{"id":3742,"date":"2021-09-14T20:58:09","date_gmt":"2021-09-15T01:58:09","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3742"},"modified":"2021-09-14T20:58:10","modified_gmt":"2021-09-15T01:58:10","slug":"golden-saml-is-a-counterfeiting-threat","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/","title":{"rendered":"Golden SAML is a counterfeiting threat"},"content":{"rendered":"\n<p>The attack on SolarWinds Orion, carried out by the threat actor (UNC2452), has been one of the most elaborate on the supply chain, and uncovered one of the most innovative techniques: Golden SAML, now known as Solorigate el what will be the topic of today. In a golden SAML attack, attackers can gain access to any application that supports SAML authentication (e.g. Azure, AWS, vSphere, etc.) with the privileges they want and be any user in the target application (even a which does not exist in the app in some cases). At a time when more and more business infrastructure is moving to the cloud, Active Directory (AD) is no longer the ultimate authority for authenticating and authorizing users. AD can now be part of something bigger: a federation.<\/p>\n\n\n\n<p>A federation enables trust between different environments that would not otherwise be related, such as Microsoft AD, Azure, AWS, and many others. This trust enables a user in an AD, for example, to enjoy the benefits of SSO for all trusted environments in that federation. Speaking of a federation, one attacker will no longer be enough to dominate his victim&#8217;s domain controller.<\/p>\n\n\n\n<p>SAML&#8217;s golden name may remind you of another notorious attack known as Golden Ticket, which was introduced by Benjamin Delpy, known for his famous attack tool called Mimikatz. The similarity of the name is destined, as the nature of the attack is quite similar. Golden SAML presents to a federation the advantages that Golden Ticket offers in a Kerberos environment, from obtaining any type of access to maintaining persistence in a stealthy way. Golden SAML is an attack vector that can offer powerful benefits to attackers, including:<\/p>\n\n\n\n<p><strong><em>\u25b8Multifactor Authentication Bypass<\/em><\/strong> <\/p>\n\n\n\n<p>Using this technique can make the additional layer of security that MFA provides completely useless. Since users obtain a valid SAML token after authenticating using MFA, attackers using Golden SAML go straight to spoofing an identity using the stolen certificate, without having to know the user&#8217;s password or other authentication factors. This shows that the sense of security that MFA provides could be false in some cases.<\/p>\n\n\n\n<p><strong><em>\u25b8Flexibility<\/em><\/strong> <\/p>\n\n\n\n<p>Golden SAML allows attackers to impersonate almost any identity they want in the organization. Which benefits them for two reasons. First, because attackers capable of carrying out a Golden SAML attack can gain access to all the services or assets of the organization, as long as it is part of the community, of course, and the second is that if an attacker has the ability to carry out a Golden attack SAML, whatever action you intend to take, you can do it using the identity of a &#8220;known&#8221; user, which reduces the chances of being detected.<\/p>\n\n\n\n<p><strong><em>\u25b8Long-term persistence<\/em><\/strong><\/p>\n\n\n\n<p>Passwords are changed every certain period of time, but a SAML token signing certificate is almost never changed. This allows attackers to maintain their access for a long time.<\/p>\n\n\n\n<p><strong><em>\u25b8Difficulty solving<\/em><\/strong> <\/p>\n\n\n\n<p>When an attacker steals a SAML token signing certificate, things get complicated. Because if you try to change the passwords, the attacker can continue creating SAML tokens that impersonate that person, without the need to know the real password.<\/p>\n\n\n\n<p>More reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/nativezone-solarwinds-authors-return\/\">NativeZone \u2013 Solarwinds Authors Return<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/sunburst-the-biggest-malware-on-post-cold-war\/\">Sunburst \u2013 The Biggest Malware on Post-Cold War<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The attack on SolarWinds Orion, carried out by the threat actor (UNC2452), has been one of the most elaborate on the supply chain, and uncovered one of the most innovative techniques: Golden SAML, now known as Solorigate el what will be the topic of today. In a golden SAML attack, attackers can gain access to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3743,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-3742","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Golden SAML is a counterfeiting threat - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Today we will see a threat that gave much to talk about when it was discovered called Golden SAML and we will see why and what it does......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Golden SAML is a counterfeiting threat - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Today we will see a threat that gave much to talk about when it was discovered called Golden SAML and we will see why and what it does......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-09-15T01:58:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-09-15T01:58:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/Golden.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"667\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/golden-saml-is-a-counterfeiting-threat\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/golden-saml-is-a-counterfeiting-threat\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Golden SAML is a counterfeiting threat\",\"datePublished\":\"2021-09-15T01:58:09+00:00\",\"dateModified\":\"2021-09-15T01:58:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/golden-saml-is-a-counterfeiting-threat\\\/\"},\"wordCount\":540,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/golden-saml-is-a-counterfeiting-threat\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/Golden.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/golden-saml-is-a-counterfeiting-threat\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/golden-saml-is-a-counterfeiting-threat\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/golden-saml-is-a-counterfeiting-threat\\\/\",\"name\":\"Golden SAML is a counterfeiting threat - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/golden-saml-is-a-counterfeiting-threat\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/golden-saml-is-a-counterfeiting-threat\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/Golden.jpg\",\"datePublished\":\"2021-09-15T01:58:09+00:00\",\"dateModified\":\"2021-09-15T01:58:10+00:00\",\"description\":\"Today we will see a threat that gave much to talk about when it was discovered called Golden SAML and we will see why and what it does......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/golden-saml-is-a-counterfeiting-threat\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/golden-saml-is-a-counterfeiting-threat\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/golden-saml-is-a-counterfeiting-threat\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/Golden.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/Golden.jpg\",\"width\":1000,\"height\":667,\"caption\":\"Hooded hacker. Cyber attack concept.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/golden-saml-is-a-counterfeiting-threat\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Golden SAML is a counterfeiting threat\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Golden SAML is a counterfeiting threat - Truxgo Server Blog","description":"Today we will see a threat that gave much to talk about when it was discovered called Golden SAML and we will see why and what it does......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/","og_locale":"es_MX","og_type":"article","og_title":"Golden SAML is a counterfeiting threat - Truxgo Server Blog","og_description":"Today we will see a threat that gave much to talk about when it was discovered called Golden SAML and we will see why and what it does......","og_url":"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-09-15T01:58:09+00:00","article_modified_time":"2021-09-15T01:58:10+00:00","og_image":[{"width":1000,"height":667,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/Golden.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"3 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Golden SAML is a counterfeiting threat","datePublished":"2021-09-15T01:58:09+00:00","dateModified":"2021-09-15T01:58:10+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/"},"wordCount":540,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/Golden.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/","url":"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/","name":"Golden SAML is a counterfeiting threat - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/Golden.jpg","datePublished":"2021-09-15T01:58:09+00:00","dateModified":"2021-09-15T01:58:10+00:00","description":"Today we will see a threat that gave much to talk about when it was discovered called Golden SAML and we will see why and what it does......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/Golden.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/Golden.jpg","width":1000,"height":667,"caption":"Hooded hacker. Cyber attack concept."},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/golden-saml-is-a-counterfeiting-threat\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Golden SAML is a counterfeiting threat"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3742","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3742"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3742\/revisions"}],"predecessor-version":[{"id":3756,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3742\/revisions\/3756"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3743"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3742"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3742"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3742"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}