调用VirusTotal URL分析API遇404错误,ID含多余===求助
解决VirusTotal URL报告API 404错误问题
你的问题核心是VirusTotal返回的URL ID包含base64填充字符===,直接拼接URL会导致API无法识别,即使做了trim()处理也无效——这些=是合法的base64填充符,必须做URL编码才能被API正确解析。
修复步骤:
- 对获取到的ID进行URL编码:第一次调用API拿到ID后,在
trim()基础上用encodeURIComponent()对ID编码,再传递给查询报告的函数。 - 修正函数参数传递:确保查询报告的函数能正确接收编码后的ID,避免变量作用域问题。
修改后的完整代码:
1. 首次调用获取URL分析ID
const apiKey = '你的实际API Key'; // 替换为你的VirusTotal API Key const urlToScan = '要扫描的目标URL'; // 替换为你要检测的URL console.log("testing in progress"); const data = `url=${encodeURIComponent(urlToScan)}`; var response; const xhr = new XMLHttpRequest(); xhr.withCredentials = true; xhr.addEventListener('readystatechange', function () { if (this.readyState === this.DONE) { console.log(this.responseText); response = JSON.parse(this.responseText); var id = response.data.id; console.log(id); // 对ID编码后传递给报告查询函数 getReport(encodeURIComponent(id.trim())); } }); xhr.open('POST', 'https://www.virustotal.com/api/v3/urls'); xhr.setRequestHeader('accept', 'application/json'); xhr.setRequestHeader('x-apikey', apiKey); xhr.setRequestHeader('content-type', 'application/x-www-form-urlencoded'); xhr.send(data);
2. 获取URL报告的函数
function getReport(encodedId) { const data = null; const apiKey = '你的实际API Key'; // 替换为你的VirusTotal API Key const xhr = new XMLHttpRequest(); xhr.withCredentials = true; xhr.addEventListener('readystatechange', function () { if (this.readyState === this.DONE) { console.log(this.responseText); } }); // 使用编码后的ID拼接请求URL xhr.open('GET', `https://www.virustotal.com/api/v3/urls/${encodedId}`); xhr.setRequestHeader('accept', 'application/json'); xhr.setRequestHeader('x-apikey', apiKey); xhr.send(data); }
原因说明:
VirusTotal返回的URL ID是目标URL的base64编码结果,末尾的===是base64标准的填充字符。在URL规则中,=属于特殊字符,直接拼接会被服务器错误解析,导致API无法匹配到对应的扫描记录,最终返回404。通过encodeURIComponent()将=转换为%3D后,API就能正确识别这个ID了。
内容的提问来源于stack exchange,提问作者newbieInProgramming
相关产品推荐
相关产品推荐

