Shazzer logo
    • Home
    • Blog
      • Blog home
      • RSS
    • Login
    • Vectors
      • New vector
      • All vectors
      • Categories
      • Cheat sheets
      • Browser diffs
      • RSS
    • Unicode table
    • Help
    • Home
    • Blog
      • Blog home
      • RSS
    • Login
    • Vectors
      • New vector
      • All vectors
      • Categories
      • Cheat sheets
      • Browser diffs
      • RSS
    • Unicode table
    • Help

    Vector categories

    All
    Browser Quirks
    CSS Parsing
    Character Encoding
    DOM Behavior
    Entity Parsing
    HTML Parsing
    JavaScript Syntax
    URL Handling
    XML Parsing
    XSS Execution
    Shazzer logo

    Shazzer
    Shared online fuzzer

    Fuzzing browsers since 2012

    Made by Gareth Heyes
    Follow me on Twitter: @garethheyes

    Javascript for hackers!

    Hackvertor logo
    The Spanner logo
    My Github account
    New users
    bbcoms3fleazyIIlllIlIIltrongphuc12SwaildeafTitifelBro47crinkytreadmill180masudranaalirezakhoshsohbatPentestteamfoodTS0NW0RKjejex0lulzashadonisKahilaalt33370xbartmosslogag1ehourdebaigtdavidbors-snykph4nt0mbyt3
    Popular users
    hackvertor (37)renniepak (8)JorianWoltjer (6)joaxcar (5)albinowax (5)RenwaX23 (4)0x999-x (4)masatokinugawa (3)d0ge (2)hansmach1ne (2)DreyAnd (1)securaji (1)jonathann403 (1)B-i-t-K (1)koto (1)ThomasOrlita (1)weizman (1)InsertScript (1)K4r1it0 (1)sqjor (1)
    Recently updated vectors
    Character allowed after onerror eventCharacters that change length on .toLowerCase()XSS vectors that execute automatically inside mathCharacters allowed instead of equal signProperties are accessible in a sandboxed iframeHTML entities inside JavaScript URL before colonCharacters that can break out of an inline style with double quotesCharacters that can break out of an inline style with single quotesISO-2022-JP ASCII escape sequenceCharacters ignored following slash in self closing tagCharacters cause self closing tag
    New vectors
    Characters allowed in between // in absolute URLcharacters between function name and parenthesesCharacters allowed begin from a forward slash character in javascript protocolCharacters allowed while closing script tagCharacters after https URI scheme which prevent URL parsing of hrefchars before img tagsChars allowed before style attribute...Characters allowed before after onerror eventsElectron XSS TESTCharacters allowed in between @importdsqdClosing title tag name separatorsmasato - braves parsing finding entity testmasato - braves parsing finding valid charactersmasato - braves parsing finding valid attributesmasato - braves parsing findingNamed HTML entities that can be closed with !Characters cause self closing tagCharacters ignored following slash in self closing tagCharacters allowed inside javascript protocol and still returns the hostname
    Most popular
    URL domain dot alternatives (5.6k)Characters allowed javascript and colon (5.5k)JavaScript Scheme starting with https:// (5.4k)Characters between < and element name (5.2k)DOM element relationships (4.9k)Characters that can precede the javascript protocol (4.9k)Characters allowed between hostname and / but don't change the hostname (4.9k)Characters allowed javascript and colon copy2 (4.3k)< removal bypass (4.1k)characters allowed between exclamation mark and greater then (3.9k)HTML entities that create ASCII characters inside a JavaScript URL (3.8k)Character that closes HTML tag (3.5k)Characters that close or encapsulate HTML attribute values (3.5k)Entities that cause an external URL before @ (3.4k)Includes Validation Chars Allowed (3.3k)Characters that cause exceptions when URL encoded (3.2k)Characters allowed between multiple HTML attributes (3.2k)Characters allowed in-between operators (3.2k)HTML elements that are self closing or different text content (3.2k)XSS vectors that consume tag (3.1k)
    Most liked
    URL domain dot alternatives (5)HTML entities that create ASCII characters inside a JavaScript URL (4)Characters allowed between hostname and / but don't change the hostname (4)JavaScript Scheme starting with https:// (4)Entities that cause an external URL before @ (4)Characters allowed between multiple HTML attributes (4)Characters that can precede the javascript protocol (3)Characters allowed javascript and colon (3)Characters that cause an external URL before @ (3)HTML elements that are self closing or different text content (2)Characters allowed after hostname but don't change the hostname (2)Characters allowed after optional chaining (2)Unicode characters that get normalized into path traversal characters (2)Characters that can be used as valid labels in JavaScript (2)Characters that cause exceptions when URL encoded (2)Characters that can start an HTML comment (2)Characters allowed inside javascript protocol and still returns the hostname (2)Characters appended at the end of TLD within URL, which yield in the same Origin (2)Characters allowed in-between operators (2)Properties that contain URLs (2)