Shazzer logo
    • Home
    • Blog
      • Blog home
      • RSS
    • Login
    • Vectors
      • New vector
      • All vectors
      • Categories
      • Dynamic template
      • Browser diffs
      • RSS
    • Cheat sheet
    • Unicode table
    • Help
    • Home
    • Blog
      • Blog home
      • RSS
    • Login
    • Vectors
      • New vector
      • All vectors
      • Categories
      • Dynamic template
      • Browser diffs
      • RSS
    • Cheat sheet
    • Unicode table
    • Help
    Shazzer logo

    Shazzer
    Shared online fuzzer

    Fuzzing browsers since 2012

    Made by Gareth Heyes
    Follow me on Twitter: @garethheyes

    Javascript for hackers!

    Hackvertor logo
    The Spanner logo
    My Github account
    New users
    pablosobrerobdohocnchipotermiahacksfishystockdulphMaindandh811Serizao-bzhuntt0t048LEEjieiunnullkryptjonathanlevy-imperxkmikzeL3ster1337ixSlyfiansodesminesx6vrnsantaonbeachMbarekYtasumeet-darekarslandren
    Popular users
    hackvertor (38)renniepak (9)JorianWoltjer (6)joaxcar (5)albinowax (5)RenwaX23 (4)0x999-x (4)masatokinugawa (3)d0ge (2)hansmach1ne (2)AyushXtha (2)freddyb (1)B-i-t-K (1)ThomasOrlita (1)koto (1)DreyAnd (1)jonathann403 (1)securaji (1)InsertScript (1)K4r1it0 (1)
    Recently updated vectors
    Characters that cause the backslash to be consumed with GBK charsetURL scheme separator alternativesCharacters appended at the end of PORT within URL, which yield a different HOSTCharacters before custom tagCharacters encoded by encodeURIComponent()Characters encoded by encodeURI()Characters encoded by escape()encodeURI() not encoded with %Characters allowed after throw statementCharacters allowed either side of a variable assignmentCharacters allowed after a bigintCharacters allowed inside javascript protocol and still returns the hostnameCharacters ignored following slash in self closing tagCharacters cause self closing tagmasato - braves parsing finding valid charactersClosing title tag name separatorsdsqd
    New vectors
    Valid space characters in a regexUnicode "Latin" characters using \p{scx=Latin} RegExCharacters matching RegEx /\w/uiCharacters allowed in between // in absolute URLcharacters between function name and parenthesesCharacters allowed begin from a forward slash character in javascript protocolCharacters allowed while closing script tagCharacters after https URI scheme which prevent URL parsing of hrefchars before img tagsChars allowed before style attribute...Characters allowed before after onerror eventsElectron XSS TESTCharacters allowed in between @importdsqdClosing title tag name separatorsmasato - braves parsing finding entity testmasato - braves parsing finding valid charactersmasato - braves parsing finding valid attributesmasato - braves parsing findingNamed HTML entities that can be closed with !
    Most popular
    URL domain dot alternatives (6.5k)Characters allowed javascript and colon (6.2k)JavaScript Scheme starting with https:// (6.2k)Characters allowed between hostname and / but don't change the hostname (5.3k)Characters between < and element name (5.3k)Characters that can precede the javascript protocol (5k)DOM element relationships (5k)HTML entities that create ASCII characters inside a JavaScript URL (4.7k)characters allowed between exclamation mark and greater then (4.6k)Characters allowed javascript and colon copy2 (4.5k)< removal bypass (4.2k)Characters appended at the end of TLD within URL, which yield in the same Origin (3.8k)Characters that close or encapsulate HTML attribute values (3.7k)Character that closes HTML tag (3.7k)Characters that cause exceptions when URL encoded (3.6k)Entities that cause an external URL before @ (3.5k)Unicode characters that get normalized into path traversal characters (3.4k)Characters allowed between multiple HTML attributes (3.4k)Includes Validation Chars Allowed (3.4k)Characters allowed after hostname but don't change the hostname (3.4k)
    Most liked
    URL domain dot alternatives (5)JavaScript Scheme starting with https:// (4)Characters allowed between hostname and / but don't change the hostname (4)Characters allowed between multiple HTML attributes (4)HTML entities that create ASCII characters inside a JavaScript URL (4)Entities that cause an external URL before @ (4)Characters that cause an external URL before @ (3)Characters allowed inside javascript protocol and still returns the hostname (3)Characters allowed while closing script tag (3)Characters allowed javascript and colon (3)Characters that can precede the javascript protocol (3)Characters that cause exceptions when URL encoded (2)Properties that contain URLs (2)Characters allowed after hostname but don't change the hostname (2)Unicode characters that get normalized into path traversal characters (2)Characters that can start an HTML comment (2)HTML elements that are self closing or different text content (2)Characters appended at the end of TLD within URL, which yield in the same Origin (2)Characters allowed in-between operators (2)Characters that can be used as valid labels in JavaScript (2)

    Distributed Fuzzing

    Enabled:
    Status:disconnected
    Your browser automatically contributes to distributed fuzzing when idle.