Zabbix enumeration works through the JSON-RPC API (/api_jsonrpc.php) and the web UI. The version is readable, usually without authentication, through apiinfo.version and the login-page footer, and it is the key fact for exploit selection. After authenticating (or via any session), the API enumerates the user accounts (user.get), which feeds credential attacks, and the monitored hosts (host.get), which is a map of the internal estate: the IP addresses, hostnames, and interfaces Zabbix reaches, plus the items and macros that often hold the credentials used to monitor them. The API is the efficient path; the UI shows the same data.
Z=https://<target>/zabbix/api_jsonrpc.php; H='Content-Type: application/json-rpc'
# version (no auth in many versions)
curl -sk $Z -H "$H" -d '{"jsonrpc":"2.0","method":"apiinfo.version","params":{},"id":1}'
# authenticate to get a token, then enumerate
TOK=$(curl -sk $Z -H "$H" -d '{"jsonrpc":"2.0","method":"user.login","params":{"username":"Admin","password":"zabbix"},"id":1}' | jq -r .result)
curl -sk $Z -H "$H" -d '{"jsonrpc":"2.0","method":"user.get","params":{"output":["userid","username","roleid"]},"auth":"'"$TOK"'","id":1}'
curl -sk $Z -H "$H" -d '{"jsonrpc":"2.0","method":"host.get","params":{"output":["host"],"selectInterfaces":["ip","dns"]},"auth":"'"$TOK"'","id":1}'
Subtopics#
- Version detection: reading the Zabbix version.
- API: the JSON-RPC API as the enumeration interface.
- User: enumerating accounts.
- Host: the monitored-host inventory.