Shazzer logo
    • Home
    • Blog
      • Blog home
      • RSS
    • Login
    • Vectors
      • New vector
      • All Vectors
      • Cheat sheets
      • Browser diffs
      • RSS
    • Unicode table
    • Help
    • Home
    • Blog
      • Blog home
      • RSS
    • Login
    • Vectors
      • New vector
      • All Vectors
      • Cheat sheets
      • Browser diffs
      • RSS
    • Unicode table
    • Help
    Shazzer logo

    Shazzer
    Shared online fuzzer

    Fuzzing browsers since 2012

    Made by Gareth Heyes
    Follow me on Twitter: @garethheyes

    Javascript for hackers!

    Hackvertor logo
    The Spanner logo
    My Github account
    New users
    nt0xarafax00phatdz159itsryukuRhynoratersaltify7SefeinSaeedYM0124MYbehroozgholizade2-labshidor4585saminormasina-infhackhavenpouria-cryptomahdifn13cookingmbColo-vimaxshihebamrimemorypuddingdaanbreurs2ongmo
    Popular users
    hackvertor (36)renniepak (8)albinowax (5)joaxcar (5)JorianWoltjer (4)0x999-x (4)RenwaX23 (3)masatokinugawa (3)d0ge (2)freddyb (1)hansmach1ne (1)ThomasOrlita (1)DreyAnd (1)B-i-t-K (1)koto (1)jonathann403 (1)securaji (1)InsertScript (1)K4r1it0 (1)sqjor (1)
    Recently updated vectors
    Consuming tagsCharacters that can be inserted in the middle of the JS protocol nameCharacters allowed before javascript URLCharacters between < and element nameEntities still parsed in uppercaseCharacters allowed before CSS selectorsEntities that convert to less than in a iframe srcdocCharacters allowed in path traversalURL domain dot alternativesCharacters allowed between multiple HTML attributesEntities that cause an external URL before @Characters that can be inside the javascript protocolCharacters that starts element nameCharacters allowed inside javascript protocol and still returns the hostnameNamed HTML entities that can be closed with !Closing title tag name separators
    New vectors
    dsqdClosing title tag name separatorsmasato - braves parsing finding entity testmasato - braves parsing finding valid charactersmasato - braves parsing finding valid attributesmasato - braves parsing findingNamed HTML entities that can be closed with !Characters cause self closing tagCharacters ignored following slash in self closing tagCharacters allowed inside javascript protocol and still returns the hostnameCharacters allowed after a bigintCharacters allowed either side of a variable assignmentCharacters allowed after throw statementencodeURI() not encoded with %Characters encoded by escape()Characters encoded by encodeURI()Characters encoded by encodeURIComponent()Characters before custom tagInjection in src attribute PORT, characters that change hostnameCharacters appended at the end of PORT within URL, which yield a different HOST
    Most popular
    URL domain dot alternatives (5.4k)Characters between < and element name (4.7k)DOM element relationships (4.5k)Characters allowed between hostname and / but don't change the hostname (4.4k)Characters that can precede the javascript protocol (4.4k)Characters allowed javascript and colon (4.3k)JavaScript Scheme starting with https:// (4.3k)Characters allowed javascript and colon copy2 (4.2k)< removal bypass (3.9k)characters allowed between exclamation mark and greater then (3.7k)HTML entities that create ASCII characters inside a JavaScript URL (3.6k)Characters that close or encapsulate HTML attribute values (3.3k)Entities that cause an external URL before @ (3.2k)Character that closes HTML tag (3.1k)Characters allowed between multiple HTML attributes (3k)Characters that cause exceptions when URL encoded (2.9k)Includes Validation Chars Allowed (2.9k)XSS vectors that consume tag (2.9k)Characters allowed after hostname but don't change the hostname (2.7k)Tags that get reordered in the DOM (2.7k)
    Most liked
    URL domain dot alternatives (5)HTML entities that create ASCII characters inside a JavaScript URL (4)Characters allowed between hostname and / but don't change the hostname (4)JavaScript Scheme starting with https:// (4)Entities that cause an external URL before @ (4)Characters allowed between multiple HTML attributes (3)Characters that cause an external URL before @ (3)Characters allowed javascript and colon (3)Characters that can precede the javascript protocol (3)Properties that contain URLs (2)Characters allowed after hostname but don't change the hostname (2)Characters that cause exceptions when URL encoded (2)Unicode characters that get normalized into path traversal characters (2)Characters that can start an HTML comment (2)HTML elements that are self closing or different text content (2)Characters appended at the end of TLD within URL, which yield in the same Origin (2)Characters allowed in-between operators (2)Characters that can be used as valid labels in JavaScript (2)Characters allowed after optional chaining (2)All events on window (1)
    freddyb

    freddyb's profile

    You are not following. Is not following you.

    Github profile

    Followers: 1

    hackvertor

    Following: 0

    Vectors 2

    Vector nameUser Created Type Likes
    Firefox logo 116
    Safari logo 79
    Chrome logo 123
    All properties on navigator (two levels of nesting deep)freddyb6/6/2024JS0
    Firefox logo 2
    Safari logo 2
    Chrome logo 2
    Characters that act as attribute quotes copyfreddyb5/31/2024XSS0