> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/ru/hacking-tools/web/wmap-scan-web-vulnerabilities.md).

# Сканирование веб-уязвимостей WMAP

{% hint style="info" %}
WMAP — это плагин Metasploit, предназначенный для проведения тестирования на проникновение веб-приложений, особенно для выявления уязвимостей, специфичных для сайтов. Он позволяет выполнять автоматизированные сканирования безопасности веб-целей.
{% endhint %}

**Подключение к Metasploit:** В отличие от других инструментов, WMAP не требует специального подключения к Metasploit; он напрямую интегрируется в фреймворк Metasploit для работы.

#### Запуск сканирования WMAP

1. **Загрузите модуль WMAP:** Для начала необходимо загрузить модуль WMAP в Metasploit с помощью следующей команды:

```
load wmap
```

2. **Создайте целевой сайт:** Необходимо указать IP-адрес или домен сайта для тестирования с помощью следующей команды:

```
wmap_sites -a 10.10.10.10 
```

3. **Укажите целевой объект:** Чтобы задать URL целевого сайта, используйте следующую команду, которая настраивает URL для сканирования:

```bash
wmap_target -t http://10.10.10.10/
```

4. **Начать сканирование всех модулей:** Чтобы выполнить полное сканирование со всеми включенными модулями WMAP, используйте команду:

```bash
wmap_run -t
```

* Эта команда запускает сканирование с использованием всех доступных модулей для поиска уязвимостей в целевом веб-приложении.

```bash
wmap_run -e
```

<figure><img src="/files/81fbb56f8c0352a8cb98addc173beb1d597a08ad" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/ru/hacking-tools/web/wmap-scan-web-vulnerabilities.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
