Gareth Heyes :verified:
gaz@infosec.exchange
<p>Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. </p><p><a href="https://garethheyes.co.uk/" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">garethheyes.co.uk/</span><span class="invisible"></span></a> <br /><a href="https://javascriptforhackers.co.uk/" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">javascriptforhackers.co.uk/</span><span class="invisible"></span></a></p>
Posts
-
View post
Chrome's new tag has something to say: Another XSS vector for our cheat sheet, found by omidxrz. https://portswigger.net/web-security/cross-site-scripting/cheat-sheet#onvalidationstatuschange
-
View post
I've released Burp Hackvertor v2.2.67. This version supports the check tag and expressions. You can read how to use them here: https://github.com/hackvertor/hackvertor/wiki/Tag-Syntax#tag-expressions I'd love any feedback you have, let me know if the expressions are powerful enough.
-
View post
Shazzer can now fuzz over 1 million characters now. I got Claude to refactor the fuzzing code and now it fuzzes in chunks. This is amazingly fast on Chromium based browsers because sandboxed iframes are process isolated. Firefox is pretty slow because it does not do this.
-
View post
Shazzer now displays ranges in nice unicode groups. I made the decision to convert large amount of character logs into ranges a while ago, this compresses the data really well and I can show massive amounts of data like JS variables easily.
-
View post
I think this is the best most elegant XSS vector I&#39;ve ever found. It still works in Safari. Here&#39;s the write up: https://thespanner.co.uk/xssing-typeerrors-in-safari
-
View post
Just finished an improved toast dialog in Shazzer. It now shows the char codes with a preview of the character too when you press &quot;Test Fuzz&quot; or &quot;Fuzz&quot;. If the character isn&#39;t printable it shows hex instead. https://shazzer.co.uk/
-
View post
On my lunch today I improve the Shazzer fuzz results toast. It looks really nice and can handle ranges easily.
-
View post
I&#39;ve added performance/feature vectors to Shazzer. Along with stats. You can now see which browsers perform better. It uses the same shared fuzzing network. https://shazzer.co.uk/stats/performance
-
View post
Messing around with inertia on my blog. Demo: https://thespanner.co.uk/
-
View post
You can now make a batch of private vectors public and assign them a collection in Shazzer. This is useful when presenting at a conference and you want to make a few public after the talk.
-
View post
Both Hackvertor &amp; Shazzer evolve the more you use them. It&#39;s such a shame they are not widely used and everyone is just using an LLM these days. That said I&#39;ve found them both essential for conducting web security research.
-
View post
My 3D world now has collision detection in CSS! If you run into a wall or door it will stop. Open the door and you can go through. This model is unbelievable. https://garethheyes.co.uk/
-
View post
Next week I&#39;m going to make you terrified of opening your emails...Join me at Black Hat USA for CSS:the bomb inside your inbox
-
View post
I've wrote up how to do collision detection in pure CSS. I had loads of fun doing this. https://thespanner.co.uk/pure-css-3d-world-collision-detection
-
View post
Fixed the teleports on my site. The burger menu now works on all browsers. I'd previously tried to get this working and failed. Opus just did it in about 5 mins. https://garethheyes.co.uk/
-
View post
I redesigned my website using Claude. I burned through a lot of tokens. I basically put all my research in a hallway and created a bookshelf of links. Yes I was up till 1am doing this ๐ it even works on the iPhone. No JS! https://garethheyes.co.uk/
-
View post
I haven't posted a crazy XSS vector for a while... Works on every browser https://portswigger-labs.net/xss/xss.php?x=%3Calert(1)%20onfocus=%22attributes[0].value=localName,new%20onfocus%22%20autofocus%20tabindex=1%3E
-
View post
Hackvertor evolves as you add tags. You're not just adding a new encoding, you're teaching the auto-decoder how to recognise and decode it too. Every custom tag makes Hackvertor smarter for future use. Read the tutorial to find out more... https://thespanner.co.uk/how-to-write-a-hackvertor-tag
-
View post
I have a passion for 3D. I used to read 3D world magazine every month and the CD always contained trial software. I used to love messing around with 3D max and Poser. As I often do my interests pour into my research or projects. I made a 3D portfolio and a 3D tile blog. Check them out: 3D portfolio: https://garethheyes.co.uk/ 3D tile blog: https://thespanner.co.uk/
-
View post
Shazzer &amp; Hackvertor OAuth was broken because of a Github change. Hopefully I&#39;ve fixed the issues now.
-
View post
If you haven&#39;t tried Shazzer yet you should give it a go. You can easily find browser behaviour and get it tested by other users or your team. It supports private vectors too and you can assign them to your team. You can even have your own private fuzzing network. ๐ฅ๐ฅ๐ฅ
-
View post
RE: https://infosec.exchange/@cure53/116441365961018637 ๐
-
View post
String.fromCharCode overflows. I didn&#39;t know how this worked many years ago. Now it seems so simple. The maximum value a character can be generated is 0xffff. So if you want to generate A (0x41) you simply add one to the max value plus the character you want to generate. 0x10000 is 0xffff+1. So to generate A you do: String.fromCharCode(0x10000 + 0x41)//A All this is explained in: https://portswigger.net/research/splitting-the-email-atom
-
View post
I needed code snippets for presentations. I was worried about pasting code snippets into untrusted sites. So I just wrote my own using AI. You can trust I won&#39;t be tracking your code. It&#39;s very customisable and the default is for presentations and has the option for twitter too. https://hackvertor.co.uk/snippet
-
View post
Shazzer is now a social network. You can post messages, links and vectors. Let&#39;s build and break it together and create a true web security social network. https://shazzer.co.uk/
-
View post
After extensive testing with more generic versions, I decided to make browser version numbers more accurate now in Shazzer. This will create more fuzz data but will be more useful to test quirks in browsers. I&#39;ve also hid older browser versions by default and provide filtering.
-
View post
I broke Shazzer, should be fixed now
-
View post
Added AI features to Shazzer using Chrome&#39;s local model. They aren&#39;t very useful yet because the local model is very slow and isn&#39;t very smart but should improve over time when the model is updated. I&#39;ve added: - AI write description - AI generate vector - AI generate variant
-
View post
Allowed you to use Chrome&#39;s local AI model in Hackvertor tags. Warning it&#39;s very slow but should get better with time. You have to enable the local model in chrome://flags for it to work. https://hackvertor.co.uk/urls/33
-
View post
You may have noticed I&#39;ve been a bit quiet on social media recently, this is why...I&#39;m going to present at Black Hat! Can&#39;t wait to present these techniques! Here is a link to the abstract in case the screenshot is hard to read: https://blackhat.com/us-26/briefings/schedule/index.html#css-the-bomb-inside-your-inbox-51909