{"id":476929,"date":"2023-08-09T09:05:36","date_gmt":"2023-08-09T09:05:36","guid":{"rendered":""},"modified":"2023-09-05T11:13:43","modified_gmt":"2023-09-05T11:13:43","slug":"dns-reflection-attack","status":"publish","type":"wiki","link":"https:\/\/oneproxy.pro\/tr\/wiki\/dns-reflection-attack\/","title":{"rendered":"DNS yans\u0131ma sald\u0131r\u0131s\u0131"},"content":{"rendered":"<h2>Tarih ve K\u00f6ken<\/h2>\n<p>DNS yans\u0131ma sald\u0131r\u0131s\u0131, hedefin altyap\u0131s\u0131n\u0131 y\u00fcksek hacimli istenmeyen trafikle bunaltmak i\u00e7in Etki Alan\u0131 Ad\u0131 Sisteminin (DNS) \u00f6zelliklerinden yararlanan bir t\u00fcr da\u011f\u0131t\u0131lm\u0131\u015f hizmet reddi (DDoS) sald\u0131r\u0131s\u0131d\u0131r. Bu sald\u0131r\u0131, kurbana y\u00f6nelik trafik hacmini art\u0131rmak i\u00e7in a\u00e7\u0131k DNS \u00e7\u00f6z\u00fcmleyicilerden yararlan\u0131yor.<\/p>\n<p>DNS yans\u0131ma sald\u0131r\u0131lar\u0131n\u0131n ilk s\u00f6z\u00fc 2006 y\u0131llar\u0131na kadar uzan\u0131yor. \u0130lk DDoS sald\u0131r\u0131lar\u0131nda, sald\u0131rganlar \u00f6ncelikli olarak hedeflere do\u011frudan trafik sa\u011flamak i\u00e7in botnet&#039;leri kullan\u0131yordu. Ancak bu t\u00fcr sald\u0131r\u0131lara kar\u015f\u0131 savunmalar geli\u015ftik\u00e7e siber su\u00e7lular yeni taktikler aramaya ba\u015flad\u0131. A\u00e7\u0131k DNS \u00e7\u00f6z\u00fcmleyicilere sahte kaynak IP adresiyle DNS sorgular\u0131 g\u00f6ndererek, \u00e7\u00f6z\u00fcmleyicileri kurbana daha b\u00fcy\u00fck yan\u0131tlar g\u00f6ndermeye te\u015fvik ederek sald\u0131r\u0131y\u0131 g\u00fc\u00e7lendirebileceklerini ke\u015ffettiler.<\/p>\n<h2>DNS Reflection Sald\u0131r\u0131s\u0131 Hakk\u0131nda Detayl\u0131 Bilgi<\/h2>\n<p>Bir DNS yans\u0131ma sald\u0131r\u0131s\u0131 genellikle \u015fu ad\u0131mlar\u0131 izler:<\/p>\n<ol>\n<li>\n<p><strong>Sahte Kaynak IP&#039;si<\/strong>: Sald\u0131rgan, istek hedeften geliyormu\u015f gibi g\u00f6r\u00fcnmesini sa\u011flamak i\u00e7in bir DNS sorgu paketindeki kaynak IP adresini taklit eder.<\/p>\n<\/li>\n<li>\n<p><strong>DNS \u00c7\u00f6z\u00fcmleyicileri a\u00e7\u0131n<\/strong>: Sald\u0131rgan bu sahte DNS sorgular\u0131n\u0131 a\u00e7\u0131k DNS \u00e7\u00f6z\u00fcmleyicilere g\u00f6nderir. Bu \u00e7\u00f6z\u00fcmleyiciler herkesin eri\u015fimine a\u00e7\u0131kt\u0131r ve herhangi bir IP adresinden gelen sorgulara yan\u0131t verecek \u015fekilde yanl\u0131\u015f yap\u0131land\u0131r\u0131lm\u0131\u015flard\u0131r.<\/p>\n<\/li>\n<li>\n<p><strong>Amplifikasyon Fakt\u00f6r\u00fc<\/strong>: A\u00e7\u0131k DNS \u00e7\u00f6z\u00fcmleyiciler sahte sorgular\u0131 al\u0131r ve bunlar\u0131n me\u015fru istekler oldu\u011funa inanarak yan\u0131tlar\u0131n\u0131 hedefin IP adresini kullanarak hedefe g\u00f6nderir. Yan\u0131tlar genellikle orijinal sorgulardan \u00e7ok daha b\u00fcy\u00fckt\u00fcr ve bu da sald\u0131r\u0131 trafi\u011fini art\u0131r\u0131r.<\/p>\n<\/li>\n<li>\n<p><strong>Hedefi A\u015fmak<\/strong>: Art\u0131k \u00e7ok b\u00fcy\u00fck miktarda trafikle dolup ta\u015fan hedef, y\u00fcksek istek oran\u0131n\u0131 kar\u015f\u0131lamakta zorlan\u0131r, bu da hizmetin bozulmas\u0131na veya tamamen kullan\u0131lamaz duruma gelmesine neden olur.<\/p>\n<\/li>\n<\/ol>\n<h2>DNS Yans\u0131ma Sald\u0131r\u0131s\u0131n\u0131n Temel \u00d6zellikleri<\/h2>\n<p>DNS yans\u0131ma sald\u0131r\u0131s\u0131, onu \u00f6zellikle etkili k\u0131lan birka\u00e7 temel \u00f6zellik sergiliyor:<\/p>\n<ol>\n<li>\n<p><strong>Amplifikasyon Fakt\u00f6r\u00fc<\/strong>: Sald\u0131r\u0131, DNS sorgular\u0131 ve yan\u0131tlar\u0131 aras\u0131ndaki b\u00fcy\u00fck boyut fark\u0131ndan yararlan\u0131r. Bu b\u00fcy\u00fctme fakt\u00f6r\u00fc 50 ila 100 kat olabilir; bu, k\u00fc\u00e7\u00fck bir sorgunun \u00e7ok daha b\u00fcy\u00fck bir yan\u0131ta yol a\u00e7abilece\u011fi anlam\u0131na gelir.<\/p>\n<\/li>\n<li>\n<p><strong>Ba\u015flat\u0131lmas\u0131 Kolay<\/strong>: Sald\u0131r\u0131, sald\u0131rgan taraf\u0131ndan minimum d\u00fczeyde kaynak gerektirir ve bu da onu acemi siber su\u00e7lular i\u00e7in cazip hale getirir. \u0130nternette mevcut olan \u00e7ok say\u0131da a\u00e7\u0131k DNS \u00e7\u00f6z\u00fcmleyici, sald\u0131r\u0131n\u0131n ba\u015flat\u0131lmas\u0131n\u0131 daha da kolayla\u015ft\u0131r\u0131r.<\/p>\n<\/li>\n<li>\n<p><strong>Da\u011f\u0131t\u0131lm\u0131\u015f Do\u011fa<\/strong>: Di\u011fer DDoS sald\u0131r\u0131lar\u0131 gibi, DNS yans\u0131ma sald\u0131r\u0131s\u0131 da da\u011f\u0131t\u0131l\u0131r; bu, birden fazla kayna\u011f\u0131n hedefin ta\u015fmas\u0131na dahil oldu\u011fu anlam\u0131na gelir ve bu da sald\u0131r\u0131n\u0131n hafifletilmesini zorla\u015ft\u0131r\u0131r.<\/p>\n<\/li>\n<li>\n<p><strong>UDP Protokol\u00fc<\/strong>: Sald\u0131r\u0131 \u00f6ncelikli olarak \u0130letim Kontrol Protokol\u00fc (TCP) paketleri gibi el s\u0131k\u0131\u015fma gerektirmeyen Kullan\u0131c\u0131 Datagram Protokol\u00fc (UDP) paketleri kullan\u0131larak ger\u00e7ekle\u015ftirilir ve bu da kayna\u011fa do\u011fru izini s\u00fcrmeyi zorla\u015ft\u0131r\u0131r.<\/p>\n<\/li>\n<\/ol>\n<h2>DNS Yans\u0131ma Sald\u0131r\u0131s\u0131 T\u00fcrleri<\/h2>\n<p>DNS yans\u0131ma sald\u0131r\u0131lar\u0131, kullan\u0131lan DNS sorgusunun t\u00fcr\u00fcne ve yan\u0131t\u0131n boyutuna g\u00f6re kategorize edilebilir. En yayg\u0131n t\u00fcrler \u015funlar\u0131 i\u00e7erir:<\/p>\n<table>\n<thead>\n<tr>\n<th>Sald\u0131r\u0131 T\u00fcr\u00fc<\/th>\n<th>\u00d6zellikler<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Standart Sorgu<\/td>\n<td>Sald\u0131rgan normal bir DNS sorgusu g\u00f6nderir.<\/td>\n<\/tr>\n<tr>\n<td>Herhangi bir sorgu<\/td>\n<td>Sald\u0131rgan HERHANG\u0130 bir kay\u0131t i\u00e7in bir DNS sorgusu g\u00f6nderir.<\/td>\n<\/tr>\n<tr>\n<td>Var Olmayan Sorgu<\/td>\n<td>Sald\u0131rgan var olmayan alan adlar\u0131 i\u00e7in sorgu g\u00f6nderir.<\/td>\n<\/tr>\n<tr>\n<td>EDNS0 Sorgusu<\/td>\n<td>Sald\u0131rgan, yan\u0131t boyutunu art\u0131rmak i\u00e7in DNS Uzant\u0131 Mekanizmalar\u0131n\u0131 (EDNS0) kullan\u0131r.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>DNS Yans\u0131ma Sald\u0131r\u0131s\u0131n\u0131 Kullanma Yollar\u0131 ve \u00c7\u00f6z\u00fcmleri<\/h2>\n<p>DNS yans\u0131ma sald\u0131r\u0131lar\u0131, a\u015fa\u011f\u0131dakiler de dahil olmak \u00fczere \u00e7e\u015fitli \u015fekillerde k\u00f6t\u00fcye kullan\u0131lm\u0131\u015ft\u0131r:<\/p>\n<ol>\n<li>\n<p><strong>Hizmetleri aksat\u0131yor<\/strong>: Sald\u0131rganlar, \u00e7evrimi\u00e7i hizmetleri kesintiye u\u011fratmak i\u00e7in DNS yans\u0131tma sald\u0131r\u0131lar\u0131n\u0131 kullan\u0131r, bu da i\u015fletmelerin kesintiye u\u011framas\u0131na ve mali kay\u0131plara neden olur.<\/p>\n<\/li>\n<li>\n<p><strong>Kayna\u011f\u0131 Maskelemek<\/strong>: Sald\u0131rganlar, kaynak IP adresini taklit ederek sald\u0131r\u0131 trafi\u011finin kurban\u0131n IP&#039;sinden geliyormu\u015f gibi g\u00f6r\u00fcnmesini sa\u011flayabilir ve bu da olaya m\u00fcdahale s\u0131ras\u0131nda olas\u0131 kar\u0131\u015f\u0131kl\u0131\u011fa yol a\u00e7abilir.<\/p>\n<\/li>\n<li>\n<p><strong>Savunma \u00d6nlemlerini Atlamak<\/strong>: DNS yans\u0131ma sald\u0131r\u0131lar\u0131, g\u00fcvenlik ekiplerinin dikkatini ba\u015fka y\u00f6ne \u00e7ekmek i\u00e7in oyalama takti\u011fi olarak kullan\u0131labilirken, di\u011fer sald\u0131r\u0131lar e\u015f zamanl\u0131 olarak ger\u00e7ekle\u015ftirilir.<\/p>\n<\/li>\n<\/ol>\n<h3>\u00c7\u00f6z\u00fcmler:<\/h3>\n<ol>\n<li>\n<p><strong>H\u0131z S\u0131n\u0131rlamas\u0131<\/strong>: \u0130nternet Servis Sa\u011flay\u0131c\u0131lar\u0131 (ISP&#039;ler) ve DNS \u00e7\u00f6z\u00fcmleyici operat\u00f6rleri, belirli bir IP adresine g\u00f6nderdikleri yan\u0131tlar\u0131n say\u0131s\u0131n\u0131 k\u0131s\u0131tlamak i\u00e7in h\u0131z s\u0131n\u0131rlay\u0131c\u0131 politikalar uygulayabilir ve bu da y\u00fckseltme fakt\u00f6r\u00fcn\u00fc azaltabilir.<\/p>\n<\/li>\n<li>\n<p><strong>Kaynak IP Do\u011frulamas\u0131<\/strong>: DNS \u00e7\u00f6z\u00fcmleyicileri, yan\u0131tlar\u0131n yaln\u0131zca me\u015fru istek sahiplerine g\u00f6nderilmesini sa\u011flamak i\u00e7in kaynak IP do\u011frulamas\u0131n\u0131 uygulayabilir.<\/p>\n<\/li>\n<li>\n<p><strong>DNS Yan\u0131t Boyutu S\u0131n\u0131r\u0131<\/strong>: A\u011f y\u00f6neticileri, DNS \u00e7\u00f6z\u00fcmleyicilerini, amplifikasyonu \u00f6nlemek amac\u0131yla yan\u0131tlar\u0131n boyutunu s\u0131n\u0131rlayacak \u015fekilde yap\u0131land\u0131rabilir.<\/p>\n<\/li>\n<li>\n<p><strong>A\u00e7\u0131k \u00c7\u00f6z\u00fcmleyicileri Filtreleme<\/strong>: \u0130SS&#039;ler ve a\u011f y\u00f6neticileri, sald\u0131r\u0131da k\u00f6t\u00fcye kullan\u0131mlar\u0131n\u0131 \u00f6nlemek i\u00e7in a\u00e7\u0131k DNS \u00e7\u00f6z\u00fcmleyicilerini tan\u0131mlayabilir ve filtreleyebilir.<\/p>\n<\/li>\n<\/ol>\n<h2>Ana \u00d6zellikler ve Kar\u015f\u0131la\u015ft\u0131rmalar<\/h2>\n<table>\n<thead>\n<tr>\n<th>karakteristik<\/th>\n<th>DNS Yans\u0131ma Sald\u0131r\u0131s\u0131<\/th>\n<th>DNS Geni\u015fletme Sald\u0131r\u0131s\u0131<\/th>\n<th>DNS Flood Sald\u0131r\u0131s\u0131<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Sald\u0131r\u0131 Y\u00f6ntemi<\/td>\n<td>Trafi\u011fi art\u0131rmak i\u00e7in a\u00e7\u0131k \u00e7\u00f6z\u00fcmleyicilerden yararlan\u0131r<\/td>\n<td>Trafi\u011fi art\u0131rmak i\u00e7in yanl\u0131\u015f yap\u0131land\u0131r\u0131lm\u0131\u015f DNS sunucular\u0131n\u0131 kullan\u0131r<\/td>\n<td>Y\u00fcksek istek oran\u0131yla hedefin DNS altyap\u0131s\u0131n\u0131 zorlar<\/td>\n<\/tr>\n<tr>\n<td>Amplifikasyon Fakt\u00f6r\u00fc<\/td>\n<td>Y\u00fcksek (50-100x)<\/td>\n<td>Y\u00fcksek (10-100x)<\/td>\n<td>D\u00fc\u015f\u00fck<\/td>\n<\/tr>\n<tr>\n<td>Uygulaman\u0131n Zorlu\u011fu<\/td>\n<td>Nispeten kolay<\/td>\n<td>Nispeten kolay<\/td>\n<td>Daha fazla kaynak gerektirir<\/td>\n<\/tr>\n<tr>\n<td>\u0130zlenebilirlik<\/td>\n<td>\u0130zini s\u00fcrmek daha zor<\/td>\n<td>\u0130zini s\u00fcrmek daha zor<\/td>\n<td>\u0130zini s\u00fcrmek daha zor<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Perspektifler ve Gelece\u011fin Teknolojileri<\/h2>\n<p>\u0130nternet geli\u015fmeye devam ettik\u00e7e, a\u00e7\u0131k DNS \u00e7\u00f6z\u00fcmleyicilerdeki do\u011fal g\u00fcvenlik a\u00e7\u0131klar\u0131 nedeniyle DNS yans\u0131tma sald\u0131r\u0131lar\u0131 devam edebilir. Ancak, DNSSEC&#039;nin (Alan Ad\u0131 Sistemi G\u00fcvenlik Uzant\u0131lar\u0131) da\u011f\u0131t\u0131m\u0131 ve daha g\u00fcvenli DNS \u00e7\u00f6z\u00fcmleyici yap\u0131land\u0131rmalar\u0131 gibi a\u011f g\u00fcvenli\u011findeki geli\u015fmeler, bu t\u00fcr sald\u0131r\u0131lar\u0131n etkisini \u00f6nemli \u00f6l\u00e7\u00fcde azaltabilir.<\/p>\n<p>Gelecekteki teknolojiler, a\u00e7\u0131k \u00e7\u00f6z\u00fcmleyicilerin k\u00f6t\u00fcye kullan\u0131lmas\u0131n\u0131 tespit etmek ve \u00f6nlemek i\u00e7in DNS \u00e7\u00f6z\u00fcmleyici d\u00fczeyinde geli\u015fmi\u015f izleme ve filtreleme mekanizmalar\u0131na odaklanabilir. Ek olarak, yanl\u0131\u015f yap\u0131land\u0131rmalar\u0131 proaktif bir \u015fekilde ele almak i\u00e7in ISP&#039;ler ve a\u011f y\u00f6neticileri aras\u0131ndaki geli\u015fmi\u015f i\u015fbirli\u011fi, DNS yans\u0131ma sald\u0131r\u0131lar\u0131 riskini daha da azaltabilir.<\/p>\n<h2>Proxy Sunucular\u0131 ve DNS Yans\u0131ma Sald\u0131r\u0131lar\u0131<\/h2>\n<p>Proxy sunucular\u0131, a\u00e7\u0131k DNS \u00e7\u00f6z\u00fcmleyicileri olarak g\u00f6rev yapacak \u015fekilde yanl\u0131\u015f yap\u0131land\u0131r\u0131l\u0131rsa, yanl\u0131\u015fl\u0131kla DNS yans\u0131ma sald\u0131r\u0131lar\u0131n\u0131n bir par\u00e7as\u0131 haline gelebilir. Sald\u0131rganlar, sald\u0131r\u0131 trafi\u011fini art\u0131rmak ve hedeflenen hedefe y\u00f6nlendirmek i\u00e7in bu t\u00fcr yanl\u0131\u015f yap\u0131land\u0131rmalardan yararlanabilir. OneProxy gibi proxy sunucu sa\u011flay\u0131c\u0131lar\u0131, sunucular\u0131n\u0131n bu t\u00fcr sald\u0131r\u0131larda kullan\u0131lmas\u0131n\u0131 \u00f6nlemek i\u00e7in s\u0131k\u0131 g\u00fcvenlik \u00f6nlemleri uygulamal\u0131d\u0131r.<\/p>\n<h2>\u0130lgili Ba\u011flant\u0131lar<\/h2>\n<p>DNS yans\u0131ma sald\u0131r\u0131lar\u0131 hakk\u0131nda daha fazla bilgi i\u00e7in a\u015fa\u011f\u0131daki kaynaklara ba\u015fvurabilirsiniz:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.cert.org\/incident-management\/knowledge-catalog\/Domain_Name_System_DNS_Amplification_Attacks.cfm\" target=\"_new\" rel=\"noopener nofollow\">CERT Koordinasyon Merkezi: DNS Y\u00fckseltme Sald\u0131r\u0131lar\u0131<\/a><\/li>\n<li><a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/TA13-088A\" target=\"_new\" rel=\"noopener nofollow\">US-CERT Uyar\u0131s\u0131: DNS Y\u00fckseltme Sald\u0131r\u0131lar\u0131<\/a><\/li>\n<li><a href=\"https:\/\/www.cloudflare.com\/en-gb\/learning\/ddos\/dns-amplification-ddos-attack\/\" target=\"_new\" rel=\"noopener nofollow\">Cloudflare: DNS Y\u00fckseltme Sald\u0131r\u0131lar\u0131<\/a><\/li>\n<\/ul>\n<p>Unutmay\u0131n, siber tehditlere kar\u015f\u0131 bilgili ve tetikte olmak, \u00e7evrimi\u00e7i hizmetlerin b\u00fct\u00fcnl\u00fc\u011f\u00fcn\u00fc ve kullan\u0131labilirli\u011fini korumak a\u00e7\u0131s\u0131ndan \u00e7ok \u00f6nemlidir.<\/p>","protected":false},"featured_media":476930,"menu_order":0,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-476929","wiki","type-wiki","status-publish","has-post-thumbnail","hentry"],"acf":{"faq_title":"Frequently Asked Questions about <mark>DNS Reflection Attack: An Overview<\/mark>","faq_items":[{"question":"What is a DNS reflection attack?","answer":"<p>A DNS reflection attack is a type of distributed denial of service (DDoS) attack that exploits the Domain Name System (DNS) to flood a target's infrastructure with a high volume of unwanted traffic. Attackers use open DNS resolvers to amplify the attack traffic, making it harder for the target to handle the influx of requests.<\/p>"},{"question":"How did DNS reflection attacks originate?","answer":"<p>DNS reflection attacks were first mentioned around 2006 when cybercriminals sought new tactics to bypass improved DDoS attack defenses. By spoofing the source IP address in DNS queries and using open resolvers, attackers could amplify their attack traffic and overwhelm the target.<\/p>"},{"question":"How does a DNS reflection attack work?","answer":"<p>A DNS reflection attack involves several steps:<\/p><ol><li>The attacker spoofs the source IP address in DNS queries to make it appear as if the requests are coming from the target.<\/li><li>These forged queries are sent to open DNS resolvers, which send much larger responses to the victim, amplifying the attack traffic.<\/li><li>The target becomes overwhelmed by the massive volume of traffic and may experience service degradation or complete unavailability.<\/li><\/ol>"},{"question":"What are the key features of a DNS reflection attack?","answer":"<p>DNS reflection attacks are particularly effective due to:<\/p><ul><li>Amplification factor: Attack traffic can be amplified by 50 to 100 times, making even small queries generate large responses.<\/li><li>Ease of launch: The attack requires minimal resources, attracting novice attackers.<\/li><li>Distributed nature: Multiple sources participate in the attack, making it challenging to mitigate.<\/li><li>Use of UDP protocol: UDP packets are used, making it harder to trace back to the source.<\/li><\/ul>"},{"question":"What types of DNS reflection attacks exist?","answer":"<p>DNS reflection attacks can be categorized based on the type of DNS query used and the response size. Common types include standard queries, ANY queries, non-existent queries, and EDNS0 queries.<\/p>"},{"question":"How are DNS reflection attacks used and how can they be countered?","answer":"<p>DNS reflection attacks are misused to disrupt services, mask the source, and divert security teams' attention. To counter these attacks, rate limiting, source IP validation, response size limits, and filtering open resolvers are effective solutions.<\/p>"},{"question":"How does the future look for DNS reflection attacks?","answer":"<p>While DNS reflection attacks may persist, future technologies like DNSSEC and improved DNS resolver configurations can mitigate their impact. Enhanced monitoring and filtering mechanisms can also help prevent open resolvers from being exploited.<\/p>"},{"question":"How are proxy servers associated with DNS reflection attacks?","answer":"<p>Proxy servers can inadvertently become part of DNS reflection attacks if misconfigured as open DNS resolvers. Proxy server providers like OneProxy must implement stringent security measures to prevent their servers from being exploited in such attacks.<\/p>"}]},"_links":{"self":[{"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/wiki\/476929","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/wiki"}],"about":[{"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/types\/wiki"}],"version-history":[{"count":0,"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/wiki\/476929\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/media\/476930"}],"wp:attachment":[{"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/media?parent=476929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}