Enumerating Zabbix users identifies who to attack and how much each account is worth. The user.get API method (and the Administration > Users page) returns the accounts with their usernames, assigned roles, and user-group membership. This confirms whether the default Admin superadmin and the guest account exist, identifies the administrative accounts (Super admin role) that unlock code execution, and produces the username list for password spraying. Because a sufficiently privileged Zabbix account leads directly to running commands on the server and monitored hosts, knowing which accounts hold which roles focuses the credential attack on the highest-value targets.
Z=https://<target>/zabbix/api_jsonrpc.php; H='Content-Type: application/json-rpc'
curl -sk $Z -H "$H" -d '{"jsonrpc":"2.0","method":"user.get","params":{"output":["userid","username","roleid"],"selectUsrgrps":["name"]},"auth":"'"$TOK"'","id":1}'
# map roles to privileges (which accounts are Super admin)
curl -sk $Z -H "$H" -d '{"jsonrpc":"2.0","method":"role.get","params":{"output":"extend"},"auth":"'"$TOK"'","id":1}'
Exploitation notes#
- The role/usergroup mapping is the point: target Super-admin accounts for credential attacks, since they unlock script execution and full configuration; a non-admin account may still enable item-based execution depending on permissions.
- Confirm the default accounts: a present
Admin(default passwordzabbix) or an enabledguestis an immediate default-credential/guest-access win. - The username list feeds brute force and spraying; Zabbix logins are web-based, so respect any lockout and prefer spraying.
user.getrequires an authenticated session, so it follows initial access; before access, rely on default-account knowledge and the login page.