Gaining access to Zabbix is the gateway to its code-execution features and stored credentials, and there are several routes. The default Admin superadmin account ships with the password zabbix and is frequently unchanged. Weak passwords and the absence of a strong policy make brute force and spraying effective. The built-in guest account, where enabled, grants unauthenticated read access. Specific versions have had API authentication-bypass flaws. And stolen session cookies or API tokens are replayed directly. What matters after access is the account's role: a Super admin unlocks script execution and full configuration, while lesser roles may still enable item-based execution depending on permissions.
# web login and API login both validate the same credentials
Z=https://<target>/zabbix/api_jsonrpc.php
curl -sk $Z -H 'Content-Type: application/json-rpc' \
-d '{"jsonrpc":"2.0","method":"user.login","params":{"username":"Admin","password":"zabbix"},"id":1}'
Subtopics#
- Default credentials: Admin/zabbix and guest.
- Weak passwords: common and reused passwords.
- Brute force: online attacks on the login.
- Guest access: the built-in read-only guest account.
- API authentication bypass: version-specific auth-bypass flaws.
- Session and token theft: replaying stolen sessions and API tokens.