Gareth Heyes @garethheyes.co.uk · 17hChrome added a <camera> tag. omidxrz made it an XSS vector: Now in our XSS cheat sheet. portswigger.net/web-security... 031
Gareth Heyes @garethheyes.co.uk · 28/09/2026Stuck inside a <meta> and angle brackets blocked? You can still get XSS... In Firefox, use hidden=until-found and onbeforematch with a URL hash to trigger your handler. Now in our XSS cheat sheet, thanks to Mathias Karlsson. 1165
Reposted by Gareth HeyesTom Stacey @t0xodile.com · 23/09/2026Turbo Intruder 2 has landed! You can now surpass 100,000 RPS over WiFi using the new HTTP/3 engine, test HTTP/3 exclusive targets with the Burp adapter, and deploy new research-grade race condition techniques! Check out the post below for full details: 142
Gareth Heyes @garethheyes.co.uk · 21/09/2026I thought how can fuzz this interesting Safari behaviour. First the code checks markup is consumed by only incrementing the counter if it is not. The second snippet then wraps the tag in a select and see if the code executes.shazzer.co.ukTags that consume markup but select consumes them - ShazzerNOT CURRENTLY WORKING. This vector attempts to detect tags that consume markup. Then shows select can be used to break out of the consumption. 110
Gareth Heyes @garethheyes.co.uk · 17/09/2026I've improved the sandbox in web Hackvertor to prevent tags from interfering with each other. For example if one tag executes first it used to be able to overwrite other functions like btoa. Fixed! <@encode(js)>btoa=()=>"pwnd"</@encode> <@encode(base64)>foobar</@encode> 000
Gareth Heyes @garethheyes.co.uk · 17/09/2026I've released Burp Hackvertor v2.2.67. This version supports the check tag and expressions. You can read how to use them here: github.com/hackvertor/h... I'd love any feedback you have, let me know if the expressions are powerful enough.github.comTag SyntaxContribute to hackvertor/hackvertor development by creating an account on GitHub. 010
Gareth Heyes @garethheyes.co.uk · 16/09/2026I've added a super powerful feature to Hackvertor. Check tags.They let you perform expressions on tags <@check(isJson)>{"a":1}</@check> && <@encode(base64)>{"a":1}</@encode> The above example only returns base 64 encoded JSON if the first is valid JSON. thespanner.co.uk/hackvertor-c...thespanner.co.uk 021
Gareth Heyes @garethheyes.co.uk · 16/09/2026Did a small post about mutating Safari a behaviour that Shazzer found. thespanner.co.uk/mutating-saf...thespanner.co.uk 020
Gareth Heyes @garethheyes.co.uk · 11/09/2026Just something I've been working on. Jigsaw mode in Hackvertor! 011
Gareth Heyes @garethheyes.co.uk · 02/09/2026I've added a single execution type in Shazzer. This allows you to execute JS once. Useful for enumerating things in a browser such as events. Example vector: shazzer.co.uk/vectors/665a...shazzer.co.ukAll events on window - ShazzerThis vector shows all the available events on the window object. 010
Gareth Heyes @garethheyes.co.uk · 30/08/2026Safari actually supports CSS random! It's buggy but it does work. My escape room puzzles are now randomised on desktop and iPhone other browsers will follow 010
Gareth Heyes @garethheyes.co.uk · 30/08/2026The coolest part of Shazzer is the fuzzing network. To reflect that I've updated the design and added animations. Now you can see swarms of browsers when they are connected shazzer.co.uk/networkshazzer.co.ukFuzzing Network - ShazzerReal-time view of the distributed fuzzing network 010
Gareth Heyes @garethheyes.co.uk · 28/08/2026Added a trophy room to my 3D world with what I think is my best work. Claude casually building 3D CSS like it's nothing... 000
Gareth Heyes @garethheyes.co.uk · 28/08/2026I've made a major change to Shazzer. It will now collate historical fuzz result data. Previously to save costs it would remove older result data. I've since upgraded my db server. We should then have a history of interesting browser data. You can get RSS feeds of fuzz results too 030
Gareth Heyes @garethheyes.co.uk · 27/08/2026Made the gallery a zig zag shape instead which fixes the performance glitches on Chrome. Check it out! garethheyes.co.ukgarethheyes.co.ukPure CSS first person 3D website portfolio without any JavaScriptThis is website portfolio of Gareth Heyes 020
Gareth Heyes @garethheyes.co.uk · 26/08/2026Fixed another collision bug. If you opened the doors you could walk through walls. 010
Gareth Heyes @garethheyes.co.uk · 26/08/2026My site now uses random() to randomize the solutions to the escape room. Random isn't available yet in any modern browser so it will fallback to a static solution. 000
Gareth Heyes @garethheyes.co.uk · 25/08/2026With Claude I've created CSS/HTML only escape room puzzles on my website. Check it out! Absolutely no JS! Claude created the puzzles so it was quite fun trying to solve them myself 😀 garethheyes.co.ukgarethheyes.co.ukPure CSS first person 3D website portfolio without any JavaScriptThis is website portfolio of Gareth Heyes 010
Gareth Heyes @garethheyes.co.uk · 25/08/2026I put a JavaScript URL inside an HTML tag name, and every browser executed it. Apparently, tag names are code now. portswigger.net/research/wha... 1104
Reposted by Gareth HeyesFreddy @freddyb.bsky.social · 20/08/2026My presentation from OWASP AppSec '26 in Vienna is finally public. Watch me talk about XSS and XSS and Cross-Site Scripting, and XSS in this talk titled "The Devil Is In The Defaults: What To Do About XSS" youtube.com/watch?v=b7RlQdvPY3 (It's also about XSS).youtube.comYouTubeShare your videos with friends, family, and the world 132
Gareth Heyes @garethheyes.co.uk · 13/08/2026You can now generate QR codes in web Hackvertor to share your URLs in presentations. Just click the QR code button. 001
Gareth Heyes @garethheyes.co.uk · 13/08/2026I stole an Outlook password with nothing but CSS inside an email 👀 Whitepaper below 👇 This video is from my research "CSS: the bomb inside your inbox". Whitepaper & slides: portswigger.net/research/css... 174
Reposted by Gareth HeyesTom Stacey @t0xodile.com · 12/08/2026Did you know you can use HTTP header injection to trigger response queue poisoning and make it rain credentials? Learn how with the new @portswiggerres.bsky.social whitepaper "CRLF-Powered Desync Attacks: Beheading HTTP Streams" by @turtlesec.io and I. Read the full paper below 👇 1103
Gareth Heyes @garethheyes.co.uk · 12/08/2026@html5test.com I saw you're doom game :) you could probably do it in pure HTML/CSS. Check this out collision detection in CSS: thespanner.co.uk/pure-css-3d-...thespanner.co.uk 000
Gareth Heyes @garethheyes.co.uk · 07/08/2026If you want to see how to compromise an account from a paste and steal passwords in CSS and much more check out my paper "CSS: the bomb inside your inbox" 👇 portswigger.net/research/css...portswigger.netCSS:the bomb inside your inboxGareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this 163
Gareth Heyes @garethheyes.co.uk · 29/07/2026Next week I'm going to make you terrified of opening your emails...Join me at Black Hat USA for CSS:the bomb inside your inbox 052
Reposted by Gareth HeyesJames Kettle @jameskettle.com · 29/07/2026Next week I'll present "Can AI Do Novel Security Research? Meet the HTTP Terminator" at @defcon.bsky.social & Black Hat USA! I'm really excited to share this one - got some spectacular outcomes from a wild research journey. See you there! 093
Reposted by Gareth HeyesTom Stacey @t0xodile.com · 29/07/2026Come and see Tobia from @turtlesec.io and I at @blackhatevents.bsky.social and @defcon.bsky.social next week! We cannot wait to share what we've found! 011
Gareth Heyes @garethheyes.co.uk · 25/07/2026I've wrote up how to do collision detection in pure CSS. I had loads of fun doing this. thespanner.co.uk/pure-css-3d-...thespanner.co.uk 020
Gareth Heyes @garethheyes.co.uk · 25/07/2026Fixed the teleports on my site. The burger menu now works on all browsers. I'd previously tried to get this working and failed. Opus just did it in about 5 mins. garethheyes.co.ukgarethheyes.co.ukPure CSS first person 3D website portfolio without any JavaScriptThis is website portfolio of Gareth Heyes 000
Gareth Heyes @garethheyes.co.uk · 24/07/2026My 3D world now has collision detection in CSS! If you run into a wall or door it will stop. Open the door and you can go through. This model is unbelievable. garethheyes.co.uk 150
Gareth Heyes @garethheyes.co.uk · 24/07/2026I redesigned my website using Claude. I burned through a lot of tokens. I basically put all my research in a hallway and created a bookshelf of links. Yes I was up till 1am doing this 😂 it even works on the iPhone. No JS! garethheyes.co.uk 020
Gareth Heyes @garethheyes.co.uk · 21/07/2026I haven't posted a crazy XSS vector for a while... Works on every browser 1396
Gareth Heyes @garethheyes.co.uk · 17/07/2026Both Hackvertor & Shazzer evolve the more you use them. It's such a shame they are not widely used and everyone is just using an LLM these days. That said I've found them both essential for conducting web security research. 030
Gareth Heyes @garethheyes.co.uk · 17/07/2026Hackvertor evolves as you add tags. You're not just adding a new encoding, you're teaching the auto-decoder how to recognise and decode it too. Every custom tag makes Hackvertor smarter for future use. Read the tutorial to find out more... thespanner.co.uk/how-to-write...thespanner.co.uk 021
Gareth Heyes @garethheyes.co.uk · 16/07/2026You can now make a batch of private vectors public and assign them a collection in Shazzer. This is useful when presenting at a conference and you want to make a few public after the talk. 000
Gareth Heyes @garethheyes.co.uk · 14/07/2026Messing around with inertia on my blog. Demo: thespanner.co.uk 010
Gareth Heyes @garethheyes.co.uk · 08/07/2026I have a passion for 3D. I used to read 3D world magazine every month and the CD always contained trial software. I used to love messing around with 3D max and Poser. As I often do my interests pour into my research or projects. I made a 3D portfolio and a 3D tile blog. 1/2 100
Gareth Heyes @garethheyes.co.uk · 04/07/2026I've added performance/feature vectors to Shazzer. Along with stats. You can now see which browsers perform better. It uses the same shared fuzzing network. shazzer.co.uk/stats/perfor...shazzer.co.ukPerformance statsAn app to enable to fuzz all sorts of browser behaviour. Share your fuzz results with the world and discover new bugs! 010
Gareth Heyes @garethheyes.co.uk · 03/07/2026On my lunch today I improve the Shazzer fuzz results toast. It looks really nice and can handle ranges easily. 000
Gareth Heyes @garethheyes.co.uk · 02/07/2026Just finished an improved toast dialog in Shazzer. It now shows the char codes with a preview of the character too when you press "Test Fuzz" or "Fuzz". If the character isn't printable it shows hex instead. shazzer.co.uk 000
Gareth Heyes @garethheyes.co.uk · 29/06/2026I think this is the best most elegant XSS vector I've ever found 130
Gareth Heyes @garethheyes.co.uk · 10/06/2026Shazzer now displays ranges in nice unicode groups. I made the decision to convert large amount of character logs into ranges a while ago, this compresses the data really well and I can show massive amounts of data like JS variables easily. 000
Reposted by Gareth HeyesJonnie Hallman @jonnie.com · 09/06/2026Just realized that one of my favorite easter eggs I made while at Stripe is still on the /jobs page… The monitor in the photo mimics everything you do on the page itself. 🥚💅 (only visible on Firefox because it uses an experimental feature) 737335
Gareth Heyes @garethheyes.co.uk · 09/06/2026Shazzer can now fuzz over 1 million characters now. I got Claude to refactor the fuzzing code and now it fuzzes in chunks. This is amazingly fast on Chromium based browsers because sandboxed iframes are process isolated. Firefox is pretty slow because it does not do this. 010