Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nullnullnullCollectionsnullstiven_-2009@hotmail.comswo5ne2cti
nullnull96222a1b81b95f8a40726d06b9519d59d40c2ac6dropbox.comnulljim@usaradiorentals.comnull
nullnull9f64895764ce1f5d9912f992658d40387cc49a92linkedin.comnull14995734null
nullnullf3e4423c2b76221e64f0157ddb4cd7fbe889d041linkedin.comnull98755856null
nullnullnulllinkedin.comnull3264562xxx
nullnull17e676052a3f4f9696f8543914c1941b74ea4b1alinkedin.comnulllpuma@mmrree.gob.ecnull
nullnullnullCollectionsnullHenleys@cox.nethenleys
nullnullde7f8f95173fa8c74be5e97527dee630ddc91198linkedin.comnull113089876null
nullnull6d955bd6553b5689c9e9a123b09aba412d845ca3linkedin.comnull68961906null
nullnullnulllinkedin.comnulleducordoba@ciudad.com.arxxx
nullnull529ca70b7b0f403f2797d2dc2de419176fcd1a9elinkedin.comnull82933164null
nullnullnullCollectionsnullahumite@gmailerttl.comv7qif85P
nullnull1f59f261d33a3006d359da877089d89ddc939350linkedin.comnull92322186null
nullben_hep_seviyorum@hotmail.com3424770f9d563c7d4faf7ba3ef7534efbadoo.comnullnullnull
nullnullnulllinkedin.comnull148630632xxx
nullnullnullCollectionsnullpeacock102@msn.comtwosocks
nullnullnullCollectionsnullharkovskiy.valentin@yandex.ru123987645
nullnull04c2994d0a124fc5812ca93ab92b9b779c5e0230linkedin.comnullvvillafaena@gmail.comnull
nullgiuseppe.sireci@aliceposta.itd479263a1438a8f9e85937a3a2d4f4a8badoo.comnullnullnull
nullnulla3b211fdc8e5051200f7f2c97113b0b4b2e69a11linkedin.comnull18753359null
nullnullnullCollectionsnulllen12345@hotmail.com12345
190.50.79.231nullnull000webhost.comPablo Barrenecheapablo.barrenechea@gmail.compablo84
nullnull03dfd4368098030618222ac9c78715090557071dlinkedin.comnullf.seinstra@live.nlnull
nullnull1c6042b9bdcdd770b665eba4ce29716106d71ef8linkedin.comnull167598065null
nullnullnulllinkedin.comnull87778792xxx
nullfabiolaf1@live.itd47169676fe2f3cd90e97d7bb26f6fe9badoo.comnullnullnull
nullnullf4483dcbc483416e2e56ae197e390fbe0a767439linkedin.comnull116624067null
nullnullb9967cc6b50c07955b32dcecd31c254eb3c950c2linkedin.comnull139583573null
nullhellion92@hotmail.com294e5308a769abafa11b5caea4160b01badoo.comnullnullnull
nullracsogm_89@hotmail.com6b38dfea8bece3315fcb233447730c71badoo.comnullnullnull
nullnullfdbaf16e96c3a2b4a7b7513d66172cc37cc40754dropbox.comnullmanny@fleetfeetsanfrancisco.comnull
nullnulla060ced6131d46a3375f90c3a37926890ebc325dlinkedin.comnull149849844null
nullnull7c4a8d09ca3762af61e59520943dc26494f8941blinkedin.comnull1122914null
nullnull8d04d4dd2aeeaec046b890d162f0d94ffa74272clinkedin.comnull57586844null
nullnullnulllinkedin.comnull20972222xxx
nullnullnull7k7k.comnullLIUHU@LL.COM2526620
nullnullnullCollectionsnullaustinpaul1997abcd1234
nullnullnullCollectionsnullmz.daniel_652@rocketmail.commz.danielallday
nullnull40ffa173eaacf794b2ce046f0611592180929763linkedin.comnull94755207null
nullnullnulllinkedin.comnull97172482xxx
nullnullc9f00763b2697d930a2f117249278fc90cae3df4linkedin.comnull43910849null
nullnelonutz@bk.ru42844c40b4f14b8ccbb0c3bb006a1c1fbadoo.comnullnullnull
nullmanos_the_dude@hotmail.com53103306c257b62216f94562d9582186badoo.comnullnullnull
nullmanuelrg2011@hotmail.es92b8e148ff3fd42ce267af5491def576badoo.comnullnullnull
nulllamechagerman@hotmail.com0065abeb3658f03f26cd6b0e8d4c8597badoo.comnullnullnull
nullsoomin310@naver.com3fa5f02cca315be7eadf82dc369ba201badoo.comnullnullnull
nullnullnull7k7k.comnullvincentone520860803
nullnull328e904745c28b29ef3a1eedaba26d7577097a34linkedin.comnull88978846null
nullnull8e23f224d533daebe7fc034e5dc86720aa123002linkedin.comnullctoliverjr@gmail.comnull
nullnull0e818bfa0679df304036382aaa7667df92cbe30elinkedin.comnull70061106null
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.