{"id":72053,"date":"2020-03-01T08:42:47","date_gmt":"2020-03-01T05:42:47","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimost-v-apache-tomcat-pozvolyayushhaya-podstavit-jsp-kod-i-poluchit-fajly-web-prilozhenij"},"modified":"2020-03-03T16:10:21","modified_gmt":"2020-03-03T13:10:21","slug":"uyazvimost-v-apache-tomcat-pozvolyayushhaya-podstavit-jsp-kod-i-poluchit-fajly-web-prilozhenij","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-apache-tomcat-pozvolyayushhaya-podstavit-jsp-kod-i-poluchit-fajly-web-prilozhenij","title":{"rendered":"Una vulnerabilidad en Apache Tomcat que permite insertar c\u00f3digo JSP y obtener archivos de aplicaciones web","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Investigadores de la empresa china Chaitin Tech han identificado <noindex><a rel=\"nofollow\" href=\"https:\/\/www.chaitin.cn\/en\/ghostcat\">vulnerabilidad<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-1938\">CVE-2020-1938<\/a><\/noindex>) en <noindex><a rel=\"nofollow\" href=\"http:\/\/tomcat.apache.org\/\">Apache Tomcat<\/a><\/noindex>, una implementaci\u00f3n abierta de las tecnolog\u00edas Java Servlet, JavaServer Pages, Java Expression Language y Java WebSocket. Esta vulnerabilidad ha recibido el nombre en clave Ghostcat y su nivel de peligrosidad es cr\u00edtico (9.8 CVSS). El problema permite, en la configuraci\u00f3n predeterminada, leer el contenido de cualquier archivo del directorio de la aplicaci\u00f3n web mediante el env\u00edo de una solicitud al puerto de red 8009, incluyendo archivos de configuraci\u00f3n y el c\u00f3digo fuente de la aplicaci\u00f3n.<\/p>\n<p>La vulnerabilidad tambi\u00e9n permite importar otros archivos en el c\u00f3digo de la aplicaci\u00f3n, lo que posibilita la ejecuci\u00f3n de c\u00f3digo en el servidor, si la aplicaci\u00f3n permite la carga de archivos en el servidor (por ejemplo, un atacante puede subir un script JSP haci\u00e9ndose pasar por una imagen a trav\u00e9s de un formulario de carga). El ataque puede llevarse a cabo si hay posibilidad de enviar una solicitud al puerto de red con el manejador AJP. Seg\u00fan datos preliminares, en la red <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/hrbrmstr\/status\/1233766331314581509\">cuatro problemas menores (activaci\u00f3n de mensajes de depuraci\u00f3n, falta de bloqueo de copias de seguridad mediante la utilidad ADB, cifrado de configuraciones con una clave predefinida, falta de vinculaci\u00f3n del certificado SSL) y una vulnerabilidad de gravedad media (finalizaci\u00f3n incompleta de la sesi\u00f3n, lo que permite la reutilizaci\u00f3n de tokens de sesi\u00f3n).<\/a><\/noindex> hay m\u00e1s de 1.2 millones de hosts que aceptan solicitudes a trav\u00e9s del protocolo AJP. <\/p>\n<p> La vulnerabilidad est\u00e1 presente en el protocolo AJP, y <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/solutions\/4851251\">no es causada<\/a><\/noindex> por un error en la implementaci\u00f3n. Adem\u00e1s de aceptar conexiones por HTTP (puerto 8080), Apache Tomcat, por defecto, permite el acceso a la aplicaci\u00f3n web a trav\u00e9s del protocolo AJP (<noindex><a rel=\"nofollow\" href=\"https:\/\/tomcat.apache.org\/connectors-doc\/ajp\/ajpv13a.html\">Apache Jserv Protocol<\/a><\/noindex>, puerto 8009), que es un an\u00e1logo binario optimizado para lograr un mayor rendimiento del HTTP, utilizado generalmente al crear un cl\u00faster de servidores Tomcat o para acelerar la interacci\u00f3n con Tomcat en un proxy inverso o equilibrador de carga.<\/p>\n<p>AJP proporciona una funci\u00f3n est\u00e1ndar para acceder a archivos en el servidor, que tambi\u00e9n puede ser utilizada para obtener archivos que no deber\u00edan ser divulgados. Se supone que el acceso a AJP est\u00e1 abierto solo para servidores de confianza, pero en realidad, en la configuraci\u00f3n predeterminada, Tomcat se inicia con el manejador en todas las interfaces de red, y las solicitudes se aceptan sin autenticaci\u00f3n. Es posible acceder a cualquier archivo de la aplicaci\u00f3n web, incluyendo contenido de WEB-INF, META-INF y cualquier otro directorio accesible a trav\u00e9s de la llamada ServletContext.getResourceAsStream(). AJP tambi\u00e9n permite utilizar cualquier archivo en los directorios disponibles para la aplicaci\u00f3n web como un script JSP.<\/p>\n<p>El problema se manifiesta desde el lanzamiento de la versi\u00f3n Tomcat 6.x hace 13 a\u00f1os. Adem\u00e1s de Tomcat, el problema afecta <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/solutions\/4851251\">afecta<\/a><\/noindex> a productos que lo utilizan, como Red Hat JBoss Web Server (JWS), JBoss Enterprise Application Platform (EAP), as\u00ed como aplicaciones web independientes que usan <noindex><a rel=\"nofollow\" href=\"https:\/\/spring.io\/projects\/spring-boot\">Spring Boot<\/a><\/noindex>. Una vulnerabilidad similar (CVE-2020-1745) <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/solutions\/4851251\">hay<\/a><\/noindex> en el servidor web <noindex><a rel=\"nofollow\" href=\"http:\/\/undertow.io\/\">Undertow<\/a><\/noindex>, utilizado en el servidor de aplicaciones Wildfly. En JBoss y Wildfly, el protocolo AJP est\u00e1 habilitado por defecto solo en standalone-full-ha.xml, standalone-ha.xml y en los perfiles ha\/full-ha en domain.xml. En Spring Boot, el soporte para AJP est\u00e1 desactivado de forma predeterminada. Actualmente, varios grupos han preparado m\u00e1s de una docena de ejemplos funcionales de exploits (<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/dacade\/cve-2020-1938\">1<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ze0r\/GhostCat-LFI-exp\">2<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/laolisafe\/CVE-2020-1938\">3<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/00theway\/Ghostcat-CNVD-2020-10487\">4<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/xindongzhuaizhuai\/CVE-2020-1938\">5<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/0nise\/CVE-2020-1938\">6<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/nibiwodong\/CNVD-2020-10487-Tomcat-ajp-POC\">7<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/YDHCUI\/CNVD-2020-10487-Tomcat-Ajp-lfi\">8<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/LandGrey\/ClassHound\">9<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/fairyming\/CVE-2020-1938\">10<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/jiangsir404\/POC-S\">11<\/a><\/noindex>). <\/p>\n<p>La vulnerabilidad ha sido corregida en las versiones de Tomcat <noindex><a rel=\"nofollow\" href=\"https:\/\/tomcat.apache.org\/security-9.html#Fixed_in_Apache_Tomcat_9.0.31\">9.0.31<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/tomcat.apache.org\/security-8.html#Fixed_in_Apache_Tomcat_8.5.51\">8.5.51<\/a><\/noindex> y <noindex><a rel=\"nofollow\" href=\"https:\/\/tomcat.apache.org\/security-7.html#Fixed_in_Apache_Tomcat_7.0.100\">7.0.100<\/a><\/noindex> (mantenimiento de la rama 6.x  <noindex><a rel=\"nofollow\" href=\"https:\/\/tomcat.apache.org\/security-6.html\">detenido<\/a><\/noindex>). Se puede seguir la aparici\u00f3n de actualizaciones en las distribuciones en estas p\u00e1ginas: <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-1938\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2020\/CVE-2020-1938.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2020-1938\">RHEL<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1806805\">Fedora<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.suse.com\/security\/cve\/CVE-2020-1938\/\">SUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"http:\/\/www.vuxml.org\/freebsd\/\">FreeBSD<\/a><\/noindex>Como medida alternativa de protecci\u00f3n, se puede deshabilitar el servicio Tomcat AJP Connector (vincular el socket de escucha a localhost o comentar la l\u00ednea con Connector port = &#171;8009&#187;), si no es necesario, o <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2020-1938\">configurar<\/a><\/noindex> acceso autenticado mediante los atributos &#171;secret&#187; y &#171;address&#187;, si el servicio se utiliza para interactuar con otros servidores y proxies basados en mod_jk y mod_proxy_ajp (mod_cluster no soporta autenticaci\u00f3n). <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52459\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u0438\u0442\u0430\u0439\u0441\u043a\u043e\u0439 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Chaitin Tech \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-1938) \u0432 Apache Tomcat, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0439 Java Servlet, JavaServer Pages, Java Expression Language \u0438 Java WebSocket. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f Ghostcat \u0438 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 (9.8 CVSS). \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u043f\u043e \u0441\u0435\u0442\u0435\u0432\u043e\u043c\u0443 \u043f\u043e\u0440\u0442\u0443 8009 \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043b\u044e\u0431\u044b\u0445 \u0444\u0430\u0439\u043b\u043e\u0432 \u0438\u0437 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-72053","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u0438\u0442\u0430\u0439\u0441\u043a\u043e\u0439 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Chaitin Tech \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-apache-tomcat-pozvolyayushhaya-podstavit-jsp-kod-i-poluchit-fajly-web-prilozhenij\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Apache Tomcat, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u044c JSP-\u043a\u043e\u0434 \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0444\u0430\u0439\u043b\u044b web-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u0438\u0442\u0430\u0439\u0441\u043a\u043e\u0439 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Chaitin Tech \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-apache-tomcat-pozvolyayushhaya-podstavit-jsp-kod-i-poluchit-fajly-web-prilozhenij\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-03-01T05:42:47+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-03T13:10:21+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilidad en Apache Tomcat que permite inyectar c\u00f3digo JSP y obtener archivos de aplicaciones web | ProHoster","description":"Investigadores de la empresa china Chaitin Tech han descubierto una vulnerabilidad (","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-apache-tomcat-pozvolyayushhaya-podstavit-jsp-kod-i-poluchit-fajly-web-prilozhenij","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Apache Tomcat, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u044c JSP-\u043a\u043e\u0434 \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0444\u0430\u0439\u043b\u044b web-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u0438\u0442\u0430\u0439\u0441\u043a\u043e\u0439 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Chaitin Tech \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-apache-tomcat-pozvolyayushhaya-podstavit-jsp-kod-i-poluchit-fajly-web-prilozhenij","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-03-01T05:42:47+00:00","article:modified_time":"2020-03-03T13:10:21+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"72053","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 18:51:22","updated":"2022-10-08 06:25:27","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/72053","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=72053"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/72053\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=72053"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=72053"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=72053"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}