{"id":97349,"date":"2020-10-17T14:42:14","date_gmt":"2020-10-17T12:42:14","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/minimizacziya-riskov-ispolzovaniya-dns-over-tls-dot-i-dns-over-https-doh"},"modified":"2020-10-17T14:42:14","modified_gmt":"2020-10-17T12:42:14","slug":"minimizacziya-riskov-ispolzovaniya-dns-over-tls-dot-i-dns-over-https-doh","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/minimizacziya-riskov-ispolzovaniya-dns-over-tls-dot-i-dns-over-https-doh","title":{"rendered":"Minimizing risks of using DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH)","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Minimizing risks of using DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH)\" src=\"\/wp-content\/uploads\/2020\/10\/8a0e2dc9bf2f465277a2284fc595a472.jpg\" style=\"display:block;margin: 0 auto;\" \/>Minimizing the Risks of Using DoH and DoT<\/p>\n<h2>Protection Against DoH and DoT<\/h2>\n<p>Are you monitoring your DNS traffic? Organizations invest a lot of time, money, and effort in securing their networks. However, one area that often gets overlooked is DNS. <\/p>\n<p>A good overview of the risks posed by DNS is <noindex><a rel=\"nofollow\" href=\"https:\/\/www.infosecurityeurope.com\/__novadocuments\/484127\">Verisign's presentation<\/a><\/noindex> at the Infosecurity conference. <\/p>\n<p><img decoding=\"async\" alt=\"Minimizing risks of using DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH)\" src=\"\/wp-content\/uploads\/2020\/10\/f6ccff28c50acaa63796479ecf74d717.jpg\" style=\"display:block;margin: 0 auto;\" \/>31% of surveyed ransomware families used DNS for key exchange. Findings of the study<\/p>\n<p>31% of surveyed ransomware families used DNS for key exchange.<\/p>\n<p>The problem is serious. According to research by Palo Alto Networks Unit 42, approximately 85% of malware use DNS to establish command and control channels, allowing attackers to easily deploy malware in your network and exfiltrate data. Since its inception, DNS traffic has mainly been unencrypted and easily analyzed by NGFW mechanisms.&nbsp;<\/p>\n<p>New protocols for DNS have emerged, aimed at enhancing the privacy of DNS connections. They are actively supported by major browser vendors and other software providers. Soon, corporate networks will see a rise in encrypted DNS traffic. Encrypted DNS traffic, which is not properly analyzed and permitted, poses a security threat to the company. For example, such a threat comes from ransomware that uses DNS for exchanging encryption keys. Attackers are currently demanding ransom amounts in the millions of dollars to restore access to your data. For instance, Garmin paid $10 million.<\/p>\n<p>When properly configured, NGFW can block or protect the use of DNS-over-TLS (DoT) and can be used to prohibit DNS-over-HTTPS (DoH), allowing for the analysis of all DNS traffic in your network.<\/p>\n<h2>What is Encrypted DNS?<\/h2>\n<p>What is DNS<\/p>\n<p>The Domain Name System (DNS) translates human-readable domain names (like the address&nbsp;<noindex><a rel=\"nofollow\" href=\"http:\/\/www.paloaltonetworks.com\/\">www.paloaltonetworks.com<\/a><\/noindex>&nbsp;) to the IP address (for example, to 34.107.151.202). When a user enters a domain name in a web browser, the browser sends a DNS request to the DNS server, asking for the IP address associated with that domain name. In response, the DNS server returns the IP address that the browser will use.<\/p>\n<p>DNS requests and responses are transmitted over the network as plain text in an unencrypted form, making them vulnerable to eavesdropping or altering responses and redirecting the browser to malicious servers. DNS encryption makes it difficult to track DNS requests or alter them during transmission. Encrypting DNS requests and responses protects you from Man-in-the-Middle attacks while serving the same functions as the traditional DNS (Domain Name System) protocol in plain text.&nbsp;<\/p>\n<p>In recent years, two DNS encryption protocols have been implemented:<\/p>\n<ol>\n<li>\n<p>DNS-over-HTTPS (DoH)<\/p>\n<\/li>\n<li>\n<p>DNS-over-TLS (DoT) <\/p>\n<\/li>\n<\/ol>\n<p>These protocols share one common feature: they intentionally hide DNS queries from any interception\u2026 including from the organization's security personnel. The protocols primarily utilize the TLS (Transport Layer Security) protocol to establish an encrypted connection between the client making requests and the DNS server resolving those requests, via a port that is typically not used for DNS traffic.<\/p>\n<p>The privacy of DNS requests is a significant advantage of these protocols. However, they create challenges for security personnel who need to monitor network traffic and detect and block malicious connections. Since the protocols differ in their implementation, the analysis methods will vary for DoH and DoT.<\/p>\n<h2>DNS over HTTPS (DoH)<\/h2>\n<p><img decoding=\"async\" alt=\"Minimizing risks of using DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH)\" src=\"\/wp-content\/uploads\/2020\/10\/e22b3de1268de10d51471a734ae4b783.jpg\" style=\"display:block;margin: 0 auto;\" \/>DNS inside HTTPS<\/p>\n<p>DoH uses the well-known port 443 for HTTPS, for which the RFC specifically states that the goal is to \"mix DoH traffic with other HTTPS traffic in the same connection,\" \"make DNS traffic analysis difficult,\" and thereby circumvent corporate control measures (&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc8484#section-8.1\">RFC 8484 DoH, section 8.1<\/a><\/noindex>&nbsp;). The DoH protocol uses TLS encryption and the request syntax provided by common HTTPS and HTTP\/2 standards, adding DNS requests and responses on top of standard HTTP requests.<\/p>\n<h2>Risks associated with DoH<\/h2>\n<p>If you cannot distinguish regular HTTPS traffic from DoH requests, then applications within your organization may (and will) bypass local DNS settings by redirecting requests to external servers that respond to DoH requests, which circumvents any monitoring, thus eliminating the ability to control DNS traffic. Ideally, you should manage DoH using HTTPS decryption features.&nbsp;<\/p>\n<p>I can use&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/blog.mozilla.org\/blog\/2020\/02\/25\/firefox-continues-push-to-bring-dns-over-https-by-default-for-us-users\/\">Google and Mozilla have implemented DoH capabilities<\/a><\/noindex>&nbsp;in the latest versions of their browsers, and both companies are working towards using DoH by default for all DNS requests.&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/techcommunity.microsoft.com\/t5\/networking-blog\/windows-will-improve-user-privacy-with-dns-over-https\/ba-p\/1014229\">Microsoft is also developing plans<\/a><\/noindex>&nbsp;to integrate DoH into its operating systems. The downside is that not only reputable software development companies but also malicious actors have begun using DoH as a means to bypass traditional corporate firewall measures. ( For example, see the following articles:&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/psixbot-now-using-google-dns-over-https-and-possible-new-sexploitation-module\">PsiXBot now uses Google DoH<\/a><\/noindex>&nbsp;,&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/psixbot-continues-evolve-updated-dns-infrastructure\">PsiXBot continues to evolve with an updated DNS infrastructure<\/a><\/noindex>&nbsp;and&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/blog.netlab.360.com\/an-analysis-of-godlua-backdoor-en\/\">analysis of the Godlua backdoor<\/a><\/noindex>&nbsp;.) In any case, both good and malicious DoH traffic will remain undetected, leaving the organization blind to the nefarious use of DoH as a channel for controlling malware (C2) and stealing sensitive data.<\/p>\n<h2>Ensuring visibility and control over DoH traffic<\/h2>\n<p>As the best solution for controlling DoH, we recommend configuring HTTPS traffic decryption and blocking DoH traffic in NGFW (application name: dns-over-https).&nbsp;<\/p>\n<p>First, ensure that NGFW is configured for HTTPS decryption, according to&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/docs.paloaltonetworks.com\/best-practices\/9-0\/decryption-best-practices.html\">the decryption best practices guide<\/a><\/noindex>.<\/p>\n<p>Second, create a rule for the application traffic \u2018dns-over-https\u2019, as shown below:<\/p>\n<p><img decoding=\"async\" alt=\"Minimizing risks of using DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH)\" src=\"\/wp-content\/uploads\/2020\/10\/7876ec3c8af4177e9a81433eec91d419.jpg\" style=\"display:block;margin: 0 auto;\" \/>Palo Alto Networks NGFW rule to block DNS-over-HTTPS<\/p>\n<p>As an interim alternative (if your organization has not fully implemented HTTPS decryption), NGFW can be configured to apply the 'deny' action to the application identifier 'dns-over-https', but the effect will be limited to blocking certain well-known DoH servers by their domain name, as without HTTPS decryption, DoH traffic cannot be fully inspected (see.&nbsp;&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/applipedia.paloaltonetworks.com\/\">Palo Alto Networks Applipedia<\/a><\/noindex>&nbsp;&nbsp; and search for the phrase \u2018dns-over-https\u2019).<\/p>\n<h2>DNS over TLS (DoT)<\/h2>\n<p><img decoding=\"async\" alt=\"Minimizing risks of using DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH)\" src=\"\/wp-content\/uploads\/2020\/10\/1ce6c475d123f807971bbc286915349a.jpg\" style=\"display:block;margin: 0 auto;\" \/>DNS within TLS<\/p>\n<p>While the DoH protocol aims to blend in with other traffic on the same port, DoT, by contrast, uses a dedicated port reserved for this sole purpose by default, even specifically prohibiting the use of the same port for traditional unencrypted DNS traffic (&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc7858#section-3.1\">RFC 7858, Section 3.1<\/a><\/noindex>&nbsp;).<\/p>\n<p>The DoT protocol uses the TLS protocol to provide encryption that encapsulates standard DNS protocol queries, with traffic using the well-known port 853 (&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc7858#section-6\">RFC 7858, Section 6<\/a><\/noindex>&nbsp;). The DoT protocol was developed to simplify the process for organizations to either block traffic on that port or permit its use while enabling decryption on that port.<\/p>\n<h2>Risks associated with DoT<\/h2>\n<p>Google implemented DoT in its client&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/android-developers.googleblog.com\/2018\/04\/dns-over-tls-support-in-android-p.html\">Android 9 Pie and later versions<\/a><\/noindex>&nbsp;, with automatic use of DoT enabled by default if available. If you have assessed the risks and are ready to use DoT at the organizational level, then network administrators will need to explicitly allow outbound traffic on port 853 through their perimeter for this new protocol.<\/p>\n<h2>Ensuring visibility and control over DoT traffic<\/h2>\n<p>As best practices for controlling DoT, we recommend any of the following, based on your organization's requirements:<\/p>\n<ul>\n<li>\n<p>Configure your NGFW to decrypt all traffic to destination port 853. With traffic decrypted, DoT will display as a DNS application to which you can apply any action, such as enabling logging.&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/docs.paloaltonetworks.com\/pan-os\/9-0\/pan-os-admin\/threat-prevention\/dns-security\/enable-dns-security\">Palo Alto Networks DNS Security<\/a><\/noindex>&nbsp;for controlling DGA domains or already existing&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/safebdv.blogspot.com\/2019\/11\/dga.html\">DNS Sinkholing&nbsp;<\/a><\/noindex>and anti-spyware.<\/p>\n<\/li>\n<li>\n<p>Alternatively, you can completely block 'dns-over-tls' traffic through port 853 using the App-ID engine. It is usually blocked by default, requiring no action unless you have specifically allowed the 'dns-over-tls' application or traffic through port 853.<\/p>\n<\/li>\n<\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/523676\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041c\u0438\u043d\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u044f \u0440\u0438\u0441\u043a\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f DoH \u0438 DoT \u0417\u0430\u0449\u0438\u0442\u0430 \u043e\u0442 DoH \u0438 DoT \u041a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u0442\u0435 \u043b\u0438 \u0432\u044b \u0441\u0432\u043e\u0439 DNS \u0442\u0440\u0430\u0444\u0438\u043a? \u041e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u043a\u043b\u0430\u0434\u044b\u0432\u0430\u044e\u0442 \u043c\u043d\u043e\u0433\u043e \u0432\u0440\u0435\u043c\u0435\u043d\u0438, \u0434\u0435\u043d\u0435\u0433 \u0438 \u0443\u0441\u0438\u043b\u0438\u0439 \u0432 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u0435 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0441\u0432\u043e\u0438\u0445 \u0441\u0435\u0442\u0435\u0439. \u041e\u0434\u043d\u0430\u043a\u043e, \u043e\u0434\u043d\u043e\u0439 \u0438\u0437 \u043e\u0431\u043b\u0430\u0441\u0442\u0435\u0439, \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0447\u0430\u0441\u0442\u043e \u043d\u0435 \u0443\u0434\u0435\u043b\u044f\u0435\u0442\u0441\u044f \u0434\u043e\u043b\u0436\u043d\u043e\u0433\u043e \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u044f, \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f DNS. \u0425\u043e\u0440\u043e\u0448\u0438\u043c \u043e\u0431\u0437\u043e\u0440\u043e\u043c \u0440\u0438\u0441\u043a\u043e\u0432, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u0440\u0438\u043d\u043e\u0441\u0438\u0442 DNS \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043f\u0440\u0435\u0437\u0435\u043d\u0442\u0430\u0446\u0438\u044f Verisign \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Infosecurity. 31% \u043e\u0431\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u043d\u044b\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":97350,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-97349","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041c\u0438\u043d\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u044f \u0440\u0438\u0441\u043a\u043e\u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/minimizacziya-riskov-ispolzovaniya-dns-over-tls-dot-i-dns-over-https-doh\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041c\u0438\u043d\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u044f \u0440\u0438\u0441\u043a\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f DNS-over-TLS (DoT) \u0438 DNS-over-HTTPS (DoH) | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041c\u0438\u043d\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u044f \u0440\u0438\u0441\u043a\u043e\u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/minimizacziya-riskov-ispolzovaniya-dns-over-tls-dot-i-dns-over-https-doh\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-10-17T12:42:14+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-10-17T12:42:14+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Minimizing risks with DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH) | ProHoster","description":"Minimizing risks.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/minimizacziya-riskov-ispolzovaniya-dns-over-tls-dot-i-dns-over-https-doh","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041c\u0438\u043d\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u044f \u0440\u0438\u0441\u043a\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f DNS-over-TLS (DoT) \u0438 DNS-over-HTTPS (DoH) | ProHoster","og:description":"\u041c\u0438\u043d\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u044f \u0440\u0438\u0441\u043a\u043e\u0432.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/minimizacziya-riskov-ispolzovaniya-dns-over-tls-dot-i-dns-over-https-doh","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-10-17T12:42:14+00:00","article:modified_time":"2020-10-17T12:42:14+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"97349","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 10:22:33","updated":"2022-09-28 02:55:30","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/97349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=97349"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/97349\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/97350"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=97349"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=97349"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=97349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}