Elektrine lite

โ† Feed

Gareth Heyes :verified:

gaz@infosec.exchange

<p>Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. </p><p><a href="https://garethheyes.co.uk/" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">garethheyes.co.uk/</span><span class="invisible"></span></a> <br /><a href="https://javascriptforhackers.co.uk/" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">javascriptforhackers.co.uk/</span><span class="invisible"></span></a></p>

Posts

  • View post

    Chrome&#39;s new tag has something to say: Another XSS vector for our cheat sheet, found by omidxrz. https://portswigger.net/web-security/cross-site-scripting/cheat-sheet#onvalidationstatuschange

  • View post

    I&#39;ve released Burp Hackvertor v2.2.67. This version supports the check tag and expressions. You can read how to use them here: https://github.com/hackvertor/hackvertor/wiki/Tag-Syntax#tag-expressions I&#39;d love any feedback you have, let me know if the expressions are powerful enough.

  • View post

    Shazzer can now fuzz over 1 million characters now. I got Claude to refactor the fuzzing code and now it fuzzes in chunks. This is amazingly fast on Chromium based browsers because sandboxed iframes are process isolated. Firefox is pretty slow because it does not do this.

  • View post

    Shazzer now displays ranges in nice unicode groups. I made the decision to convert large amount of character logs into ranges a while ago, this compresses the data really well and I can show massive amounts of data like JS variables easily.

  • View post

    I think this is the best most elegant XSS vector I&amp;#39;ve ever found. It still works in Safari. Here&amp;#39;s the write up: https://thespanner.co.uk/xssing-typeerrors-in-safari

  • View post

    Just finished an improved toast dialog in Shazzer. It now shows the char codes with a preview of the character too when you press &amp;quot;Test Fuzz&amp;quot; or &amp;quot;Fuzz&amp;quot;. If the character isn&amp;#39;t printable it shows hex instead. https://shazzer.co.uk/

  • View post

    On my lunch today I improve the Shazzer fuzz results toast. It looks really nice and can handle ranges easily.

  • View post

    I&amp;#39;ve added performance/feature vectors to Shazzer. Along with stats. You can now see which browsers perform better. It uses the same shared fuzzing network. https://shazzer.co.uk/stats/performance

  • View post

    Messing around with inertia on my blog. Demo: https://thespanner.co.uk/

  • View post

    You can now make a batch of private vectors public and assign them a collection in Shazzer. This is useful when presenting at a conference and you want to make a few public after the talk.

  • View post

    Both Hackvertor &amp;amp; Shazzer evolve the more you use them. It&amp;#39;s such a shame they are not widely used and everyone is just using an LLM these days. That said I&amp;#39;ve found them both essential for conducting web security research.

  • View post

    My 3D world now has collision detection in CSS! If you run into a wall or door it will stop. Open the door and you can go through. This model is unbelievable. https://garethheyes.co.uk/

  • View post

    Next week I&amp;#39;m going to make you terrified of opening your emails...Join me at Black Hat USA for CSS:the bomb inside your inbox

  • View post

    I&#39;ve wrote up how to do collision detection in pure CSS. I had loads of fun doing this. https://thespanner.co.uk/pure-css-3d-world-collision-detection

  • View post

    Fixed the teleports on my site. The burger menu now works on all browsers. I&#39;d previously tried to get this working and failed. Opus just did it in about 5 mins. https://garethheyes.co.uk/

  • View post

    I redesigned my website using Claude. I burned through a lot of tokens. I basically put all my research in a hallway and created a bookshelf of links. Yes I was up till 1am doing this ๐Ÿ˜‚ it even works on the iPhone. No JS! https://garethheyes.co.uk/

  • View post

    I haven&#39;t posted a crazy XSS vector for a while... Works on every browser https://portswigger-labs.net/xss/xss.php?x=%3Calert(1)%20onfocus=%22attributes[0].value=localName,new%20onfocus%22%20autofocus%20tabindex=1%3E

  • View post

    Hackvertor evolves as you add tags. You&#39;re not just adding a new encoding, you&#39;re teaching the auto-decoder how to recognise and decode it too. Every custom tag makes Hackvertor smarter for future use. Read the tutorial to find out more... https://thespanner.co.uk/how-to-write-a-hackvertor-tag

  • View post

    I have a passion for 3D. I used to read 3D world magazine every month and the CD always contained trial software. I used to love messing around with 3D max and Poser. As I often do my interests pour into my research or projects. I made a 3D portfolio and a 3D tile blog. Check them out: 3D portfolio: https://garethheyes.co.uk/ 3D tile blog: https://thespanner.co.uk/

  • View post

    Shazzer &amp;amp; Hackvertor OAuth was broken because of a Github change. Hopefully I&amp;#39;ve fixed the issues now.

  • View post

    If you haven&amp;#39;t tried Shazzer yet you should give it a go. You can easily find browser behaviour and get it tested by other users or your team. It supports private vectors too and you can assign them to your team. You can even have your own private fuzzing network. ๐Ÿ”ฅ๐Ÿ”ฅ๐Ÿ”ฅ

  • View post

    RE: https://infosec.exchange/@cure53/116441365961018637 ๐Ÿ˜‚

  • View post

    String.fromCharCode overflows. I didn&amp;#39;t know how this worked many years ago. Now it seems so simple. The maximum value a character can be generated is 0xffff. So if you want to generate A (0x41) you simply add one to the max value plus the character you want to generate. 0x10000 is 0xffff+1. So to generate A you do: String.fromCharCode(0x10000 + 0x41)//A All this is explained in: https://portswigger.net/research/splitting-the-email-atom

  • View post

    I needed code snippets for presentations. I was worried about pasting code snippets into untrusted sites. So I just wrote my own using AI. You can trust I won&amp;#39;t be tracking your code. It&amp;#39;s very customisable and the default is for presentations and has the option for twitter too. https://hackvertor.co.uk/snippet

  • View post

    Shazzer is now a social network. You can post messages, links and vectors. Let&amp;#39;s build and break it together and create a true web security social network. https://shazzer.co.uk/

  • View post

    After extensive testing with more generic versions, I decided to make browser version numbers more accurate now in Shazzer. This will create more fuzz data but will be more useful to test quirks in browsers. I&amp;#39;ve also hid older browser versions by default and provide filtering.

  • View post

    I broke Shazzer, should be fixed now

  • View post

    Added AI features to Shazzer using Chrome&amp;#39;s local model. They aren&amp;#39;t very useful yet because the local model is very slow and isn&amp;#39;t very smart but should improve over time when the model is updated. I&amp;#39;ve added: - AI write description - AI generate vector - AI generate variant

  • View post

    Allowed you to use Chrome&amp;#39;s local AI model in Hackvertor tags. Warning it&amp;#39;s very slow but should get better with time. You have to enable the local model in chrome://flags for it to work. https://hackvertor.co.uk/urls/33

  • View post

    You may have noticed I&amp;#39;ve been a bit quiet on social media recently, this is why...I&amp;#39;m going to present at Black Hat! Can&amp;#39;t wait to present these techniques! Here is a link to the abstract in case the screenshot is hard to read: https://blackhat.com/us-26/briefings/schedule/index.html#css-the-bomb-inside-your-inbox-51909