Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Gareth Heyes :verified:

@gaz@infosec.exchange
  • Open on infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor.

https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

2696 Followers
236 Following
50 Posts
Joined November 07, 2022
My web site:
https://garethheyes.co.uk/
PortSwigger Research:
https://portswigger.net/research
Github:
https://github.com/hackvertor/
My blog:
http://www.thespanner.co.uk/
JavaScript for hackers:
https://leanpub.com/javascriptforhackers/

Posts

Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 29, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Next week I'm going to make you terrified of opening your emails...Join me at Black Hat USA for CSS:the bomb inside your inbox

4
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 25, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange
I've wrote up how to do collision detection in pure CSS. I had loads of fun doing this. https://thespanner.co.uk/pure-css-3d-world-collision-detection
6
1
3
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 25, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange
Fixed the teleports on my site. The burger menu now works on all browsers. I'd previously tried to get this working and failed. Opus just did it in about 5 mins. https://garethheyes.co.uk/
1
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 24, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

My 3D world now has collision detection in CSS! If you run into a wall or door it will stop. Open the door and you can go through. This model is unbelievable.

https://garethheyes.co.uk/

4
1
1
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 24, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange
I redesigned my website using Claude. I burned through a lot of tokens. I basically put all my research in a hallway and created a bookshelf of links. Yes I was up till 1am doing this 😂 it even works on the iPhone. No JS! https://garethheyes.co.uk/
Your browser does not support the video tag.
1
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 21, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange
I haven't posted a crazy XSS vector for a while... Works on every browser https://portswigger-labs.net/xss/xss.php?x=%3Calert(1)%20onfocus=%22attributes[0].value=localName,new%20onfocus%22%20autofocus%20tabindex=1%3E
18
0
2
1
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 17, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Both Hackvertor & Shazzer evolve the more you use them. It's such a shame they are not widely used and everyone is just using an LLM these days. That said I've found them both essential for conducting web security research.

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 17, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange
Hackvertor evolves as you add tags. You're not just adding a new encoding, you're teaching the auto-decoder how to recognise and decode it too. Every custom tag makes Hackvertor smarter for future use. Read the tutorial to find out more... https://thespanner.co.uk/how-to-write-a-hackvertor-tag
0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 16, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

You can now make a batch of private vectors public and assign them a collection in Shazzer. This is useful when presenting at a conference and you want to make a few public after the talk.

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 14, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Messing around with inertia on my blog.

Demo:
https://thespanner.co.uk/

Your browser does not support the video tag.
0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 14, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy@social.security.plumbing @cure53@infosec.exchange Hehe cool I really enjoyed writing that book, it was great to collaborate with such talented people. I'm also glad the XSS payload in the subtitle fired on some random book site 😂
0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 08, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange
I have a passion for 3D. I used to read 3D world magazine every month and the CD always contained trial software. I used to love messing around with 3D max and Poser. As I often do my interests pour into my research or projects. I made a 3D portfolio and a 3D tile blog. Check them out: 3D portfolio: https://garethheyes.co.uk/ 3D tile blog: https://thespanner.co.uk/
0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 04, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

I've added performance/feature vectors to Shazzer. Along with stats. You can now see which browsers perform better. It uses the same shared fuzzing network.

https://shazzer.co.uk/stats/performance

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 03, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

On my lunch today I improve the Shazzer fuzz results toast. It looks really nice and can handle ranges easily.

1
0
1
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jul 02, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Just finished an improved toast dialog in Shazzer. It now shows the char codes with a preview of the character too when you press "Test Fuzz" or "Fuzz". If the character isn't printable it shows hex instead.

https://shazzer.co.uk/

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jun 29, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

I think this is the best most elegant XSS vector I've ever found. It still works in Safari. Here's the write up:
https://thespanner.co.uk/xssing-typeerrors-in-safari

26
1
7
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jun 10, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Shazzer now displays ranges in nice unicode groups. I made the decision to convert large amount of character logs into ranges a while ago, this compresses the data really well and I can show massive amounts of data like JS variables easily.

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jun 09, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Shazzer can now fuzz over 1 million characters now. I got Claude to refactor the fuzzing code and now it fuzzes in chunks. This is amazingly fast on Chromium based browsers because sandboxed iframes are process isolated. Firefox is pretty slow because it does not do this.

1
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · May 19, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

You may have noticed I've been a bit quiet on social media recently, this is why...I'm going to present at Black Hat!

Can't wait to present these techniques! Here is a link to the abstract in case the screenshot is hard to read:

https://blackhat.com/us-26/briefings/schedule/index.html#css-the-bomb-inside-your-inbox-51909

6
0
4
1
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · May 07, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Allowed you to use Chrome's local AI model in Hackvertor tags. Warning it's very slow but should get better with time. You have to enable the local model in chrome://flags for it to work.
https://hackvertor.co.uk/urls/33

1
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · May 07, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Added AI features to Shazzer using Chrome's local model. They aren't very useful yet because the local model is very slow and isn't very smart but should improve over time when the model is updated. I've added:

- AI write description
- AI generate vector
- AI generate variant

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · May 01, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

I broke Shazzer, should be fixed now

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · May 01, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy@social.security.plumbing I'm fully vibed lol
1
1
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · May 01, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

After extensive testing with more generic versions, I decided to make browser version numbers more accurate now in Shazzer. This will create more fuzz data but will be more useful to test quirks in browsers. I've also hid older browser versions by default and provide filtering.

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · May 01, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Shazzer is now a social network. You can post messages, links and vectors. Let's build and break it together and create a true web security social network.

https://shazzer.co.uk/

0
2
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Apr 28, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange
Replying to @dynom@toot.community
@dynom@toot.community Nah I wanted more customisation options and the ability to highlight selections etc
1
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Apr 28, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

I needed code snippets for presentations. I was worried about pasting code snippets into untrusted sites. So I just wrote my own using AI. You can trust I won't be tracking your code. It's very customisable and the default is for presentations and has the option for twitter too.

https://hackvertor.co.uk/snippet

1
2
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Apr 21, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

String.fromCharCode overflows. I didn't know how this worked many years ago. Now it seems so simple. The maximum value a character can be generated is 0xffff. So if you want to generate A (0x41) you simply add one to the max value plus the character you want to generate.

0x10000 is 0xffff+1. So to generate A you do:

String.fromCharCode(0x10000 + 0x41)//A

All this is explained in:

https://portswigger.net/research/splitting-the-email-atom

Splitting the email atom: exploiting parsers to bypass access controls
PortSwigger Research

Splitting the email atom: exploiting parsers to bypass access controls

Some websites parse email addresses to extract the domain and infer which organisation the owner belongs to. This pattern makes email-address parser discrepancies critical. Predicting which domain an

2
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Apr 21, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

RE: @cure53@infosec.exchange

😂

3
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Apr 15, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange
Replying to @gaz@infosec.exchange
Link: https://shazzer.co.uk/
1
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Apr 15, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

If you haven't tried Shazzer yet you should give it a go. You can easily find browser behaviour and get it tested by other users or your team. It supports private vectors too and you can assign them to your team. You can even have your own private fuzzing network. 🔥🔥🔥

0
2
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Apr 09, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Shazzer & Hackvertor OAuth was broken because of a Github change. Hopefully I've fixed the issues now.

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Apr 03, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Hehe WTF.

https://shazzer.co.uk/vectors/69d009776d238ed31d31e687

shazzer.co.uk

Entities after protocol-relative URL - Shazzer

Tests which entities are allowed after a protocol-relative URL

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Apr 02, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

I improved the collection view in Shazzer. You can now expand the results below the vector.

https://shazzer.co.uk/collections/69cebd940e3146875ac3465c

Entities in protocol relative URLs - Collection - Shazzer
shazzer.co.uk

Entities in protocol relative URLs - Collection - Shazzer

An app to enable to fuzz all sorts of browser behaviour. Share your fuzz results with the world and discover new bugs!

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Mar 30, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Shazzer had an interesting bug. I write to a blob URL thats sandboxed but because its a blob URL it breaks relative URLs which means vectors with them would return false negatives. The fix was: use a base tag to change the domain. This fixes vectors like:

https://shazzer.co.uk/vectors/69c81542145f0a28b7d202be

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Mar 28, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy Yeah it used JS for some aspects but still cool. I think we're not far from doing it in CSS/HTML only
1
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Mar 28, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy So cool!!!
1
2
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Mar 08, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Been doing a lot of statistical analysis in my free time on yet another side project. It's quite fun and far less challenging than my other side projects.

1
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Mar 04, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

You can now create collections of vectors on Shazzer. You can select up to 10 vectors and view the results of each by clicking a button. If anyone has any ideas to display the results in a better way let me know.

https://shazzer.co.uk/

1
0
1
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Feb 26, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Last night I added GZip and Deflate compression to Hackvertor. I also improved the autodecoder to detect it. Yesterday on my lunch I added autocompletion for HackPad and fixed a bunch of bugs.

https://hackvertor.co.uk/urls/31

Hackvertor - Cutting edge conversion
hackvertor.co.uk

Hackvertor - Cutting edge conversion

An app to make conversion tags to help with web security research

1
0
1
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Feb 20, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Hackvertor v2.2.45 released!

Fixed UI, primary buttons now have primary colour
Websocket message editor (Big thanks snooze6)
Hex edit functionality (Big thanks snooze6)
Centred dialogs (Big thanks psalire)

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Feb 13, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Question is what do I build next? So exciting. So many ideas...

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Feb 13, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange
Replying to @gaz@infosec.exchange
They are never ever going to be used by millions of people and they've always been niche. But they have given me great satisfaction and brought back my love of design, dev and constructing good UX as well as providing me with very interesting problems.
1
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Feb 13, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

I've got to the point where I've implemented nearly every 1 of my ideas for Shazzer and Hackvertor. Claude played a big part in that. I'm proud of them both. My approach of semi-vibing was long winded but now I think it's really paid off in both knowledge and speed of development

1
1
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Feb 13, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

I've added tool tips to the tags in Hackvertor!

Your browser does not support the video tag.
0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Feb 12, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Last night I made web Hackvertor more beautiful. I followed the same process I did with Shazzer. The footer is cleaned up and the nav bar now remembers the section and is reorganized.

0
1
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Feb 11, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

I've added a modal dialog to confirm if you want to opt in to Shared fuzzing in Shazzer. If you've already made a choice it should not show. Sorry about the dialog they are annoying but necessary in this case.

0
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Feb 10, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

New geolocation-based XSS vectors just landed in our XSS cheat sheet. Huge thanks to AmirMohammad Safari for the great submission.

https://portswigger.net/web-security/cross-site-scripting/cheat-sheet#onpromptaction

4
0
2
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Feb 10, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Last night I fixed Hackvertor history to work when real time is enabled. I made the collapsable panels remember their state. Various UI fixes. In Shazzer I fixed the like count on the vector card.

1
0
0
0
Open post
gaz
Gareth Heyes :verified: @gaz@infosec.exchange · Jan 25, 2026
Gareth Heyes :verified:
@gaz@infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/

infosec.exchange

Did huge amounts of updates to Shazzer. The fuzzing network was particularly tricky. I had production issues but hopefully I've fixed them. You can now visually see the fuzzing network at:

https://shazzer.co.uk/network

2
0
2
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 23:35:28 UTC