = Host-only Adapter on your lab network, and no other adapters enabled. (To install packages first, you may install it on NAT, update it, then switch to Host-only before any testing.) Prove isolation: it gets a 192.168.56.x address, can ping Kali, and cannot ping 8.8.8.8.
Samjla ka? A closed room, a weak-on-purpose VM inside it, and proof the door is locked. Aata pudhe jaauya: Chapter 19 takes an inventory of this lab.