{"id":228081,"date":"2015-07-01T15:33:27","date_gmt":"2015-07-01T13:33:27","guid":{"rendered":"http:\/\/securite.intrinsec.com\/?p=1863"},"modified":"2015-07-01T15:33:27","modified_gmt":"2015-07-01T13:33:27","slug":"hack-in-paris-2015-seconde-journee","status":"publish","type":"post","link":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2015-seconde-journee\/","title":{"rendered":"Hack in Paris 2015 \u2013 Day Two"},"content":{"rendered":"<h2>KEYNOTE: ATTACKING SECURE COMMUNICATION: THE (SAD) STATE OF ENCRYPTED MESSAGING \u2013 Thomas Roth<\/h2>\n<p>Since Edward Snowden&#039;s revelations, encryption of communications has become a necessity, especially in the event of civil conflict, such as in Egypt or Hong Kong.<\/p>\n<p>Since the use of PGP and S\/MIME is not easy, Thomas Roth therefore became interested in the security of secure public communication systems promising users protection from the NSA.<\/p>\n<p>The findings are damning: across the tested products (Proton Mail, SpiderOak, Tutonota, etc.), several vulnerabilities or implementation flaws were detected. In addition to the use of non-standard cryptographic implementations, XSS or CSRF vulnerabilities were also found on web portals that allow access to the user&#039;s private data, including their private key.<\/p>\n<p>The Electronic Frontier Foundation maintains a list of tools for securing communications, categorized according to several criteria, which is available: <a href=\"https:\/\/www.eff.org\/secure-messaging-scorecard\">https:\/\/www.eff.org\/secure-messaging-scorecard<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<h2>SERVER-SIDE BROWSING CONSIDERED HARMFUL \u2013 Nicolas Gr\u00e9goire<\/h2>\n<p>Nicolas Gr\u00e9goire told us about the various Bug Bounty programs he participates in. The main criteria for participation are: the website must be large, the security team must be good and responsive, and the payment must be fair.<\/p>\n<p>The author presented several vulnerabilities identified on various websites, including Facebook and Yahoo. The presentation focused primarily on Server Side Request Forgery vulnerabilities.<\/p>\n<p>This type of vulnerability can be exploited to scan the local network or all of the server&#039;s ports. The speaker then presented several solutions for bypassing application firewalls using the various possible representations of IP addresses. A script is available on his website to generate the different existing formats: <a href=\"http:\/\/www.agarri.fr\/docs\/ipobf.py\">http:\/\/www.agarri.fr\/docs\/ipobf.py<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h2>FITNESS TRACKER: HACK IN PROGRESS \u2013 Axelle Apvrille<\/h2>\n<p>Axelle Apvrille took an interest in the Fitbit Flex bracelet and presented the work done so far.<\/p>\n<p>The presentation began with a summary of several vulnerabilities impacting data privacy, such as users&#039; sexual activity.<\/p>\n<p>Then, she presented us with a state-of-the-art overview of the advances in reverse engineering the exchange protocol with the tracker, with the aim of understanding the content of the exchanged data and being able to create alternative clients.<\/p>\n<p>Finally, the presentation ended with a bit of <em>hardware hacking<\/em> using the bracelet as an entropy generator.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h2>SAP SECURITY: REAL\u2010LIFE ATTACKS TO BUSINESS PROCESSES \u2013 Arsal Ertunga<\/h2>\n<p>Arsal Ertunga presented concrete examples of attacks on SAP, including the possibility of extracting credit card numbers. Securing an SAP system is complex because the attack surface it exposes is very large. We recommend reading the presentation, which was quite detailed.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h2>ORACLE PEOPLESOFT APPLICATIONS ARE UNDER ATTACK! \u2013 Alexey GreenDog Tyurin<\/h2>\n<p>Oracle&#039;s PeopleSoft tool is used in most large companies for human resources management and is sometimes accessible online. As a result, a great deal of sensitive information is processed within it. After presenting the overall architecture of the solution, Alexey &quot;GreenDog&quot; Tyutin focused on several vulnerabilities discovered in the software.<\/p>\n<p>He then focused on the SSO solution provided by Oracle within PeopleSoft, and more specifically on how the user&#039;s session cookie is created. Indeed, the cookie&#039;s integrity is verified using the SHA1 hash of a string with a known structure. Only one component of this string is not transmitted to the user.<\/p>\n<p>The proposed solution is to forge a valid administrator cookie from a standard user cookie by brute-forcing the missing parameter.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h2>EXPLOITING TCP TIMESTAMPS \u2013 Veit Hailperin<\/h2>\n<p>Veit Hailperin revisits a well-known topic: TCP timestamps. After a brief overview of their use and the various existing attacks, he proposes a solution for enumerating the different machines behind a NAT, firewall, or load balancer based solely on TCP timestamps. A script that exploits the results of an Nmap scan is available on his GitHub page. <a href=\"https:\/\/github.com\/luh2\/timestamps\">https:\/\/github.com\/luh2\/timestamps<\/a><\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<h2>SIMPLE NETWORK MANAGEMENT PWND: INFORMATION DATA LEAKAGE ATTACKS AGAINST SNMP ENABLED EMBEDDED DEVICES \u2013 Deral Heiland and Mathew Kienow<\/h2>\n<p>Deral Heiland and Mathew Kienov, researchers at Rapid7, were interested in the information available via the SNMP protocol.<\/p>\n<p>Currently, 7 million machines using the &quot;public&quot; SNMP community are accessible on the internet, according to Shodan. The authors focused particularly on routers. Indeed, 73,000 routers were found to be disclosing sometimes sensitive information on the internet.<\/p>\n<p>Based on the use of the &quot;snmpbulkwalk&quot; command, they wrote several scripts capable of retrieving information such as email addresses, passwords, and even the private community used for machine administration. These scripts are available on their GitHub repository. <a href=\"https:\/\/github.com\/dheiland-r7\/snmp\">https:\/\/github.com\/dheiland-r7\/snmp<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h2>REVISITING ATM VULNERABILITIES FOR OUR FUN AND VENDOR\u2019S PROFIT \u2013 Alexey Osipov &amp; Olga Kochetova<\/h2>\n<p>Currently, 95% ATMs run on an outdated operating system: Windows XP. Alexey Osipov and Olga Kochetova began by summarizing the various physical (skimmer) and logical (malware) attacks against ATMs. For example, over the past two years, the Tyupkin malware has been primarily detected in the United States, Canada, and France.<\/p>\n<p>Then, continuing from Black Hat 2014, they presented their attack using serial or USB ports via a Raspberry Pi. This creates an access point that allows them to communicate directly with the vending machine and send commands.<\/p>","protected":false},"excerpt":{"rendered":"<p>KEYNOTE: ATTACKING SECURE COMMUNICATION: THE (SAD) STATE OF ENCRYPTED MESSAGING &#8211; Thomas Roth Depuis les [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":1861,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22],"tags":[134,135,101],"class_list":["post-228081","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-veille-securite","tag-conference","tag-hack-in-paris","tag-hip"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Hack in Paris 2015 - Seconde journ\u00e9e - INTRINSEC<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2015-seconde-journee\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hack in Paris 2015 - Seconde journ\u00e9e\" \/>\n<meta property=\"og:description\" content=\"KEYNOTE: ATTACKING SECURE COMMUNICATION: THE (SAD) STATE OF ENCRYPTED MESSAGING &#8211; Thomas Roth Depuis les [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2015-seconde-journee\/\" \/>\n<meta property=\"og:site_name\" content=\"INTRINSEC\" \/>\n<meta property=\"article:published_time\" content=\"2015-07-01T13:33:27+00:00\" \/>\n<meta name=\"author\" content=\"Admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:site\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/hack-in-paris-2015-seconde-journee\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/hack-in-paris-2015-seconde-journee\\\/\"},\"author\":{\"name\":\"Admin\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/5636e3e5276b952facbd0aadb12a858a\"},\"headline\":\"Hack in Paris 2015 &#8211; Seconde journ\u00e9e\",\"datePublished\":\"2015-07-01T13:33:27+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/hack-in-paris-2015-seconde-journee\\\/\"},\"wordCount\":1070,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/hack-in-paris-2015-seconde-journee\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"keywords\":[\"conf\u00e9rence\",\"hack in paris\",\"HIP\"],\"articleSection\":[\"Veille S\u00e9curit\u00e9\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/hack-in-paris-2015-seconde-journee\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/hack-in-paris-2015-seconde-journee\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/hack-in-paris-2015-seconde-journee\\\/\",\"name\":\"Hack in Paris 2015 - Seconde journ\u00e9e - INTRINSEC\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/hack-in-paris-2015-seconde-journee\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/hack-in-paris-2015-seconde-journee\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"datePublished\":\"2015-07-01T13:33:27+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/hack-in-paris-2015-seconde-journee\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/hack-in-paris-2015-seconde-journee\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/hack-in-paris-2015-seconde-journee\\\/#primaryimage\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/hack-in-paris-2015-seconde-journee\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.intrinsec.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hack in Paris 2015 &#8211; Seconde journ\u00e9e\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"name\":\"INTRINSEC\",\"description\":\"Notre m\u00e9tier , Prot\u00e9ger le v\u00f4tre\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.intrinsec.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\",\"name\":\"INTRINSEC\",\"alternateName\":\"ISEC\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"contentUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"width\":1322,\"height\":1322,\"caption\":\"INTRINSEC\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/Intrinsec\",\"https:\\\/\\\/fr.linkedin.com\\\/company\\\/intrinsec\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UC0trUZAHNZOUbxYnNdecM4A\"],\"description\":\"soci\u00e9t\u00e9 de consulting, pure player cybers\u00e9curit\u00e9 fran\u00e7ais et europ\u00e9en depuis plus de 30ans, sp\u00e9cialiste dans la s\u00e9curit\u00e9 offensive & audit (pentest\\\/red team), GRC, et services IMSS comme le SOC, CTI et CERT Intrinsec est qualifi\u00e9 PASSI Elev\u00e9, PRIS Elev\u00e9 et PACS par l'ANSSI\",\"email\":\"contact@intrinsec.com\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/5636e3e5276b952facbd0aadb12a858a\",\"name\":\"Admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"caption\":\"Admin\"},\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Hack in Paris 2015 - Day Two - INTRINSEC","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2015-seconde-journee\/","og_locale":"en_US","og_type":"article","og_title":"Hack in Paris 2015 - Seconde journ\u00e9e","og_description":"KEYNOTE: ATTACKING SECURE COMMUNICATION: THE (SAD) STATE OF ENCRYPTED MESSAGING &#8211; Thomas Roth Depuis les [&hellip;]","og_url":"https:\/\/www.intrinsec.com\/en\/hack-in-paris-2015-seconde-journee\/","og_site_name":"INTRINSEC","article_published_time":"2015-07-01T13:33:27+00:00","author":"Admin","twitter_card":"summary_large_image","twitter_creator":"@Intrinsec","twitter_site":"@Intrinsec","twitter_misc":{"Written by":"Admin","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.intrinsec.com\/hack-in-paris-2015-seconde-journee\/#article","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/hack-in-paris-2015-seconde-journee\/"},"author":{"name":"Admin","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/5636e3e5276b952facbd0aadb12a858a"},"headline":"Hack in Paris 2015 &#8211; Seconde journ\u00e9e","datePublished":"2015-07-01T13:33:27+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intrinsec.com\/hack-in-paris-2015-seconde-journee\/"},"wordCount":1070,"commentCount":0,"publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"image":{"@id":"https:\/\/www.intrinsec.com\/hack-in-paris-2015-seconde-journee\/#primaryimage"},"thumbnailUrl":"","keywords":["conf\u00e9rence","hack in paris","HIP"],"articleSection":["Veille S\u00e9curit\u00e9"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intrinsec.com\/hack-in-paris-2015-seconde-journee\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.intrinsec.com\/hack-in-paris-2015-seconde-journee\/","url":"https:\/\/www.intrinsec.com\/hack-in-paris-2015-seconde-journee\/","name":"Hack in Paris 2015 - Day Two - INTRINSEC","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intrinsec.com\/hack-in-paris-2015-seconde-journee\/#primaryimage"},"image":{"@id":"https:\/\/www.intrinsec.com\/hack-in-paris-2015-seconde-journee\/#primaryimage"},"thumbnailUrl":"","datePublished":"2015-07-01T13:33:27+00:00","breadcrumb":{"@id":"https:\/\/www.intrinsec.com\/hack-in-paris-2015-seconde-journee\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intrinsec.com\/hack-in-paris-2015-seconde-journee\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/hack-in-paris-2015-seconde-journee\/#primaryimage","url":"","contentUrl":""},{"@type":"BreadcrumbList","@id":"https:\/\/www.intrinsec.com\/hack-in-paris-2015-seconde-journee\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.intrinsec.com\/"},{"@type":"ListItem","position":2,"name":"Hack in Paris 2015 &#8211; Seconde journ\u00e9e"}]},{"@type":"WebSite","@id":"https:\/\/www.intrinsec.com\/#website","url":"https:\/\/www.intrinsec.com\/","name":"INTRINSEC","description":"Our job is to protect yours.","publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intrinsec.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.intrinsec.com\/#organization","name":"INTRINSEC","alternateName":"ISEC","url":"https:\/\/www.intrinsec.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","contentUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","width":1322,"height":1322,"caption":"INTRINSEC"},"image":{"@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/Intrinsec","https:\/\/fr.linkedin.com\/company\/intrinsec","https:\/\/www.youtube.com\/channel\/UC0trUZAHNZOUbxYnNdecM4A"],"description":"Intrinsec, a consulting firm and pure-play French and European cybersecurity provider for over 30 years, specializes in offensive security and auditing (penetration testing\/red teams), GRC, and IMSS services such as SOC, CTI, and CERT. Intrinsec is qualified at PASSI High, PRIS High, and PACS levels by ANSSI.","email":"contact@intrinsec.com"},{"@type":"Person","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/5636e3e5276b952facbd0aadb12a858a","name":"Admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","caption":"Admin"},"url":"https:\/\/www.intrinsec.com\/en\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/228081","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/comments?post=228081"}],"version-history":[{"count":0,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/228081\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/elementor_library\/1861"}],"wp:attachment":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/media?parent=228081"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/categories?post=228081"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/tags?post=228081"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}