Metasploit becomes easier to understand when you can follow one module from search results through configuration, execution, session management, and cleanup. This beginner course provides that focused first workflow in six guided Ubuntu terminal labs, using a locally prepared target rather than a broad collection of remote scenarios.
You will install the framework, learn how msfconsole organizes commands and workspaces, search and select modules, and run an auxiliary TCP scan. The final two labs use a deliberately vulnerable local VSFTPD 2.3.4 service to open a Meterpreter session and practice a shell plus basic file transfer. Troubleshooting notes are part of the learning design because current module checks, encoders, and the first exploit attempt can affect whether a session opens immediately.
What You Will Learn
After completing the course, you will be able to:
- Install Metasploit Framework on Ubuntu with the official Rapid7 installation script and complete its initial console setup.
- Navigate
msfconsolehelp, create and switch workspaces, search the module catalog, and inspect detailed module information. - Filter exploit searches by type and platform, select a module with
use, review required options, and set values such asLHOST. - Configure and run the
auxiliary/scanner/portscan/tcpmodule against a controlled target and interpret reported open ports. - Select and configure the VSFTPD 2.3.4 backdoor exploit, handle relevant validation or encoding issues, execute it, and list the resulting session.
- Background and re-enter a Meterpreter session, open a command shell, transfer a prepared file in both directions, and exit cleanly.
Who This Course Is For
This course is for complete Metasploit beginners, cybersecurity students who know basic networking, and Linux users who want a small, coherent practice path before attempting broader exploitation labs. It teaches framework mechanics through one scanner and one exploit target. It does not survey many vulnerability classes, teach exploit development, or cover a complete penetration-test engagement and remediation process.
Prerequisites: No prior Metasploit experience is required. Basic Linux terminal skills and an understanding of IP addresses, ports, services, and attacker-versus-target roles will help. You should be comfortable following exact commands and checking option values when output differs from an example.
Learning environment: You will use a browser-accessible Ubuntu 22.04 terminal, not a Kali desktop. The first lab downloads the official Metasploit installer and therefore can depend on network and repository availability. Scanning, exploitation, Meterpreter, and file-transfer exercises target services prepared on 127.0.0.1; keep all activity inside the authorized lab.
Frequently Asked Questions
Do I need Kali Linux to take this course?
No. Metasploit is installed and used directly in the provided Ubuntu terminal. This keeps the course focused on framework commands; Kali-specific desktop usage and its wider tool collection are outside the scope.
How does this differ from Kali Server Exploitation in Action?
This is the shorter foundation: six guided labs, one local scanner, one prepared VSFTPD exploit, and basic Meterpreter operations. Kali Server Exploitation in Action contains 20 broader scenarios with Metasploitable2, multiple vulnerable services, custom module work, root-access paths, and riskier post-exploitation topics.
Will the exploit session always open on the first attempt?
Not necessarily. The lab documents possible LHOST validation, encoder, automatic-check, and backdoor cooldown issues; you may need to adjust the specified options or retry. Learning to read the error and confirm the session with sessions -l is part of the exercise.
Does this course teach a complete penetration test or defensive remediation?
No. It introduces installation, console navigation, scanning, one controlled exploit, and basic post-exploitation. Scoping, evidence handling, reporting, exploit selection across real systems, cleanup verification, and fixing the underlying vulnerability require additional study and authorization.





