首页 开发文档 注入攻击检测

注入攻击检测

注入攻击特征检测。内置五大类规则:SQL 注入(布尔恒真、UNION 查询、堆叠语句、延时盲注、注释截断等)、XSS(script 标签、事件属性、javascript: 伪协议等)、命令注入(管道与反引号、系统命令拼接)、路径穿越(../ 与敏感文件路径)、SSRF(内网地址、云元数据地址、file/gopher 等危险协议)。返回风险等级与命中的具体片段,可用于验证自身系统的输入过滤是否有效。

请求信息
请求地址 https://cx4.cn/openApi/risk/inject 复制
请求方式 GET / POST
接口标识 risk_inject
鉴权方式 必须
四种方式任选其一:Header「X-Api-Key」/ Header「Authorization: Bearer 你的key」/ URL 参数「?key=你的key」/ POST 参数「key」
请求参数
参数名 类型 必填 说明 示例
text string 是 待检测内容,最多 50000 字节 1' OR '1'='1
type string 否 all 全部 / sql / xss / cmd / path / ssrf 单类检测 all
返回参数

下表字段位于返回结构的 data 内;外层 code / message 为全平台统一格式,不在此重复列出。

参数名 类型 说明 示例
ok bool 是否成功 true
type string 检测类型 all
risky bool 是否发现风险特征 true
risk_level string 风险等级:none / low / medium / high high
hit_count int 命中规则条数 1
hits array 命中明细,含分组、规则名、等级与片段 []
length int 检测内容长度 13
note string 使用说明 本接口用于自查自身系统的输入过滤
返回示例

成功

{
    "code": 200,
    "message": "操作成功",
    "data": {
        "ok": true,
        "type": "all",
        "risky": true,
        "risk_level": "high",
        "hit_count": 1,
        "hits": [
            {
                "group": "sql",
                "rule": "布尔条件恒真",
                "level": "high",
                "sample": "OR '1'='1"
            }
        ],
        "length": 12,
        "note": "规则匹配仅供参考(存在误报),用于自身系统安全自查,不代表目标系统存在漏洞"
    }
}

失败

{
    "code": 400,
    "message": "缺少待检测内容",
    "data": null
}
平台通用状态码
状态码 说明
200调用成功
400缺少必填参数或参数格式有误
401密钥缺失或无效
402余额不足,请充值后重试
403未开通该接口,请在本页开通后调用
404接口不存在或已下架
429触发限流,请稍后重试
500接口调用失败(已扣款的会自动退款)
调用示例

cURL 复制

curl -X POST "https://cx4.cn/openApi/risk/inject" -H "X-Api-Key: 你的SecretKey" -d "text=1' OR '1'='1&type=all"

JavaScript 复制

fetch('https://cx4.cn/openApi/risk/inject', {
  method: 'POST',
  headers: {
    'X-Api-Key': '你的SecretKey',
    'Content-Type': 'application/x-www-form-urlencoded'
  },
  body: 'text=1' OR '1'='1&type=all'
})
.then(res => res.json())
.then(data => console.log(data));

PHP 复制

post('https://cx4.cn/openApi/risk/inject', [
    'headers' => ['X-Api-Key' => '你的SecretKey'],
    'form_params' => ['text' => '1' OR '1'='1', 'type' => 'all'],
]);
echo $response->getBody();

Java 复制

HttpClient client = HttpClient.newHttpClient();
HttpRequest request = HttpRequest.newBuilder()
    .uri(URI.create("https://cx4.cn/openApi/risk/inject"))
    .header("X-Api-Key", "你的SecretKey")
    .header("Content-Type", "application/x-www-form-urlencoded")
    .POST(HttpRequest.BodyPublishers.ofString("text=1' OR '1'='1&type=all"))
    .build();
HttpResponse response = client.send(
        request, HttpResponse.BodyHandlers.ofString());
System.out.println(response.body());

Python 复制

import requests

res = requests.post('https://cx4.cn/openApi/risk/inject',
    headers={'X-Api-Key': '你的SecretKey'},
    data={'text': '1' OR '1'='1', 'type': 'all'})
print(res.json())
在线测试 (使用你的密钥真实调用,计费与正常调用一致)

登录后可在线测试: 立即登录

计费说明

¥0.0010

每次调用


每日免费额度:100 次

累计调用:6 次


快速上手

1. 注册并完成邮箱验证:立即注册

2. 登录后复制 Secret Key:去登录

3. 点击右侧「开通接口」按钮

4. 用下方「在线测试」一键体验,或复制下方示例代码直接调用