Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nulllady.1968@hotmail.de97b6515781563c4f2dc0e17fbac6968abadoo.comnullnullnull
nullnullf7e8066b5810871dedb038fc739dec06d4514415linkedin.comnulldrhffulmer@yahoo.comnull
nullnallelarsen@live.dka1f3b0ce614e8f9e1d2035562ae0b915badoo.comnullnullnull
nullnull$2a$08$KWpyRf2IKtECtcurk1RAr.zK/aQ6shdqoaXLvyjjUWH5uCk4Gb7SKdropbox.comnulljarka.metelkova@gmail.comnull
nullvalentyn-ka@centrum.cza84114aa9a2a25a5100be820cb049674badoo.comnullnullnull
nullhornyforeurop@hotmail.comc7630aa8566c2c39c4c2ea1589cc75e7badoo.comnullnullnull
nullnullnullCollectionsnullRogermwa@gmail.comdum
nullnull1652d912ac7ac136f414fca42577a7839678c9f3linkedin.comnullstephanie_hartzell@vfc.comnull
nullnull99996b911567c83cce17cdf194f314975c57ddf1linkedin.comnull23703876null
nullnullnullCollectionsnullfaiez_sazwan@yahoo.comkacang
nullnull$2a$08$OCuMTnI19mXITLxZaVlSCuIdrYsKLwZfWrDTLfus23NHTW0pINcZ.dropbox.comnullo.brohm@lantastic.orgnull
nullnulla80c5ccf303862093d30fdaeb3311d952ea0b23alinkedin.comnull144669804null
nullnull5bd68a05519ea66d95f09aed121f6b9ee424e494linkedin.comnull144283799null
nullnullnullCollectionsnullhimselfwins@yahoo.comcatxcatx1
nullnullnullCollectionsnullhan_yoo_min1983@hotmail.comtogzad34
nullhak38@live.fr6a3495f5be0a54f2eaf8fb54f8867fd3badoo.comnullnullnull
nullnulld07100ac3bfe8a86e9654236382769ee2df2d088linkedin.comnull126473138null
nullerquic_81@hotmail.com8f91bdb4de0142710ac1718345b96308badoo.comnullnullnull
nullnulled9d3d832af899035363a69fd53cd3be8f71501clinkedin.comnull67652017null
nullnullnull7k7k.comnullmaxtyttyt910911
nullazemezad_fiw115@hotmail.comda0ea5a22fb09094f5da473430af7c5cbadoo.comnullnullnull
201.230.73.154nullnull000webhost.compuca21animax_fx@hotmail.comnemrac41
nullnullnullCollectionsnullgabrielcazoni@hotmail.com159852
nullnullnulllinkedin.comnull166014802xxx
nullnullnulllinkedin.comnulldekadhruba54@gmail.comxxx
nullnullnulllinkedin.comnull71117675 34f4a89aed98426845b005d41c224c95f7335540 -> mikej042002@yahoo.com
nullnullcedf41fccb586dc39e1ce34bb482f0afe557b49flinkedin.comnull145129853null
nullnullnullCollectionsnullg.tony.121@hotmail.comtrinitron121
nullnullnullCollectionsnulllonesome_being@yahoo.comworldofwarcraft
nullnull768f3c08b3df8b7eb06df8d81ca5551fc98680bclinkedin.comnull145093099null
nullnullnulllinkedin.comnull123326632xxx
nullnullnullCollectionsnullloolly2510@hotmail.com251072211
nullnullnulllinkedin.comnullroof_runner@hotmail.comxxx
nullnull2e8839c3f0ac32c638e538da37f17739e3ce85c5linkedin.comnull155698108null
nullnullnulllinkedin.comnull149742542xxx
nullnullcac113a94846e356ab11687a4a2180024c73c47blinkedin.comnull102858298null
88.20.85.76nullnull000webhost.comYour nameflesk88@gmail.comzmxn10alsk10
nullnullnulllinkedin.comnull20012882xxx
nullnullnulllinkedin.comnulljy100aaa@hotmail.comxxx
nullnullnullCollectionsnulltashajaner@yahoo.co.ukshankley1
nullnull1c784d8e5b66c01ee0f549490d644b97715e0fb1linkedin.comnull161894006null
nullnullnulllinkedin.comnull12758431xxx
nullnullnullCollectionsnullwallmark.eric@telia.commamma45
nullnullnulllinkedin.comnull67585051xxx
nullnullnullCollectionsnulltina_colija_i@hotmail.comcufi533
nullstefan2105@freenet.de0e9e0a87a0f05387aaee642237cf1573badoo.comnullnullnull
nullnullnulllinkedin.comnull65460402xxx
nullnullf9a2b31caa8ec026a6d1aecf7d56b666487bd346linkedin.comnulldaniel.rosario@stofgaming.comnull
nullhighdaumrutu@yahoo.comc232e18d33117cd9c02da67375e5b5f8badoo.comnullnullnull
nulllaviolettedavid@live.fr20148ed2c9a4f8f02a5eceb836a67360badoo.comnullnullnull
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.