Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nulllurpapedro@hotmail.com06d22508e33a783cd0b5d88a454b5d8dbadoo.comnullnullnull
nullluciano.rgt@gmail.com37ac15dd2b47c59ba5c93848c52c5501badoo.comnullnullnull
nullnullc0a0d29a973d3635e9c07220541783278fd65ffclinkedin.comnullcarbiologo@hotmail.comnull
nullnullnullCollectionsnullfarias3318@yahoo.comsarahabdelaziz
nullnullnull7k7k.comnullviracocha@sina.combsksfc
nullnullnulllinkedin.comnullviola210120@hotmail.comxxx
nullnullc0debe4450198d5c5f00cc46f58d6f67e9fbda58linkedin.comnullabourassa@wasteprofessionals.comnull
nullnull10c31b8e81ae0e4c6dd1b97d41d0abe48d5fc841linkedin.comnull81297374null
nullpaty010x@hotmail.combfee377f3ba305117ef9c89899eaa713badoo.comnullnullnull
nullnullnullCollectionsnullcbrandle79@hotmail.comslayer666
nullnullnullCollectionsnullBenwolf@yahoo.comcowboys
nullnull$2a$08$40sxD9FRJUixlycHnvQw9utgRZ9TM9P9N8tHpFAhlerX0ty1Qjtlmdropbox.comnulldkhordi@gmail.comnull
nullnull124b3f693a401a72f54361db5ed65f230eaa920elinkedin.comnullayesha.khaan1102@gmail.comnull
nullnullnulllinkedin.comnull125335141xxx
nulluma.coolzone@gmail.comc2856ad08c52de18d4af571a7bcece5abadoo.comnullnullnull
nullsbvivian2008@hotmail.comc890079d3a774ee59e793a3fd3e4e68ebadoo.comnullnullnull
nullnullc95ae20d6aa7ce3de0b9643f20e76edd856da7c4linkedin.comnulla.b@c.esnull
nullnull6e4590bf3b352a2722b1f9fd56e545a3310c65a7dropbox.comnullbrueggemann.christin@web.denull
nullnullnull7k7k.comnull86420975315buxksySJE
nullnullnulllinkedin.comnull48517591xxx
nullmasters76460@orange.frb56b8c8d2f31778eab016f22700d5417badoo.comnullnullnull
nullnulld8fd6c8ef87b913b686a362afd60d8482f2a2a8flinkedin.comnulloumar.traore@sotra.cinull
nullildaruela@hotmail.comb382c4efbfc18db5e0c8c09eee1ade5bbadoo.comnullnullnull
nullgege33007@yahoo.fr0c48360c82f3dff2fcfbf1b207c32b0fbadoo.comnullnullnull
nulls.burgos@terra.es131985bc4d4f5e3ff7a2b58bd4d89656badoo.comnullnullnull
nullnull98c88b309402922555094602b017fb4ada9b1439linkedin.comnullJROJAS_212@hotmail.comnull
60.53.177.91nullnull000webhost.comChosenilovetpg@gmail.comilovetpg@gmail.com
nullnull75634113be468efc6d8b11e0b6b6a611bfa5ea0fdropbox.comnullannagalliker@yahoo.denull
nullnullnullCollectionsnullperes403@wp.plpi3evest8e
86.57.185.184nullnull000webhost.comBertellicorneytzg259@yahoo.comlimaha256
nullderyaozizmir@hotmail.comf89cb9e0d49ee3b42c6f142306d4ce49badoo.comnullnullnull
nullnullnullCollectionsnulldurank1331@hotmail.com1331duran
nullnullnullCollectionsnullBernhard.Burkard@web.deul0arym4en
nullnullnull7k7k.comnullxinyi198608@yahoo.com.cn119120
nullalcatraz2001@hotmail.fr49fda5d1acc4693f7a846682eca94eeebadoo.comnullnullnull
nullnull1c6df8b8db366d48160daf3c16420754494a9963linkedin.comnull18938698null
nullnull$2a$08$uWfm58ciMDUKdH6QmVw0MOcICpbrEqc/uH0bnYLJWOkKxHV7aySvudropbox.comnulljessica.pahl@ruhr-uni-bochum.denull
nullnullnullCollectionsnullnascakirgoz@hotmail.comxokipuqa
nullnullnullCollectionsnullhuangkin@me.comkinjel
nullnullnulllinkedin.comnullethel_visita@yahoo.comxxx
nulliv32@seznam.czafcba707cb0305a9114ba0dc485c6647badoo.comnullnullnull
nullctflw@hotmail.com246bf1ab30ff831bbc087b6f87e8cf16badoo.comnullnullnull
nullnull48058e0c99bf7d689ce71c360699a14ce2f99774linkedin.comnullkit@furesoe.dknull
nullnull3c1651254431c72a3fcb9f8e6ffa2552f37d9e7clinkedin.comnull55734048null
nullnullnullCollectionsnullcarcreer@gmail.comalioli
nullnull9724e4ad0e52269011d07226ff4d873be123f3c7linkedin.comnullstraussek@skynet.benull
nullnulled84903d635d1e228dec45dc037859726da40cc5linkedin.comnull36673046null
nullnullnullCollectionsnullrocketsarg2000@yahoo.comzztop1
nullnullnulllinkedin.comnull70764481 xxx -> zoesierra@comcast.net
nullnulle3685a98848ee8a24643f69c1cd9dbaac078e495linkedin.comnull42614873null
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.