Gareth Heyes is a PortSwigger web security researcher best known for pioneering research into cross site scripting, particularly DOM based XSS, and for discovering novel filter bypass and payload techniques. His work has significantly shaped modern client side vulnerability detection and exploitation. He is the author of the book "JavaScript for Hackers" and PortSwigger’s XSS Cheat Sheet.
At PortSwigger, Gareth spends his time researching new techniques for attacking web applications and inventing ever more creative XSS vectors. He has a particular fascination with abusing CSS in unconventional ways, from pure CSS 3D rooms and games to pushing markup languages well beyond their intended limits on his website. In his spare time, he enjoys building Burp Suite extensions, including the widely used Hackvertor.
Three mechanisms hold the lid. Every figure you need is struck, chalked or engraved somewhere in these rooms — the Cipher ledger on the bookcase explains the mechanisms.
Hang brass weights on the pan until the beam reads the engraved figure. Something in this room is engraved too small to read with the naked eye.
Pans read
Three dials, one hexadecimal digit each. The pairs are etched on a plate in this room; what to do with each pair is in the ledger.
Four brass seals are struck around the rooms — two in the entrance hall, two in here. Set the tumblers to their digits, I to IV.
The lid holds fast.The hasp springs. Close this and lift the lid.
Notes on the lockbox in the corner. Three mechanisms, all of them stupid, none of them mine.
The target weight is engraved on the balance itself, in figures far too small for anyone but a jeweller. A glass hangs on the wall you had your back to as you walked in.
The plate by the window gives three pairs of hex digits. Each dial takes one pair, folded together:
the pair the pair the pairFour brass seals, numbered I–IV, each struck with one digit. Read them in order and set the four tumblers to match.
Two are in the entrance hall: one under the graffiti, one on the gallery door. Two are in here: one on the window frame, one at the foot of this bookcase.
| 0 | 1 | |
|---|---|---|
| XOR | same → 0 | different → 1 |
| AND | 1 only where both bits are 1 | |
| OR | 1 where either bit is 1 | |
Splitting the email atom: exploiting parsers to bypass access controls2024
Using form hijacking to bypass CSP2024
onwebkitplaybacktargetavailabilitychanged?! New exotic events in the XSS cheat sheet2024
Hiding payloads in Java source code strings2024
Exploiting XSS in hidden inputs and meta tags2023
Ambushed by AngularJS: a hidden CSP bypass in Piwik PRO2023
Detecting web message misconfigurations for cross-domain credential theft2022
Our favourite community contributions to the XSS cheat sheet2022
Hunting nonce-based CSP bypasses with dynamic analysis2021
Portable Data exFiltration: XSS for PDFs2020
Attacking and defending JavaScript sandboxes2020
Evading CSP with DOM-based dangling markup2018
Unearthing Z͌̈́̾a͊̈́l͊̿g̏̉͆o̾̚̚S̝̬ͅc̬r̯̼͇ͅi̼͖̜̭͔p̲̘̘̹͖t̠͖̟̹͓͇ͅ with visual fuzzing2018
Bypassing CSP using polyglot JPEGs2016
Burp Clickbandit: A JavaScript based clickjacking PoC generator2015
Abusing Chrome's XSS auditor to steal tokensAbusing Chrome's XSS auditor to steal tokens2015