Gareth Heyes 

2.7K Followers
239 Following
698 Posts
javascript:/*--></title></style></textarea></script></xmp><svg/onload='-/"/-/onmouseover=1/-/[*/[]/-alert(1)//'>

https://garethheyes.co.uk/#latestBook

https://leanpub.com/javascriptforhackers/
My web sitehttps://garethheyes.co.uk/
PortSwigger Researchhttps://portswigger.net/research
Githubhttps://github.com/hackvertor/
My bloghttp://www.thespanner.co.uk/
JavaScript for hackershttps://leanpub.com/javascriptforhackers/
I've added tool tips to the tags in Hackvertor!

New geolocation-based XSS vectors just landed in our XSS cheat sheet. Huge thanks to AmirMohammad Safari for the great submission.

https://portswigger.net/web-security/cross-site-scripting/cheat-sheet#onpromptaction

Massive update to Hackvertor
- Syntax highlighting
- Code editors
- New auto decode box
- Tag and code completion
- Brand new auto decoder
Made Shazzer even more beautiful I took inspiration from F1.

We've just hit a very important milestone - our XSS Cheat Sheet now has 1337 vectors!

Browse them here: https://portswigger.net/web-security/cross-site-scripting/cheat-sheet

Been experimenting with AI to produce 3D effects. Here as you scroll the tiles rotate into place.
Bypass CSP in a single click using my new Custom Action, powered by Rennie Pak's excellent CSP bypass project.
Burp Hackvertor has a bunch of new shortcuts and functionality. Try them out in Burp. They are activated from a Burp repeater request.

Hackvertor 2.2.33 released!

- New MultiEncoder window (CTRL+ALT+M) for applying multiple transformations across layers and sending to Repeater tab
- WebSockets support including a WebSocket handler and a new WebSocket setting
- Improved auto decoding

Demo of the new Shadow Repeater response timing differences.