{"id":120801,"date":"2024-12-01T03:46:13","date_gmt":"2024-12-01T01:46:16","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/vyyavlen-uefi-butkit-bootkitty-podstavlyayushhij-vredonosnyj-kod-v-zagruzhaemoe-yadro-linux"},"modified":"2024-12-01T03:46:13","modified_gmt":"2024-12-01T01:46:16","slug":"vyyavlen-uefi-butkit-bootkitty-podstavlyayushhij-vredonosnyj-kod-v-zagruzhaemoe-yadro-linux","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/vyyavlen-uefi-butkit-bootkitty-podstavlyayushhij-vredonosnyj-kod-v-zagruzhaemoe-yadro-linux","title":{"rendered":"Der UEFI-Bootkit Bootkitty wurde entdeckt, der b\u00f6sartigen Code in den zu ladenden Linux-Kernel einf\u00fcgt.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Forscher von ESET haben einen neuen Bootkit namens \u201eBootkitty\u201c entdeckt, der nach einem Systemhack anstelle des GRUB-Bootloaders installiert wird und verwendet wird, um b\u00f6sartige Komponenten in den Linux-Kernel einzuschleusen, die es dem Angreifer erm\u00f6glichen, das System heimlich zu kontrollieren und darin Aktionen auszuf\u00fchren. Es wird behauptet, dass dies das erste UEFI-Bootkit ist, das auf die Beeintr\u00e4chtigung von Linux-Systemen abzielt.      <\/p>\n<p>Bootkitty wird in der Datei grubx64.efi im EFI-Systempartition (EFI system partition, \/boot\/efi\/EFI\/ubuntu) anstelle des standardm\u00e4\u00dfigen GRUB-Bootloaders platziert. Nach der Aktivierung durch die UEFI-Firmware l\u00e4dt das Bootkit den echten GRUB2-Bootloader in den Speicher und nimmt \u00c4nderungen am im Speicher befindlichen Code von GRUB2 vor, die die Integrit\u00e4tspr\u00fcfung der sp\u00e4ter geladenen Komponenten deaktivieren, und f\u00fcgt einen Handler hinzu, der nach dem Entpacken des Linux-Kernel-Images in den Speicher aufgerufen wird. Der angegebene Handler \u00e4ndert die in den Speicher geladenen Kernel-Funktionen (deaktiviert die \u00dcberpr\u00fcfung der Module anhand von digitalen Signaturen) und \u00e4ndert au\u00dferdem die Startzeile des Initialisierungsprozesses von \u201e\/init\u201c auf \u201eLD_PRELOAD=\/opt\/injector.so \/init\u201c.         <\/p>\n<p>Die Bibliothek injector.so f\u00e4ngt einige SELinux-Operationen und die Funktion init_module ab, die dann verwendet wird, um das Kernel-Modul \/opt\/dropper.ko zu laden. Das Kernel-Modul dropper.ko erstellt und startet die ausf\u00fchrbare Datei \/opt\/observer, versteckt sich anschlie\u00dfend in der Liste der Kernel-Module und setzt Systemaufruf-Handler wie getdents und tcp4_seq_show, um die Datei \/opt\/observer und bestimmten Netzwerkverkehr zu verbergen. Die ausf\u00fchrbare Datei \/opt\/observer l\u00e4dt das Kernel-Modul \/opt\/rootkit_loader.ko, das als Loader f\u00fcr das Rootkit \/opt\/rootkit fungiert.         <center><img decoding=\"async\" alt=\"Der UEFI-Bootkit Bootkitty wurde entdeckt, der b\u00f6sartigen Code in den zu ladenden Linux-Kernel einf\u00fcgt.\" src=\"\/wp-content\/uploads\/2024\/12\/6a08f46d2fa5c18cf3e01a82d86ac716.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>     <\/p>\n<p>F\u00fcr die Installation des Bootkits ist ein privilegierter Zugang zum System erforderlich, und solche Arten von Malware werden von Angreifern normalerweise nach einem erfolgreichen Angriff oder einer Kompromittierung des Systems verwendet, um ihre weitere Pr\u00e4senz zu sichern und b\u00f6sartige Aktivit\u00e4ten zu verbergen. Die Bibliothek injector.so und die b\u00f6sartigen Kernel-Module werden in das Image des initialen RAM-Disk oder das Dateisystem des Angreifers eingef\u00fcgt. Der Bootloader grubx64.efi wird im Verzeichnis mit Dateien f\u00fcr UEFI abgelegt.       <\/p>\n<p>In the Bootkitty variant that fell into the hands of researchers, memory function modifications in the kernel were made at predetermined offsets without checking the correctness of these offsets for the loaded kernel version. The offsets used in Bootkitty were applicable only to certain versions of the kernel and GRUB provided in specific releases of Ubuntu, causing boot failures in other systems. For verifying the Bootkitty bootloader (grubx64.efi), a self-signed certificate was used, which prevented the bootkit from being applied to systems with UEFI Secure Boot enabled without adding the attacker's certificate to the list of trusted certificates in UEFI. Such characteristics led the researchers to conclude that Bootkitty is merely a prototype bootkit, not yet used for real attacks.      <\/p>\n<p>After examining the published information from ESET, researchers from Binarly Research noted BMP images related to Bootkitty artifacts, which were used to exploit the LogoFAIL vulnerability, allowing code execution at the UEFI firmware level and bypassing the UEFI Secure Boot mechanism. In the context of Bootkitty, the LogoFAIL vulnerability was exploited to add the attacker's self-signed certificate to the list of approved UEFI certificates, which signed the Bootkitty bootloader grubx64.efi, enabling the bootkit to run on systems with active UEFI Secure Boot without manual certificate addition.        <\/p>\n<p>The attack is carried out by placing a specially crafted BMP image in the ESP (EFI System Partition) for display by the UEFI firmware as the manufacturer\u2019s logo. Due to the use of vulnerable libraries in UEFI firmware for handling images, processing the specially crafted image may lead to a buffer overflow and the execution of code with UEFI firmware privileges. The LogoFAIL vulnerability was identified a year ago and affected UEFI firmware, among others, used on laptops by Acer, HP, Fujitsu, and Lenovo. In newer versions of UEFI firmware, the issue has been resolved, but many devices still in use continue to operate with vulnerable firmware versions.    <center><img decoding=\"async\" alt=\"Der UEFI-Bootkit Bootkitty wurde entdeckt, der b\u00f6sartigen Code in den zu ladenden Linux-Kernel einf\u00fcgt.\" src=\"\/wp-content\/uploads\/2024\/12\/d5d21d5d1fe6c42e5d12950b4cab49b8.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><br \/>\n<br \/>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=62321\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 ESET \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u043d\u043e\u0432\u044b\u0439 \u0431\u0443\u0442\u043a\u0438\u0442 &#171;Bootkitty&#187;, \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u043c\u044b\u0439 \u043f\u043e\u0441\u043b\u0435 \u0432\u0437\u043b\u043e\u043c\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0432\u043c\u0435\u0441\u0442\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0430 GRUB \u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0439 \u0434\u043b\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0432 \u044f\u0434\u0440\u043e Linux \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u043e\u0432, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0437\u0430\u0442\u0435\u043c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0441\u043a\u0440\u044b\u0442\u043e \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0441\u0438\u0441\u0442\u0435\u043c\u0443 \u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0442\u044c \u0432 \u043d\u0435\u0439 \u0441\u0432\u043e\u0438 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f. \u0423\u0442\u0432\u0435\u0440\u0436\u0434\u0430\u0435\u0442\u0441\u044f, \u0447\u0442\u043e \u044d\u0442\u043e \u043f\u0435\u0440\u0432\u044b\u0439 UEFI-\u0431\u0443\u0442\u043a\u0438\u0442, \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u043d\u0430 \u043f\u043e\u0440\u0430\u0436\u0435\u043d\u0438\u0435 \u0441\u0438\u0441\u0442\u0435\u043c Linux. Bootkitty \u0440\u0430\u0437\u043c\u0435\u0449\u0430\u0435\u0442\u0441\u044f \u0432 \u0444\u0430\u0439\u043b\u0435 grubx64.efi \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u043c \u0440\u0430\u0437\u0434\u0435\u043b\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":120802,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-120801","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 ESET \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u043d\u043e\u0432\u044b\u0439 \u0431\u0443\u0442\u043a\u0438\u0442 &quot;Bootkitty&quot;, \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u043c\u044b\u0439 \u043f\u043e\u0441\u043b\u0435 \u0432\u0437\u043b\u043e\u043c\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0432\u043c\u0435\u0441\u0442\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0430 GRUB \u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0439 \u0434\u043b\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0432 \u044f\u0434\u0440\u043e Linux \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u043e\u0432, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0437\u0430\u0442\u0435\u043c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/vyyavlen-uefi-butkit-bootkitty-podstavlyayushhij-vredonosnyj-kod-v-zagruzhaemoe-yadro-linux\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u044f\u0432\u043b\u0435\u043d UEFI-\u0431\u0443\u0442\u043a\u0438\u0442 Bootkitty, \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0438\u0439 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434 \u0432 \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u043e\u0435 \u044f\u0434\u0440\u043e Linux | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 ESET \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u043d\u043e\u0432\u044b\u0439 \u0431\u0443\u0442\u043a\u0438\u0442 &quot;Bootkitty&quot;, \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u043c\u044b\u0439 \u043f\u043e\u0441\u043b\u0435 \u0432\u0437\u043b\u043e\u043c\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0432\u043c\u0435\u0441\u0442\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0430 GRUB \u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0439 \u0434\u043b\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0432 \u044f\u0434\u0440\u043e Linux \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u043e\u0432, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0437\u0430\u0442\u0435\u043c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/vyyavlen-uefi-butkit-bootkitty-podstavlyayushhij-vredonosnyj-kod-v-zagruzhaemoe-yadro-linux\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-12-01T01:46:16+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-12-01T01:46:16+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Der UEFI-Bootkit Bootkitty wurde entdeckt, der schadhafter Code in den Ladekernel von Linux einf\u00fcgt | ProHoster","description":"Researchers from ESET have discovered a new bootkit \"Bootkitty,\" which is installed after the system is compromised instead of the GRUB bootloader and is used to inject malicious components into the Linux kernel, which then allow.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/vyyavlen-uefi-butkit-bootkitty-podstavlyayushhij-vredonosnyj-kod-v-zagruzhaemoe-yadro-linux","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u044f\u0432\u043b\u0435\u043d UEFI-\u0431\u0443\u0442\u043a\u0438\u0442 Bootkitty, \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0438\u0439 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434 \u0432 \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u043e\u0435 \u044f\u0434\u0440\u043e Linux | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 ESET \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u043d\u043e\u0432\u044b\u0439 \u0431\u0443\u0442\u043a\u0438\u0442 &quot;Bootkitty&quot;, \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u043c\u044b\u0439 \u043f\u043e\u0441\u043b\u0435 \u0432\u0437\u043b\u043e\u043c\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0432\u043c\u0435\u0441\u0442\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0430 GRUB \u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0439 \u0434\u043b\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0432 \u044f\u0434\u0440\u043e Linux \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u043e\u0432, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0437\u0430\u0442\u0435\u043c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/vyyavlen-uefi-butkit-bootkitty-podstavlyayushhij-vredonosnyj-kod-v-zagruzhaemoe-yadro-linux","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-12-01T01:46:16+00:00","article:modified_time":"2024-12-01T01:46:16+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"120801","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 08:28:23","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 08:28:23","updated":"2026-01-23 08:28:23","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/120801","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=120801"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/120801\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media\/120802"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=120801"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=120801"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=120801"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}