Gareth Heyes 
Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor.
https://garethheyes.co.uk/
https://javascriptforhackers.co.uk/
I think this is the best most elegant XSS vector I've ever found. It still works in Safari. Here's the write up:
https://thespanner.co.uk/xssing-typeerrors-in-safari
Next week I'm going to make you terrified of opening your emails...Join me at Black Hat USA for CSS:the bomb inside your inbox
My 3D world now has collision detection in CSS! If you run into a wall or door it will stop. Open the door and you can go through. This model is unbelievable.
You may have noticed I've been a bit quiet on social media recently, this is why...I'm going to present at Black Hat!
Can't wait to present these techniques! Here is a link to the abstract in case the screenshot is hard to read:
https://blackhat.com/us-26/briefings/schedule/index.html#css-the-bomb-inside-your-inbox-51909
On my lunch today I improve the Shazzer fuzz results toast. It looks really nice and can handle ranges easily.
String.fromCharCode overflows. I didn't know how this worked many years ago. Now it seems so simple. The maximum value a character can be generated is 0xffff. So if you want to generate A (0x41) you simply add one to the max value plus the character you want to generate.
0x10000 is 0xffff+1. So to generate A you do:
String.fromCharCode(0x10000 + 0x41)//A
All this is explained in:
Shazzer can now fuzz over 1 million characters now. I got Claude to refactor the fuzzing code and now it fuzzes in chunks. This is amazingly fast on Chromium based browsers because sandboxed iframes are process isolated. Firefox is pretty slow because it does not do this.
Allowed you to use Chrome's local AI model in Hackvertor tags. Warning it's very slow but should get better with time. You have to enable the local model in chrome://flags for it to work.
https://hackvertor.co.uk/urls/33
I needed code snippets for presentations. I was worried about pasting code snippets into untrusted sites. So I just wrote my own using AI. You can trust I won't be tracking your code. It's very customisable and the default is for presentations and has the option for twitter too.
Been doing a lot of statistical analysis in my free time on yet another side project. It's quite fun and far less challenging than my other side projects.
You can now create collections of vectors on Shazzer. You can select up to 10 vectors and view the results of each by clicking a button. If anyone has any ideas to display the results in a better way let me know.
Last night I added GZip and Deflate compression to Hackvertor. I also improved the autodecoder to detect it. Yesterday on my lunch I added autocompletion for HackPad and fixed a bunch of bugs.
Shazzer & Hackvertor OAuth was broken because of a Github change. Hopefully I've fixed the issues now.
You can now make a batch of private vectors public and assign them a collection in Shazzer. This is useful when presenting at a conference and you want to make a few public after the talk.
I improved the collection view in Shazzer. You can now expand the results below the vector.
Question is what do I build next? So exciting. So many ideas...
I've added performance/feature vectors to Shazzer. Along with stats. You can now see which browsers perform better. It uses the same shared fuzzing network.
After extensive testing with more generic versions, I decided to make browser version numbers more accurate now in Shazzer. This will create more fuzz data but will be more useful to test quirks in browsers. I've also hid older browser versions by default and provide filtering.
Both Hackvertor & Shazzer evolve the more you use them. It's such a shame they are not widely used and everyone is just using an LLM these days. That said I've found them both essential for conducting web security research.
Just finished an improved toast dialog in Shazzer. It now shows the char codes with a preview of the character too when you press "Test Fuzz" or "Fuzz". If the character isn't printable it shows hex instead.
Shazzer had an interesting bug. I write to a blob URL thats sandboxed but because its a blob URL it breaks relative URLs which means vectors with them would return false negatives. The fix was: use a base tag to change the domain. This fixes vectors like:
I've added tool tips to the tags in Hackvertor!
Shazzer is now a social network. You can post messages, links and vectors. Let's build and break it together and create a true web security social network.
Last night I made web Hackvertor more beautiful. I followed the same process I did with Shazzer. The footer is cleaned up and the nav bar now remembers the section and is reorganized.
Shazzer now displays ranges in nice unicode groups. I made the decision to convert large amount of character logs into ranges a while ago, this compresses the data really well and I can show massive amounts of data like JS variables easily.
Hackvertor v2.2.45 released!
Fixed UI, primary buttons now have primary colour
Websocket message editor (Big thanks snooze6)
Hex edit functionality (Big thanks snooze6)
Centred dialogs (Big thanks psalire)
Added AI features to Shazzer using Chrome's local model. They aren't very useful yet because the local model is very slow and isn't very smart but should improve over time when the model is updated. I've added:
- AI write description
- AI generate vector
- AI generate variant
