Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nullnull6388f7637b0b99bb39dc9e8d52249906dd47ff1blinkedin.comnull31248868null
nullnulldad1a47ac8eb8bdc2e5e5eefe368bf7fa18e76bblinkedin.comnull89368099null
nullnulld3aa657ed3e2fc6985cf4b74b5533ae69e80c91alinkedin.comnull6524168null
nullnull1ba5bc538ec5b0c3950cc3880801552e3a78924dlinkedin.comnull41830769null
nullgidelta@aol.comd017a4f0b5c119844cd5395ddd509fc7badoo.comnullnullnull
nullnull44144c442658e3af81b8f025bf4cbfc381e6f637linkedin.comnullvicksey1@yahoo.comnull
nullnull2bb009802a89e9100dfec6e88b48a264eb756bc1dropbox.comnullnaomidawson@hotmail.comnull
nullnihat_uenver@yahoo.de8c3981800b5c2e413c6cfa642bed29aebadoo.comnullnullnull
nullnull54e8aa92c22106c786f935847f405d48e57ba302dropbox.comnullkari.lehtonen@tdc.finull
nullnulld74460c334150eac2756fc2dbef194399a9e1cf1linkedin.comnull7012669null
nullnullf8d1c2f2f9c5909c5480a1040eb79f1b42e33cablinkedin.comnulljoelgeorge75@yahoo.comnull
nullnullnulllinkedin.comnull87346692xxx
nullnull9c1aebf154e0891aea2e419a6f79bbf8fb10f936linkedin.comnull169767642null
nullnull755e0de1bef99c081285ea37c0c45ef4db0d0b90linkedin.comnullyungchorming@yahoo.com.hknull
nullbuceogalerna@hotmail.comdf8b8c1e4928d80482ea2c119e929d46badoo.comnullnullnull
nullnull3777601fdba3fe60e662fe93ad715e9272ab7c4blinkedin.comnull101814955null
nulleprahim111@homail.combb2c730714c044ae6dfe8f6c389213b3badoo.comnullnullnull
nullnulla8dad00842cb831229bc2cbc27241a0f165c6c88linkedin.comnull45005737null
nullnull726c99923f812a139b86997760cae9c5559ef7d1dropbox.comnullmargot.honecker@web.denull
nullnull8e6fe7a2984343953e4ba1758e1df896bffabdbalinkedin.comnull137390504null
nullnullnulllinkedin.comnull155224972xxx
nullnullnulllinkedin.comnullpondoksari@aol.comxxx
nullnullfa4c82bdaac0e13823fb003cd3f665bfb664975elinkedin.comnull109210263null
nullnullebdd1cd5625ede4c3ad3820ca1a8a77733e9060edropbox.comnullkh220284@gmail.comnull
nullnull301b161075fdd193c187a755cf12513350f70606linkedin.comnull41219307null
nullnullnullCollectionsnullhtran2313@hotmail.comcheese
nullnullnullCollectionsnulllacosteandre@live.cachupacabra1960
nullnulld8f23456bf712d2e3a262469a5ef7f9cae25c8d6linkedin.comnull54372826null
nullnull960b8d46ed00a033d5d411e85620ee42f90eef9cdropbox.comnullhongshcui@gmail.comnull
24.131.23.127nullnull000webhost.comDisposewebsitefe@gmail.comsilverx1
nullnullnull7k7k.comnull271353725@qq.com1404261983
nullnullnullCollectionsnullbrandon@mailmetrash.comtungvit080685
nullsm_poyraz__27@hotmail.come20fce9307bf69791aa15c050fb6bc79badoo.comnullnullnull
nullnull$2a$08$y.79h39a34UPBr4zuecpY.BX/iyHxTMOzvGBIc0zz0OgousG9QHsudropbox.comnullbauger@trane.comnull
nullnullad5a8b35c332fbfa21aa47f381a9163809ac50b6linkedin.comnull88945694null
nullnullb552f2e9a46beb6e832edefedd34469a49c33d45linkedin.comnull125067645null
nullnullnulllinkedin.comnull63918691xxx
nullnullc20bb1d8421d0c9e19591af290e1f755631303a1linkedin.comnullcatherine.a.huzjak@ual.comnull
nullnull76460c7eb07f0912d894d24ff0ffeece05441942linkedin.comnull167814981null
nullnullb3dd48328f6e1096f4ceba28ea19775c5051c8fdlinkedin.comnullblueyessi777@yahoo.comnull
nullnullnullCollectionsnullvickinorthey@yahoo.co.ukgardner
nullnullnullCollectionsnullblagov_andrey@mail.ru730183115
nullnull$2a$08$SgaGWOdEeqMuxJrcnNWdXuBSg8xQMHtQhZKp.oWwMK/Pa92aLqEk6dropbox.comnullsusanamcborges@yahoo.comnull
nullnull9f369413c9e379f6b51e049bda5857829b0a9322linkedin.comnull84897368null
nullnull6c1e06292d8a2b5e6fac32aa753cd3dc55a74678linkedin.comnull27906168null
nullnull2927093952818e4814d5f07057a7689c460d4aedlinkedin.comnullondinagomez@hotmail.comnull
nullaziza19791@gmail.com1e13484c62f72472cc3739ef0c27ca36badoo.comnullnullnull
nulltim@otgerus.de9172ccc7a50efdba87b5f2414645e2c4badoo.comnullnullnull
nullnull6831e3d98edd21a5f7830410435a04161fdafcf6linkedin.comnull120263825null
nullbaxinhitinha@gmail.com60766f92eb69e5718534b5fe17dc0d42badoo.comnullnullnull
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.