Shazzer logo
    • Home
    • Blog
      • Blog home
      • RSS
    • Login
    • Vectors
      • New vector
      • All Vectors
      • Cheat sheets
      • Browser diffs
      • RSS
    • Unicode table
    • Help
    • Home
    • Blog
      • Blog home
      • RSS
    • Login
    • Vectors
      • New vector
      • All Vectors
      • Cheat sheets
      • Browser diffs
      • RSS
    • Unicode table
    • Help
    Shazzer logo

    Shazzer
    Shared online fuzzer

    Fuzzing browsers since 2012

    Made by Gareth Heyes
    Follow me on Twitter: @garethheyes

    Javascript for hackers!

    Hackvertor logo
    The Spanner logo

    If you liked this, you may also like Hackvertor, The Spanner

    New users
    wunna1xDIBO0randomh4ckJ1W0N-1209sealldeveloperc2axraydze1codesoneaccountoneemailNeolex-Securityfatalliskaromeokarki22chil1paperTomAnthonyxskypsdupouysharmaz11hkln1PoisonNomadmantikafasi
    Popular users
    hackvertor (32)renniepak (7)joaxcar (5)albinowax (4)masatokinugawa (3)0x999-x (2)d0ge (2)JorianWoltjer (2)DreyAnd (1)B-i-t-K (1)hansmach1ne (1)securaji (1)sqjor (1)ThomasOrlita (1)weizman (1)koto (1)InsertScript (1)vitorfhc (1)K4r1it0 (1)freddyb (1)
    Recently updated vectors
    Window propertiesAll events on windowTags that support HTML commentsCharacters Allowed Between Protocol // and localhost Where Host Still Equals localhostChars allowed between src and = in img tagCharacters allowed before the JavaScript protocol colonEscape inline double quoteCharacters that starts element nameCSS inline property definitionFuzzing for Max sanitized input (simplified)Chars that can be used as opening bracket in innerHTMLCharacters allowed in the protocol that still resolve host nameURL scheme separator alternatives copyhUnicode characters with a decomposition of 2+ ASCII characters and are registerable domains
    New vectors
    Unicode characters with a decomposition of 2+ ASCII characters and are registerable domainsURL scheme separator alternatives copyhCharacters allowed in the protocol that still resolve host nameChars that can be used as opening bracket in innerHTMLFuzzing for Max sanitized input (simplified)test-idCSS inline property definitionCharacters that starts element nameEscape inline double quoteCharacters allowed before the JavaScript protocol colonChars allowed between src and = in img tagCharacters Allowed Between Protocol // and localhost Where Host Still Equals localhostUrl parsing diff b/w window.open and new URLCharacters ending XML Processing Instructions (WIP)Tags that DO NOT support HTML commentsTags that support HTML commentsTags that get moved out of parentCharacters that can be inside the javascript protocolTags that get reordered in the DOMMalformed HTML comments
    Most popular
    URL domain dot alternatives (3830)DOM element relationships (3647)Characters between < and element name (3595)Characters allowed between hostname and / but don't change the hostname (3592)JavaScript Scheme starting with https:// (3477)Characters that can precede the javascript protocol (3321)Characters allowed javascript and colon copy2 (3139)Characters allowed javascript and colon (2893)< removal bypass (2888)characters allowed between exclamation mark and greater then (2712)Characters that close or encapsulate HTML attribute values (2623)Entities that cause an external URL before @ (2460)Character that closes HTML tag (2365)HTML entities that create ASCII characters inside a JavaScript URL (2340)Includes Validation Chars Allowed (2245)XSS vectors that consume tag (2110)Characters allowed after hostname but don't change the hostname (1973)Characters allowed between multiple HTML attributes (1966)All properties on navigator (two levels of nesting deep) (1892)Characters that can precede the javascript protocol copy2 (1741)
    Most liked
    URL domain dot alternatives (5)HTML entities that create ASCII characters inside a JavaScript URL (4)JavaScript Scheme starting with https:// (4)Entities that cause an external URL before @ (4)Characters allowed between hostname and / but don't change the hostname (4)Characters that can precede the javascript protocol (3)Characters that cause an external URL before @ (3)Characters allowed javascript and colon (3)HTML elements that are self closing or different text content (2)Characters allowed between multiple HTML attributes (2)Characters allowed in-between operators (2)Unicode characters that get normalized into path traversal characters (2)Characters that can be used as valid labels in JavaScript (2)Characters that cause exceptions when URL encoded (2)Characters allowed after optional chaining (2)Characters appended at the end of TLD within URL, which yield in the same Origin (2)Characters that can start an HTML comment (2)Properties that contain URLs (2)Characters allowed after hostname but don't change the hostname (2)Characters that can break out of an inline style background-image url (1)