Weak passwords

Older Zabbix versions enforce no password policy, so even when the default is changed the replacement is frequently weak: zabbix, zabbix123, Password1, the company or system name, or a season-and-year pattern, and administrators commonly reuse a password they use elsewhere. Combined with the enumerated user list, this makes a short, targeted password spray effective: one likely password across the known accounts, focusing on the Super-admin users. The web login and the API both validate credentials, so the attack runs against either.

bash
Z=https://<target>/zabbix/api_jsonrpc.php; H='Content-Type: application/json-rpc'
# spray one likely password across enumerated users via the API
for u in Admin zabbix monitoring operator; do
  r=$(curl -sk $Z -H "$H" -d '{"jsonrpc":"2.0","method":"user.login","params":{"username":"'"$u"'","password":"zabbix123"},"id":1}')
  echo "$u: $r"; done

Exploitation notes#

  • Spray one or a few context-derived passwords across the enumerated users rather than deep brute force; target Super-admin accounts first, as their access unlocks code execution.
  • Newer Zabbix versions added a configurable password policy (and lockout), so feasibility depends on the version; older instances are unprotected.
  • Credential reuse is common: a password found elsewhere in the environment may be the Zabbix admin's, and the Zabbix password may be reused for other services.
  • A recovered account's value depends on its role; confirm with user.get/role.get and route to code execution if it is admin.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more