Gareth Heyes @garethheyes.co.uk · 06/10/2026Another XSS vector for our cheat sheet, this time using <usermedia> Special mention to AmirMohammad Safari, who found this one and has contributed so many excellent vectors to the cheat sheet. portswigger.net/web-security... 041
Gareth Heyes @garethheyes.co.uk · 05/10/2026Building on my research, my colleague Alex exfiltrated a 600-character hex token instantly using just background images and selectors. No recursive imports. portswigger.net/research/sma... 041
Gareth Heyes @garethheyes.co.uk · 01/10/2026Chrome's new <microphone> tag has something to say: Another XSS vector for our cheat sheet, found by omidxrz. portswigger.net/web-security... 042
Gareth Heyes @garethheyes.co.uk · 30/09/2026Yeah it can do the boring stuff. I find the challenge is thinking of something ambitious enough because I'm used to the mindset of that will take too long to make. Now you can just make whatever you want. 010
Gareth Heyes @garethheyes.co.uk · 30/09/2026Chrome added a <camera> tag. omidxrz made it an XSS vector: Now in our XSS cheat sheet. portswigger.net/web-security... 041
Gareth Heyes @garethheyes.co.uk · 28/09/2026portswigger.net/web-security...portswigger.netCross-Site Scripting (XSS) Cheat Sheet - 2026 Edition | Web Security AcademyInteractive cross-site scripting (XSS) cheat sheet for 2026, brought to you by PortSwigger. Actively maintained, and regularly updated with new vectors. 000
Gareth Heyes @garethheyes.co.uk · 28/09/2026Stuck inside a <meta> and angle brackets blocked? You can still get XSS... In Firefox, use hidden=until-found and onbeforematch with a URL hash to trigger your handler. Now in our XSS cheat sheet, thanks to Mathias Karlsson. 1165
Reposted by Gareth HeyesTom Stacey @t0xodile.com · 23/09/2026Turbo Intruder 2 has landed! You can now surpass 100,000 RPS over WiFi using the new HTTP/3 engine, test HTTP/3 exclusive targets with the Burp adapter, and deploy new research-grade race condition techniques! Check out the post below for full details: 142
Gareth Heyes @garethheyes.co.uk · 21/09/2026The counter is 1 if the tag consumes and is neutralized by the select. Vector: shazzer.co.uk/vectors/6ab1...shazzer.co.ukTags that consume markup but select consumes them - ShazzerNOT CURRENTLY WORKING. This vector attempts to detect tags that consume markup. Then shows select can be used to break out of the consumption. 000
Gareth Heyes @garethheyes.co.uk · 21/09/2026I thought how can fuzz this interesting Safari behaviour. First the code checks markup is consumed by only incrementing the counter if it is not. The second snippet then wraps the tag in a select and see if the code executes.shazzer.co.ukTags that consume markup but select consumes them - ShazzerNOT CURRENTLY WORKING. This vector attempts to detect tags that consume markup. Then shows select can be used to break out of the consumption. 110
Gareth Heyes @garethheyes.co.uk · 18/09/2026👏 Brilliant, excited to see being built. You were so passionate about Fiddler. Hope you love working on this project as much 010
Gareth Heyes @garethheyes.co.uk · 17/09/2026I've improved the sandbox in web Hackvertor to prevent tags from interfering with each other. For example if one tag executes first it used to be able to overwrite other functions like btoa. Fixed! <@encode(js)>btoa=()=>"pwnd"</@encode> <@encode(base64)>foobar</@encode> 000
Gareth Heyes @garethheyes.co.uk · 17/09/2026I've released Burp Hackvertor v2.2.67. This version supports the check tag and expressions. You can read how to use them here: github.com/hackvertor/h... I'd love any feedback you have, let me know if the expressions are powerful enough.github.comTag SyntaxContribute to hackvertor/hackvertor development by creating an account on GitHub. 010
Gareth Heyes @garethheyes.co.uk · 16/09/2026I've added a super powerful feature to Hackvertor. Check tags.They let you perform expressions on tags <@check(isJson)>{"a":1}</@check> && <@encode(base64)>{"a":1}</@encode> The above example only returns base 64 encoded JSON if the first is valid JSON. thespanner.co.uk/hackvertor-c...thespanner.co.uk 021
Gareth Heyes @garethheyes.co.uk · 16/09/2026Did a small post about mutating Safari a behaviour that Shazzer found. thespanner.co.uk/mutating-saf...thespanner.co.uk 020
Gareth Heyes @garethheyes.co.uk · 11/09/2026Just something I've been working on. Jigsaw mode in Hackvertor! 011
Gareth Heyes @garethheyes.co.uk · 02/09/2026I've added a single execution type in Shazzer. This allows you to execute JS once. Useful for enumerating things in a browser such as events. Example vector: shazzer.co.uk/vectors/665a...shazzer.co.ukAll events on window - ShazzerThis vector shows all the available events on the window object. 010
Gareth Heyes @garethheyes.co.uk · 30/08/2026Safari actually supports CSS random! It's buggy but it does work. My escape room puzzles are now randomised on desktop and iPhone other browsers will follow 010
Gareth Heyes @garethheyes.co.uk · 30/08/2026The coolest part of Shazzer is the fuzzing network. To reflect that I've updated the design and added animations. Now you can see swarms of browsers when they are connected shazzer.co.uk/networkshazzer.co.ukFuzzing Network - ShazzerReal-time view of the distributed fuzzing network 010
Gareth Heyes @garethheyes.co.uk · 28/08/2026Added a trophy room to my 3D world with what I think is my best work. Claude casually building 3D CSS like it's nothing... 000
Gareth Heyes @garethheyes.co.uk · 28/08/2026I've made a major change to Shazzer. It will now collate historical fuzz result data. Previously to save costs it would remove older result data. I've since upgraded my db server. We should then have a history of interesting browser data. You can get RSS feeds of fuzz results too 030
Gareth Heyes @garethheyes.co.uk · 27/08/2026Made the gallery a zig zag shape instead which fixes the performance glitches on Chrome. Check it out! garethheyes.co.ukgarethheyes.co.ukPure CSS first person 3D website portfolio without any JavaScriptThis is website portfolio of Gareth Heyes 020
Gareth Heyes @garethheyes.co.uk · 26/08/2026Fixed another collision bug. If you opened the doors you could walk through walls. 010
Gareth Heyes @garethheyes.co.uk · 26/08/2026My site now uses random() to randomize the solutions to the escape room. Random isn't available yet in any modern browser so it will fallback to a static solution. 000
Gareth Heyes @garethheyes.co.uk · 25/08/2026With Claude I've created CSS/HTML only escape room puzzles on my website. Check it out! Absolutely no JS! Claude created the puzzles so it was quite fun trying to solve them myself 😀 garethheyes.co.ukgarethheyes.co.ukPure CSS first person 3D website portfolio without any JavaScriptThis is website portfolio of Gareth Heyes 010
Gareth Heyes @garethheyes.co.uk · 25/08/2026Here are the Shazzer fuzz vectors I used whilst testing this: shazzer.co.uk/vectors/6a68... shazzer.co.uk/vectors/6a70... Interestingly null is converted to the unicode replacement character.shazzer.co.ukHTML tag localName differences - ShazzerFinds which characters get transformed in localName 000
Gareth Heyes @garethheyes.co.uk · 25/08/2026I put a JavaScript URL inside an HTML tag name, and every browser executed it. Apparently, tag names are code now. portswigger.net/research/wha... 1104
Reposted by Gareth HeyesFreddy @freddyb.bsky.social · 20/08/2026My presentation from OWASP AppSec '26 in Vienna is finally public. Watch me talk about XSS and XSS and Cross-Site Scripting, and XSS in this talk titled "The Devil Is In The Defaults: What To Do About XSS" youtube.com/watch?v=b7RlQdvPY3 (It's also about XSS).youtube.comYouTubeShare your videos with friends, family, and the world 132
Gareth Heyes @garethheyes.co.uk · 13/08/2026You can now generate QR codes in web Hackvertor to share your URLs in presentations. Just click the QR code button. 001
Gareth Heyes @garethheyes.co.uk · 13/08/2026I stole an Outlook password with nothing but CSS inside an email 👀 Whitepaper below 👇 This video is from my research "CSS: the bomb inside your inbox". Whitepaper & slides: portswigger.net/research/css... 174
Reposted by Gareth HeyesTom Stacey @t0xodile.com · 12/08/2026Did you know you can use HTTP header injection to trigger response queue poisoning and make it rain credentials? Learn how with the new @portswiggerres.bsky.social whitepaper "CRLF-Powered Desync Attacks: Beheading HTTP Streams" by @turtlesec.io and I. Read the full paper below 👇 1103
Gareth Heyes @garethheyes.co.uk · 12/08/2026@html5test.com I saw you're doom game :) you could probably do it in pure HTML/CSS. Check this out collision detection in CSS: thespanner.co.uk/pure-css-3d-...thespanner.co.uk 000
Gareth Heyes @garethheyes.co.uk · 07/08/2026If you want to see how to compromise an account from a paste and steal passwords in CSS and much more check out my paper "CSS: the bomb inside your inbox" 👇 portswigger.net/research/css...portswigger.netCSS:the bomb inside your inboxGareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this 163
Gareth Heyes @garethheyes.co.uk · 29/07/2026Next week I'm going to make you terrified of opening your emails...Join me at Black Hat USA for CSS:the bomb inside your inbox 052
Reposted by Gareth HeyesJames Kettle @jameskettle.com · 29/07/2026Next week I'll present "Can AI Do Novel Security Research? Meet the HTTP Terminator" at @defcon.bsky.social & Black Hat USA! I'm really excited to share this one - got some spectacular outcomes from a wild research journey. See you there! 093
Reposted by Gareth HeyesTom Stacey @t0xodile.com · 29/07/2026Come and see Tobia from @turtlesec.io and I at @blackhatevents.bsky.social and @defcon.bsky.social next week! We cannot wait to share what we've found! 011
Gareth Heyes @garethheyes.co.uk · 27/07/2026Of course but who cares the point was to make collision detection work in CSS. Anyway someone on Reddit suggested using sign() which is so cool because now it works cross browser. 100
Gareth Heyes @garethheyes.co.uk · 25/07/2026I've wrote up how to do collision detection in pure CSS. I had loads of fun doing this. thespanner.co.uk/pure-css-3d-...thespanner.co.uk 020
Gareth Heyes @garethheyes.co.uk · 25/07/2026Fixed the teleports on my site. The burger menu now works on all browsers. I'd previously tried to get this working and failed. Opus just did it in about 5 mins. garethheyes.co.ukgarethheyes.co.ukPure CSS first person 3D website portfolio without any JavaScriptThis is website portfolio of Gareth Heyes 000
Gareth Heyes @garethheyes.co.uk · 24/07/2026I use custom properties and if() statements using less-than/greater-than and door state. clamp() enforces the values and the if() statements choose the bound. The first room works, but moving in the other rooms is a bit quirky. 100
Gareth Heyes @garethheyes.co.uk · 24/07/2026My 3D world now has collision detection in CSS! If you run into a wall or door it will stop. Open the door and you can go through. This model is unbelievable. garethheyes.co.uk 150
Gareth Heyes @garethheyes.co.uk · 24/07/2026I redesigned my website using Claude. I burned through a lot of tokens. I basically put all my research in a hallway and created a bookshelf of links. Yes I was up till 1am doing this 😂 it even works on the iPhone. No JS! garethheyes.co.uk 020