Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nullnullnulllinkedin.comnull21189750xxx
nullnullnulllinkedin.comnullbossuyt.degroote@base.bexxx
nullnull5a3bd81cb8fb97df393ced961be8c1e2ef275b1adropbox.comnullbpostnha@gmail.comnull
nullwirk_sawio@o2.pl2f436a4490a80f83d8ba4654b4bf282dbadoo.comnullnullnull
nullnull$2a$08$GlXI0CEc/ZHRotcM88dvUOiBHZgl.LNX7RXzHXPZ.lc0VJ31byCS6dropbox.comnullmail@nickyreinert.denull
nullcedriczit@live.fr355ba1b5f5db3cf06e0df26911fa3033badoo.comnullnullnull
nullnullnullCollectionsnullwarhead31d@mail.ru1q2w3e4r5t6y
nullnullnullCollectionsnullgrotte72@hotmail.deT9V6i0p0
nullnullnulllinkedin.comnullmichelle-jardim@hotmail.comxxx
nullnullnullCollectionsnullwee_william_uk@hotmail.com.blocked_recovery39029267
nullnullnullCollectionsnullkatorina20@mail.ru199117k
nullnullnull7k7k.comnullCHENHF8@tianya.cn3.33384E+11
nullnullnulllinkedin.comnull65785444 f25c59df624a108af409184d13dc5a6800853e4e -> pmd@ltdeng.com
nullnull719f6ab91342fbae13b3aa41e6d1c2c5a654e720linkedin.comnull73212908null
nulltriagung_sihutomo@yahoo.com30862911cba1b059821d458c88567cc6badoo.comnullnullnull
nullnull59090e13bfc16d83a6b8c7ef9d9c7722f2c76fbdlinkedin.comnull107264643null
nullnullnullCollectionsnullfablenaz3123071998
nullnullnullCollectionsnullsvetlana_kumpan@mail.ru12345678
nullnullnullCollectionsnull858911806@qq.comyinan1984
nullnullnulllinkedin.comnull8218052xxx
nullnull46a551f2984d549e6e696effe1c673779ca86a56linkedin.comnullvenku_lux@yahoo.comnull
nullnull2153e647e345fae0e0bbc074611ade940a914a45linkedin.comnullpaulenechua@gmail.comnull
219.137.78.97nullnull000webhost.comwood32990091@qq.com123456789a
nullnullc0d583c45e351de742c8b9e7e50e583872bd8f04linkedin.comnulljoshua_wagner@moore.sc.edunull
nullcapi_1@libero.ite859eb5114489b9aa0dbea6d57ba85cbbadoo.comnullnullnull
nullnull5368962bb72315f994be950b51786775b648c1fblinkedin.comnull132405833null
nullnullnulllinkedin.comnullresponse@icarehospital.orgxxx
86.108.64.239nullnull000webhost.combscotehbscoteh@yahoo.com0507529236d
nullnullnulllinkedin.comnull160223600xxx
nullnull8c5c8b61f7542888ee2262b84fe2e918db9e36f8linkedin.comnull146442866null
nullnullnullCollectionsnulloksanochki@mail.ruhtRCM8ka
nullnullf08c60bbdb57b2324842919a230e440d0749a791linkedin.comnullttgrick@aol.comnull
nullnullcd6d181c8475e7d67e68668d1b2d6b12be149652linkedin.comnull135281683null
nullnullaf7928af61f2adb71027268105385e6b8663835blinkedin.comnull42244028null
nullnull7c138a280c6f47c74ff9f8a237e1885c82e4484fdropbox.comnulldiscushawk76@yahoo.comnull
nullnullnulllinkedin.comnull165131252xxx
nullnulle5113ab506641999cd7257f85d195cccd2c5e250linkedin.comnull21816493@qq.comnull
nullnull2f615f77f4cbafda2c80b19cdf2fcf81d420590elinkedin.comnull155859427null
nullnullnullCollectionsnulljrw5599@gmail.comrallyskalic123
nullnullcf9fa0d74f34730f71cd67acd789c2ad6d4124f1linkedin.comnull27800189null
nullnull2da3c7996969827bea9a352b865c3a6e301fc03elinkedin.comnull13388218null
nullnull5269efc3b199f389f449279f47f1d598106ddd65linkedin.comnullloig.noblet@gmail.comnull
nullchetina.luybov@mail.ru4f18b6e128d41db8316b454446b2a315badoo.comnullnullnull
nullnullnullCollectionsnullRashadhorton@att.netrayray89
nullnullnullCollectionsnulldeviantbehaviour619@yahoo.comkalel1123581321
nulllatupi_93@hotmail.comd10926c160ce6a5bd5c86b452bf1c70dbadoo.comnullnullnull
nullnull6721f4298917c97aa9feb19be8de4fce061995b4linkedin.comnulllatalisafran@yahoo.com.brnull
nullnullnullCollectionsnulldanilas00@yandex.ru220700
nullesra_0014@hotmail.de63b4c6c7bca44e84b927feb89ca496e8badoo.comnullnullnull
nullnullnull7k7k.comnullsinotigercai319251
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.