知盾网络安全研究中心 All systems normal Report [email protected] Hotline 400-820-0110
Current threat level

Security Self-check Tools

Three tools · all computed in your browser

These tools never send what you type to any server. Judgements rely on public rules and word lists, and every hit is shown below. They support your judgement — they do not replace the police or official channels.

TOOL 01

Password Strength

Local · no upload
Enter a password to test
Crack time assumes 10 billion offline guesses per second — consumer GPU-cluster scale. Online attacks are far slower, but once a password vault leaks, attackers get the offline scenario.
Passphrase advice
  • ·Length first: a 16-char passphrase of four random words beats 8 chars of mixed symbols — and is easier to remember
  • ·Never reuse one password across sites, especially email and banking
  • ·Keep passwords in a manager; memorize only the master password
  • ·Turn on two-factor auth for critical accounts — it is the last door when a password leaks
  • ·Avoid name pinyin, birthdays, phone numbers, plate numbers — all are in cracking dictionaries
TOOL 02

Scam Script Detector

12 scam classes · 108 feature keywords
Paste a suspicious SMS / chat message
Detection relies on script keywords that recur across scam types: more hits and higher weights mean higher risk. Zero hits does not mean safe — new scripts appear constantly. The final rule stays: if money is involved, hang up, call back, verify.
TOOL 03

URL Risk Check

11 heuristic rules
Enter a suspicious URL
What decides which server you actually reach is always the registered domain (the highlighted segment) — not the subdomain in front, not the path behind. The HTTPS lock only means the transport is encrypted; it says nothing about who is on the other side.
ZHIDUN / SENTINEL