Sign in

Gareth Heyes

@garethheyes.co.uk
3.1K followers 332 following 504 posts

Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor. javascriptforhackers.co.uk garethheyes.co.uk

PostsRepliesMedia
Gareth Heyes @garethheyes.co.uk · 17h
Chrome added a <camera> tag. omidxrz made it an XSS vector: Now in our XSS cheat sheet. portswigger.net/web-security...
<camera onvalidationstatuschange=alert(1)>
031
Gareth Heyes @garethheyes.co.uk · 28/09/2026
Stuck inside a <meta> and angle brackets blocked? You can still get XSS... In Firefox, use hidden=until-found and onbeforematch with a URL hash to trigger your handler. Now in our XSS cheat sheet, thanks to ­Mathias Karlsson.
<meta name=description 
content=x id=p 
hidden=until-found 
onbeforematch=alert(document.domain)>
1165
Reposted by Gareth Heyes
Tom Stacey @t0xodile.com · 23/09/2026
Turbo Intruder 2 has landed! You can now surpass 100,000 RPS over WiFi using the new HTTP/3 engine, test HTTP/3 exclusive targets with the Burp adapter, and deploy new research-grade race condition techniques! Check out the post below for full details:
142
Gareth Heyes @garethheyes.co.uk · 21/09/2026
I thought how can fuzz this interesting Safari behaviour. First the code checks markup is consumed by only incrementing the counter if it is not. The second snippet then wraps the tag in a select and see if the code executes.
shazzer.co.uk
Tags that consume markup but select consumes them - Shazzer
NOT CURRENTLY WORKING. This vector attempts to detect tags that consume markup. Then shows select can be used to break out of the consumption.
110
Gareth Heyes @garethheyes.co.uk · 17/09/2026
I've improved the sandbox in web Hackvertor to prevent tags from interfering with each other. For example if one tag executes first it used to be able to overwrite other functions like btoa. Fixed! <@encode(js)>btoa=()=>"pwnd"</@encode> <@encode(base64)>foobar</@encode>
000
Gareth Heyes @garethheyes.co.uk · 17/09/2026
I've released Burp Hackvertor v2.2.67. This version supports the check tag and expressions. You can read how to use them here: github.com/hackvertor/h... I'd love any feedback you have, let me know if the expressions are powerful enough.
github.com
Tag Syntax
Contribute to hackvertor/hackvertor development by creating an account on GitHub.
010
Gareth Heyes @garethheyes.co.uk · 16/09/2026
I've added a super powerful feature to Hackvertor. Check tags.They let you perform expressions on tags <@check(isJson)>{"a":1}</@check> && <@encode(base64)>{"a":1}</@encode> The above example only returns base 64 encoded JSON if the first is valid JSON. thespanner.co.uk/hackvertor-c...
thespanner.co.uk
021
Gareth Heyes @garethheyes.co.uk · 16/09/2026
Did a small post about mutating Safari a behaviour that Shazzer found. thespanner.co.uk/mutating-saf...
thespanner.co.uk
020
Gareth Heyes @garethheyes.co.uk · 12/09/2026
Burp Hackvertor now has jigsaw mode too!
010
Gareth Heyes @garethheyes.co.uk · 11/09/2026
Just something I've been working on. Jigsaw mode in Hackvertor!
011
Gareth Heyes @garethheyes.co.uk · 02/09/2026
I've added a single execution type in Shazzer. This allows you to execute JS once. Useful for enumerating things in a browser such as events. Example vector: shazzer.co.uk/vectors/665a...
shazzer.co.uk
All events on window - Shazzer
This vector shows all the available events on the window object.
010
Gareth Heyes @garethheyes.co.uk · 30/08/2026
Safari actually supports CSS random! It's buggy but it does work. My escape room puzzles are now randomised on desktop and iPhone other browsers will follow
010
Gareth Heyes @garethheyes.co.uk · 30/08/2026
The coolest part of Shazzer is the fuzzing network. To reflect that I've updated the design and added animations. Now you can see swarms of browsers when they are connected shazzer.co.uk/network
shazzer.co.uk
Fuzzing Network - Shazzer
Real-time view of the distributed fuzzing network
010
Gareth Heyes @garethheyes.co.uk · 28/08/2026
Added a trophy room to my 3D world with what I think is my best work. Claude casually building 3D CSS like it's nothing...
000
Gareth Heyes @garethheyes.co.uk · 28/08/2026
I've made a major change to Shazzer. It will now collate historical fuzz result data. Previously to save costs it would remove older result data. I've since upgraded my db server. We should then have a history of interesting browser data. You can get RSS feeds of fuzz results too
030
Gareth Heyes @garethheyes.co.uk · 27/08/2026
Made the gallery a zig zag shape instead which fixes the performance glitches on Chrome. Check it out! garethheyes.co.uk
garethheyes.co.uk
Pure CSS first person 3D website portfolio without any JavaScript
This is website portfolio of Gareth Heyes
020
Gareth Heyes @garethheyes.co.uk · 26/08/2026
Fixed another collision bug. If you opened the doors you could walk through walls.
010
Gareth Heyes @garethheyes.co.uk · 26/08/2026
Yes do it 🥳
000
Gareth Heyes @garethheyes.co.uk · 26/08/2026
Fixed collision detection bugs on my website
000
Gareth Heyes @garethheyes.co.uk · 26/08/2026
My site now uses random() to randomize the solutions to the escape room. Random isn't available yet in any modern browser so it will fallback to a static solution.
000
Gareth Heyes @garethheyes.co.uk · 25/08/2026
Hehe my escape room even works on my iPhone 😂
010
Gareth Heyes @garethheyes.co.uk · 25/08/2026
With Claude I've created CSS/HTML only escape room puzzles on my website. Check it out! Absolutely no JS! Claude created the puzzles so it was quite fun trying to solve them myself 😀 garethheyes.co.uk
garethheyes.co.uk
Pure CSS first person 3D website portfolio without any JavaScript
This is website portfolio of Gareth Heyes
010
Gareth Heyes @garethheyes.co.uk · 25/08/2026
I 😻 Firefox
020
Gareth Heyes @garethheyes.co.uk · 25/08/2026
I put a JavaScript URL inside an HTML tag name, and every browser executed it. Apparently, tag names are code now. portswigger.net/research/wha...
<JAVASCRIPT:ALERT(1) onfocus=location=localName autofocus tabindex=1>
1104
Reposted by Gareth Heyes
Freddy @freddyb.bsky.social · 20/08/2026
My presentation from OWASP AppSec '26 in Vienna is finally public. Watch me talk about XSS and XSS and Cross-Site Scripting, and XSS in this talk titled "The Devil Is In The Defaults: What To Do About XSS" youtube.com/watch?v=b7RlQdvPY3 (It's also about XSS).
youtube.com
YouTube
Share your videos with friends, family, and the world
132
Gareth Heyes @garethheyes.co.uk · 13/08/2026
You can now generate QR codes in web Hackvertor to share your URLs in presentations. Just click the QR code button.
001
Gareth Heyes @garethheyes.co.uk · 13/08/2026
I stole an Outlook password with nothing but CSS inside an email 👀 Whitepaper below 👇 This video is from my research "CSS: the bomb inside your inbox". Whitepaper & slides: portswigger.net/research/css...
174
Reposted by Gareth Heyes
Tom Stacey @t0xodile.com · 12/08/2026
Did you know you can use HTTP header injection to trigger response queue poisoning and make it rain credentials? Learn how with the new @portswiggerres.bsky.social whitepaper "CRLF-Powered Desync Attacks: Beheading HTTP Streams" by @turtlesec.io and I. Read the full paper below 👇
1103
Gareth Heyes @garethheyes.co.uk · 12/08/2026
@html5test.com I saw you're doom game :) you could probably do it in pure HTML/CSS. Check this out collision detection in CSS: thespanner.co.uk/pure-css-3d-...
thespanner.co.uk
000
Gareth Heyes @garethheyes.co.uk · 07/08/2026
If you want to see how to compromise an account from a paste and steal passwords in CSS and much more check out my paper "CSS: the bomb inside your inbox" 👇 portswigger.net/research/css...
portswigger.net
CSS:the bomb inside your inbox
Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this
163
Gareth Heyes @garethheyes.co.uk · 29/07/2026
Next week I'm going to make you terrified of opening your emails...Join me at Black Hat USA for CSS:the bomb inside your inbox
CSS: the bomb inside your inbox
052
Reposted by Gareth Heyes
James Kettle @jameskettle.com · 29/07/2026
Next week I'll present "Can AI Do Novel Security Research? Meet the HTTP Terminator" at @defcon.bsky.social & Black Hat USA! I'm really excited to share this one - got some spectacular outcomes from a wild research journey. See you there!
093
Reposted by Gareth Heyes
Tom Stacey @t0xodile.com · 29/07/2026
Come and see Tobia from @turtlesec.io and I at @blackhatevents.bsky.social and @defcon.bsky.social next week! We cannot wait to share what we've found!
011
Gareth Heyes @garethheyes.co.uk · 25/07/2026
I've wrote up how to do collision detection in pure CSS. I had loads of fun doing this. thespanner.co.uk/pure-css-3d-...
thespanner.co.uk
020
Gareth Heyes @garethheyes.co.uk · 25/07/2026
Fixed the teleports on my site. The burger menu now works on all browsers. I'd previously tried to get this working and failed. Opus just did it in about 5 mins. garethheyes.co.uk
garethheyes.co.uk
Pure CSS first person 3D website portfolio without any JavaScript
This is website portfolio of Gareth Heyes
000
Gareth Heyes @garethheyes.co.uk · 24/07/2026
My 3D world now has collision detection in CSS! If you run into a wall or door it will stop. Open the door and you can go through. This model is unbelievable. garethheyes.co.uk
150
Gareth Heyes @garethheyes.co.uk · 24/07/2026
I redesigned my website using Claude. I burned through a lot of tokens. I basically put all my research in a hallway and created a bookshelf of links. Yes I was up till 1am doing this 😂 it even works on the iPhone. No JS! garethheyes.co.uk
020
Gareth Heyes @garethheyes.co.uk · 21/07/2026
I haven't posted a crazy XSS vector for a while... Works on every browser
1396
Gareth Heyes @garethheyes.co.uk · 17/07/2026
Both Hackvertor & Shazzer evolve the more you use them. It's such a shame they are not widely used and everyone is just using an LLM these days. That said I've found them both essential for conducting web security research.
030
Gareth Heyes @garethheyes.co.uk · 17/07/2026
Hackvertor evolves as you add tags. You're not just adding a new encoding, you're teaching the auto-decoder how to recognise and decode it too. Every custom tag makes Hackvertor smarter for future use. Read the tutorial to find out more... thespanner.co.uk/how-to-write...
thespanner.co.uk
021
Gareth Heyes @garethheyes.co.uk · 16/07/2026
You can now make a batch of private vectors public and assign them a collection in Shazzer. This is useful when presenting at a conference and you want to make a few public after the talk.
000
Gareth Heyes @garethheyes.co.uk · 14/07/2026
Messing around with inertia on my blog. Demo: thespanner.co.uk
010
Gareth Heyes @garethheyes.co.uk · 08/07/2026
I have a passion for 3D. I used to read 3D world magazine every month and the CD always contained trial software. I used to love messing around with 3D max and Poser. As I often do my interests pour into my research or projects. I made a 3D portfolio and a 3D tile blog. 1/2
100
Gareth Heyes @garethheyes.co.uk · 04/07/2026
I've added performance/feature vectors to Shazzer. Along with stats. You can now see which browsers perform better. It uses the same shared fuzzing network. shazzer.co.uk/stats/perfor...
shazzer.co.uk
Performance stats
An app to enable to fuzz all sorts of browser behaviour. Share your fuzz results with the world and discover new bugs!
010
Gareth Heyes @garethheyes.co.uk · 03/07/2026
On my lunch today I improve the Shazzer fuzz results toast. It looks really nice and can handle ranges easily.
000
Gareth Heyes @garethheyes.co.uk · 02/07/2026
Just finished an improved toast dialog in Shazzer. It now shows the char codes with a preview of the character too when you press "Test Fuzz" or "Fuzz". If the character isn't printable it shows hex instead. shazzer.co.uk
000
Gareth Heyes @garethheyes.co.uk · 29/06/2026
I think this is the best most elegant XSS vector I've ever found
onerror=eval,new name
130
Gareth Heyes @garethheyes.co.uk · 10/06/2026
Shazzer now displays ranges in nice unicode groups. I made the decision to convert large amount of character logs into ranges a while ago, this compresses the data really well and I can show massive amounts of data like JS variables easily.
000
Reposted by Gareth Heyes
Jonnie Hallman @jonnie.com · 09/06/2026
Just realized that one of my favorite easter eggs I made while at Stripe is still on the /jobs page… The monitor in the photo mimics everything you do on the page itself. 🥚💅 (only visible on Firefox because it uses an experimental feature)
737335
Gareth Heyes @garethheyes.co.uk · 09/06/2026
Shazzer can now fuzz over 1 million characters now. I got Claude to refactor the fuzzing code and now it fuzzes in chunks. This is amazingly fast on Chromium based browsers because sandboxed iframes are process isolated. Firefox is pretty slow because it does not do this.
010