Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Gareth Heyes :verified:

@gaz@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor.

https://garethheyes.co.uk/
https://javascriptforhackers.co.uk/

2696 Followers
236 Following
50 Posts
Joined November 07, 2022
My web site:
https://garethheyes.co.uk/
PortSwigger Research:
https://portswigger.net/research
Github:
https://github.com/hackvertor/
My blog:
http://www.thespanner.co.uk/
JavaScript for hackers:
https://javascriptforhackers.co.uk/
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 2mo ago
I haven't posted a crazy XSS vector for a while... Works on every browser https://portswigger-labs.net/xss/xss.php?x=%3Calert(1)%20onfocus=%22attributes[0].value=localName,new%20onfocus%22%20autofocus%20tabindex=1%3E
portswigger-labs.net

XSS

18
0
2
1
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 3mo ago

I think this is the best most elegant XSS vector I've ever found. It still works in Safari. Here's the write up:
https://thespanner.co.uk/xssing-typeerrors-in-safari

thespanner.co.uk
26
1
7
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 2w ago
I've released Burp Hackvertor v2.2.67. This version supports the check tag and expressions. You can read how to use them here: https://github.com/hackvertor/hackvertor/wiki/Tag-Syntax#tag-expressions I'd love any feedback you have, let me know if the expressions are powerful enough.
GitHub

Tag Syntax

Contribute to hackvertor/hackvertor development by creating an account on GitHub.

1
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 2mo ago
I've wrote up how to do collision detection in pure CSS. I had loads of fun doing this. https://thespanner.co.uk/pure-css-3d-world-collision-detection
thespanner.co.uk
6
1
3
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 2mo ago

Next week I'm going to make you terrified of opening your emails...Join me at Black Hat USA for CSS:the bomb inside your inbox

4
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 2mo ago

My 3D world now has collision detection in CSS! If you run into a wall or door it will stop. Open the door and you can go through. This model is unbelievable.

https://garethheyes.co.uk/

garethheyes.co.uk
4
1
1
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 4mo ago

You may have noticed I've been a bit quiet on social media recently, this is why...I'm going to present at Black Hat!

Can't wait to present these techniques! Here is a link to the abstract in case the screenshot is hard to read:

https://blackhat.com/us-26/briefings/schedule/index.html#css-the-bomb-inside-your-inbox-51909

blackhat.com
6
0
4
1
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 2mo ago
Fixed the teleports on my site. The burger menu now works on all browsers. I'd previously tried to get this working and failed. Opus just did it in about 5 mins. https://garethheyes.co.uk/
garethheyes.co.uk
1
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 2mo ago
I redesigned my website using Claude. I burned through a lot of tokens. I basically put all my research in a hallway and created a bookshelf of links. Yes I was up till 1am doing this 😂 it even works on the iPhone. No JS! https://garethheyes.co.uk/
garethheyes.co.uk
1
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 5mo ago

RE: @cure53@infosec.exchange

😂

infosec.exchange
3
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 3mo ago

On my lunch today I improve the Shazzer fuzz results toast. It looks really nice and can handle ranges easily.

1
0
1
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 5mo ago

String.fromCharCode overflows. I didn't know how this worked many years ago. Now it seems so simple. The maximum value a character can be generated is 0xffff. So if you want to generate A (0x41) you simply add one to the max value plus the character you want to generate.

0x10000 is 0xffff+1. So to generate A you do:

String.fromCharCode(0x10000 + 0x41)//A

All this is explained in:

https://portswigger.net/research/splitting-the-email-atom

portswigger.net
2
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 4mo ago

Shazzer can now fuzz over 1 million characters now. I got Claude to refactor the fuzzing code and now it fuzzes in chunks. This is amazingly fast on Chromium based browsers because sandboxed iframes are process isolated. Firefox is pretty slow because it does not do this.

1
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 5mo ago

Allowed you to use Chrome's local AI model in Hackvertor tags. Warning it's very slow but should get better with time. You have to enable the local model in chrome://flags for it to work.
https://hackvertor.co.uk/urls/33

hackvertor.co.uk
1
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 5mo ago
Replying to
@freddy@social.security.plumbing I'm fully vibed lol
1
1
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 5mo ago
Replying to
@dynom@toot.community Nah I wanted more customisation options and the ability to highlight selections etc
1
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 5mo ago

I needed code snippets for presentations. I was worried about pasting code snippets into untrusted sites. So I just wrote my own using AI. You can trust I won't be tracking your code. It's very customisable and the default is for presentations and has the option for twitter too.

https://hackvertor.co.uk/snippet

hackvertor.co.uk
1
2
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 5mo ago
Replying to
Link: https://shazzer.co.uk/
Shazzer - Shared online fuzzing
shazzer.co.uk

Shazzer - Shared online fuzzing

An app to enable to fuzz all sorts of browser behaviour. Share your fuzz results with the world and discover new bugs!

1
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 6mo ago
Replying to
@freddy Yeah it used JS for some aspects but still cool. I think we're not far from doing it in CSS/HTML only
1
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 6mo ago
Replying to
@freddy So cool!!!
1
2
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 7mo ago

Been doing a lot of statistical analysis in my free time on yet another side project. It's quite fun and far less challenging than my other side projects.

1
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 7mo ago

You can now create collections of vectors on Shazzer. You can select up to 10 vectors and view the results of each by clicking a button. If anyone has any ideas to display the results in a better way let me know.

https://shazzer.co.uk/

Shazzer - Shared online fuzzing
shazzer.co.uk

Shazzer - Shared online fuzzing

An app to enable to fuzz all sorts of browser behaviour. Share your fuzz results with the world and discover new bugs!

1
0
1
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 7mo ago

Last night I added GZip and Deflate compression to Hackvertor. I also improved the autodecoder to detect it. Yesterday on my lunch I added autocompletion for HackPad and fixed a bunch of bugs.

https://hackvertor.co.uk/urls/31

hackvertor.co.uk
1
0
1
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 7mo ago
Replying to
They are never ever going to be used by millions of people and they've always been niche. But they have given me great satisfaction and brought back my love of design, dev and constructing good UX as well as providing me with very interesting problems.
1
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 5mo ago

I broke Shazzer, should be fixed now

0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 6mo ago

Shazzer & Hackvertor OAuth was broken because of a Github change. Hopefully I've fixed the issues now.

0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 2mo ago

You can now make a batch of private vectors public and assign them a collection in Shazzer. This is useful when presenting at a conference and you want to make a few public after the talk.

0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 2mo ago
Replying to
@freddy@social.security.plumbing @cure53@infosec.exchange Hehe cool I really enjoyed writing that book, it was great to collaborate with such talented people. I'm also glad the XSS payload in the subtitle fired on some random book site 😂
0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 6mo ago

I improved the collection view in Shazzer. You can now expand the results below the vector.

https://shazzer.co.uk/collections/69cebd940e3146875ac3465c

shazzer.co.uk
0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 7mo ago

Question is what do I build next? So exciting. So many ideas...

0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 3mo ago

I've added performance/feature vectors to Shazzer. Along with stats. You can now see which browsers perform better. It uses the same shared fuzzing network.

https://shazzer.co.uk/stats/performance

shazzer.co.uk
0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 2w ago
Replying to
@freddy@social.security.plumbing Any plans to allow list select? Asking for a friend
0
2
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 2mo ago
Hackvertor evolves as you add tags. You're not just adding a new encoding, you're teaching the auto-decoder how to recognise and decode it too. Every custom tag makes Hackvertor smarter for future use. Read the tutorial to find out more... https://thespanner.co.uk/how-to-write-a-hackvertor-tag
thespanner.co.uk
0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 5mo ago

After extensive testing with more generic versions, I decided to make browser version numbers more accurate now in Shazzer. This will create more fuzz data but will be more useful to test quirks in browsers. I've also hid older browser versions by default and provide filtering.

0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 1w ago
Chrome's new tag has something to say: Another XSS vector for our cheat sheet, found by omidxrz. https://portswigger.net/web-security/cross-site-scripting/cheat-sheet#onvalidationstatuschange
portswigger.net
0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 2mo ago

Both Hackvertor & Shazzer evolve the more you use them. It's such a shame they are not widely used and everyone is just using an LLM these days. That said I've found them both essential for conducting web security research.

0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 3mo ago

Just finished an improved toast dialog in Shazzer. It now shows the char codes with a preview of the character too when you press "Test Fuzz" or "Fuzz". If the character isn't printable it shows hex instead.

https://shazzer.co.uk/

Shazzer - Shared online fuzzing
shazzer.co.uk

Shazzer - Shared online fuzzing

An app to enable to fuzz all sorts of browser behaviour. Share your fuzz results with the world and discover new bugs!

0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 6mo ago

Shazzer had an interesting bug. I write to a blob URL thats sandboxed but because its a blob URL it breaks relative URLs which means vectors with them would return false negatives. The fix was: use a base tag to change the domain. This fixes vectors like:

https://shazzer.co.uk/vectors/69c81542145f0a28b7d202be

shazzer.co.uk

relative & protocol relative url starting with a slash and not immediately having a slash after it. - Shazzer

test

0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 7mo ago

I've added tool tips to the tags in Hackvertor!

0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 5mo ago

Shazzer is now a social network. You can post messages, links and vectors. Let's build and break it together and create a true web security social network.

https://shazzer.co.uk/

Shazzer - Shared online fuzzing
shazzer.co.uk

Shazzer - Shared online fuzzing

An app to enable to fuzz all sorts of browser behaviour. Share your fuzz results with the world and discover new bugs!

0
3
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 2mo ago

Messing around with inertia on my blog.

Demo:
https://thespanner.co.uk/

thespanner.co.uk
0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 7mo ago

Last night I made web Hackvertor more beautiful. I followed the same process I did with Shazzer. The footer is cleaned up and the nav bar now remembers the section and is reorganized.

0
1
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 2w ago
Replying to
@freddy@social.security.plumbing Lol :D
0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 3mo ago

Shazzer now displays ranges in nice unicode groups. I made the decision to convert large amount of character logs into ranges a while ago, this compresses the data really well and I can show massive amounts of data like JS variables easily.

0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 6mo ago

Hehe WTF.

https://shazzer.co.uk/vectors/69d009776d238ed31d31e687

shazzer.co.uk
0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 3mo ago
I have a passion for 3D. I used to read 3D world magazine every month and the CD always contained trial software. I used to love messing around with 3D max and Poser. As I often do my interests pour into my research or projects. I made a 3D portfolio and a 3D tile blog. Check them out: 3D portfolio: https://garethheyes.co.uk/ 3D tile blog: https://thespanner.co.uk/
garethheyes.co.uk
0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 7mo ago

Hackvertor v2.2.45 released!

Fixed UI, primary buttons now have primary colour
Websocket message editor (Big thanks snooze6)
Hex edit functionality (Big thanks snooze6)
Centred dialogs (Big thanks psalire)

0
0
0
0
Open post
Gareth Heyes :verified: @gaz@infosec.exchange
· 5mo ago

Added AI features to Shazzer using Chrome's local model. They aren't very useful yet because the local model is very slow and isn't very smart but should improve over time when the model is updated. I've added:

- AI write description
- AI generate vector
- AI generate variant

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 16:35:53 UTC