Gareth Heyes
Home
Book
Controls
Games
Tic Tac Toe (No JS or CSS)
Tic Tac Toe (No JS or HTML)
Cascade of duty (No JS)
Random dice (No JS or CSS)
Keyboard controls
Mac
Ctrl+Alt+WUp<br>Ctrl+Alt+ALeft<br>Ctrl+Alt+DRight<br>Ctrl+Alt+SDown<br>Ctrl+Alt+XStop
Windows
Shift+Alt+WUp<br>Shift+Alt+ALeft<br>Shift+Alt+DRight<br>Shift+Alt+SDown<br>Shift+Alt+XStop
Close
Gareth Heyes
PortSwigger researcher Gareth Heyes is probably best known for his work escaping JavaScript sandboxes, and creating super-elegant XSS vectors. When he's not authoring books (like the recent title, JavaScript for hackers), Gareth is a father to two wonderful girls and husband to an amazing wife, as well as an ardent fan of Liverpool FC.
In his daily life at PortSwigger, Gareth can often be found creating new XSS vectors, researching new techniques to attack web applications, and preparing to speak at conferences around the globe. He's also the author of PortSwigger's XSS Cheat Sheet, and the creator of Hackvertor and Taborator.
Close
Inspiration
James Kettle
Mario Heiderich
lcamtuf
Michał Bentkowski
Masato Kinugawa
Alex Inführ
Filedescriptor
Luan Herrera
Manuel Caballero
Eduardo Vela
Krzysztof Kotowicz
Ben Hayak
Mathias Karlsson
Jan Horn
Yosuke Hasegawa
Stefano Di Paola
Soroush Dalili
Giorgio Maone
Frederik Braun
Amit Sheen
Close
Profile
Profile
LinkedIn<br>Twitter<br>Mastodon<br>Bluesky<br>Blog<br>Email
Contact
DOM Invader<br>Hackvertor website<br>Hackvertor BApp<br>Shazzer website<br>Taborator BApp<br>SSPP Scanner
Tools
XSS for PDFs<br>DOM sandbox escapes<br>JSON hijacking<br>Unknown browsers<br>XSS horror show<br>Non-alpha JS/PHP<br>Splitting the email atom
Talks
Inspiration
Inspiration
JS for hackers · paperback<br>JS for hackers · ebook<br>Web App Obfuscation
Books
Research gallery
Link room
SVG animate XSS vector
Exposing Intranets with reliable Browser-based Port scanning
Rewriting relative urls with the base tag in Safari
DOM based AngularJS sandbox escapes
Executing non-alphanumeric JavaScript without parenthesis
Edge XSS filter bypass
Abusing Chrome's XSS auditor to steal tokens
New IE mutation vector
MentalJS DOM bypass
XSS Auditor bypass
Unbreakable filter
Bypassing the XSS filter using function reassignment
Sandboxed jQuery
Epic fail IE
Decoding complex non-alphanumeric JavaScript
The evolution of code
Tweetable PHP-Non Alpha
MentalJS Sandbox/Parser
Hacking caja part 2
PHP nonalpha tutorial
Code mutation experiments
Unicode rendering errors
Eval a url
RIPS static source code analyser
Introducing Shazzer: A shared online fuzzer
staticHTML property
We need @ urls
Protecting against XSS
Unicode monster is back this time eating chrome
The JSON specification is now wrong
JSON Hijacking
DOM sandboxing talk
Regex HTML Sanitisation can work
How do you spell JavaScript again?
XSS Rays extension
Late meta Christmas present
JSReg bypasses
New Hackvertor upgrade
XSS Zones
Function is the new window
Setters using VBS and constant hacks
Astalanumerator 0.7
Hackvertor Ajax applications
Month of PHP security
HTMLReg
Solving the secret question problem
Hackvertor API
My RegExp is still leaking
Facebook sandbox escape
Ping pong obfuscation
Bypassing CSP for fun, no profit
PHP self return of the slash
Fresh prototypes on all browsers
JSReg update
New beta of JSReg
Minor Safari cross domain bug
New PHPIDS vector
Hackvertor obfuscated code tutorial
Opera XSS vectors
onreadystatechange
XSS Rays
Hackvertor now translates
Javascript unique strings with RegExps
Detecting IE in 12 bytes
Hackvertor now decodes css escapes
Crazy javascript
I know what your friends did last summer
Location based XSS attacks
Javascript vbscript challenge
Wordpress plugin security
To infinity and beyond!
XSS is art
New XSS vector
Strings to array
Javascript protocol fuzz results
XSS tag fuzzer
Double encoding javascript
Javascript getters hacking
Codetcha update
Hidden javascript properties
Firefox javascript sandboxing
Hackvertor fixes
CSRF chat
Javascript regular expressions
Unicode half and full width conversion
Hackvertor update
Exploiting PHP SELF
DOM DOS Firefox
Self replicating source
Hackvertor fuzzing tool
Tracking users across browsers
Incrementing in CSS
CSS animation!
Browser window spawning DOS
Latest security news
htmlentities is badly designed
WebFu crouching tab hidden dos
Pointing the finger
Unusual XSS vectors
Safari security
Spoofing Firefox protected objects
WebFu Dojo - XSS self defence
Hackvertor video demo
IFrames security summary
JSCK demo update
Regular expression challenge
Blogsecurity
Google Adsense flaw revealed
Injecting the script tag into XML
iPhone Safari zero day
OpenID security CSS overlays
Hackvertor
Flash XSS
Noscript has iframe protection
New Spambam plugin
Thank you and good night Planet PHP
So you think you're a hacker?
Wordpress lockdown
The blogs you should read
More browser bugs equals greater risk
CSS LAN scanner
Protection...