Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nullsm_poyraz__27@hotmail.come20fce9307bf69791aa15c050fb6bc79badoo.comnullnullnull
nullnull$2a$08$y.79h39a34UPBr4zuecpY.BX/iyHxTMOzvGBIc0zz0OgousG9QHsudropbox.comnullbauger@trane.comnull
nullnullad5a8b35c332fbfa21aa47f381a9163809ac50b6linkedin.comnull88945694null
nullnullb552f2e9a46beb6e832edefedd34469a49c33d45linkedin.comnull125067645null
nullnullnulllinkedin.comnull63918691xxx
nullnullc20bb1d8421d0c9e19591af290e1f755631303a1linkedin.comnullcatherine.a.huzjak@ual.comnull
nullnull76460c7eb07f0912d894d24ff0ffeece05441942linkedin.comnull167814981null
nullnullb3dd48328f6e1096f4ceba28ea19775c5051c8fdlinkedin.comnullblueyessi777@yahoo.comnull
nullnullnullCollectionsnullvickinorthey@yahoo.co.ukgardner
nullnullnullCollectionsnullblagov_andrey@mail.ru730183115
nullnull$2a$08$SgaGWOdEeqMuxJrcnNWdXuBSg8xQMHtQhZKp.oWwMK/Pa92aLqEk6dropbox.comnullsusanamcborges@yahoo.comnull
nullnull9f369413c9e379f6b51e049bda5857829b0a9322linkedin.comnull84897368null
nullnull6c1e06292d8a2b5e6fac32aa753cd3dc55a74678linkedin.comnull27906168null
nullnull2927093952818e4814d5f07057a7689c460d4aedlinkedin.comnullondinagomez@hotmail.comnull
nullaziza19791@gmail.com1e13484c62f72472cc3739ef0c27ca36badoo.comnullnullnull
nulltim@otgerus.de9172ccc7a50efdba87b5f2414645e2c4badoo.comnullnullnull
nullnull6831e3d98edd21a5f7830410435a04161fdafcf6linkedin.comnull120263825null
nullbaxinhitinha@gmail.com60766f92eb69e5718534b5fe17dc0d42badoo.comnullnullnull
nullnullnulllinkedin.comnull46253392 xxx -> livvylouise@hotmail.com
nullnullnullCollectionsnullbl1@live.capoopy711
nullnulldebd635f3551d4f318363cb7cbd59dbbd8f0ff6edropbox.comnulldroesmann@gmail.comnull
nullnullnulllinkedin.comnull52700990xxx
nullnullnull7k7k.comnullyyq404307663198829
nulldadashe@yahoo.com62a4a8e0abadcf55b7b56624e9efbbeabadoo.comnullnullnull
nullnull8481165979c7246dba7b0bfdaa5530f8aa0510e7linkedin.comnull127376529null
nullnullnulllinkedin.comnullDavid-XJL@hotmail.comxxx
nullshuymaro@hotmail.com25e1e717a6d416f3c4dee6810bf3b04bbadoo.comnullnullnull
nullyenisian@hotmail.comf0e7dd35df88a1e6cfdf6c49d5d418d9badoo.comnullnullnull
nullnull$2a$08$QyvHitm20/85vIc0WB6eteku5IXqZNxP.w7SLDzC1KewtcDGmooe6dropbox.comnullnonboel@live.dknull
nullnullnullCollectionsnullpiciosa_animex@hotmail.comanimex12
171.255.9.32nullnull000webhost.comtranthanhthetranthanhthe87@ymail.comtheca1997
nullnull57d2f82754719e4d3edad0e4df3fdbad28cc29d3linkedin.comnulljane.cooke6@btopenworld.comnull
nullnull2b2b2528a6b61fa82b38417dbcc88f0750bf0b9elinkedin.comnull31490994null
nullnull3367405812963054bcf8434cf49f2fcc7e85dc3clinkedin.comnull13743585null
nullnullcad4690ee70d37acae6308d35182da3b7c822c36dropbox.comnullsimone@clavecom.com.brnull
nullnull2586215ba8dc06516b24993799d517c5c8b35dbdlinkedin.comnull5522004null
nullnullnullCollectionsnullmr_groovies@yahoo.com220202
nullnull$2a$08$c656tcbe8OrUFPNtg8DPmOP5zpkJTSChfz.KGq4.xVaQ5XOCtmATWdropbox.comnulladrianfranziskus.schindler@gmail.comnull
nullnull47eb00c8191f4842d68cef0bc8bbcec511d211e7linkedin.comnull116943617null
nullnulldd5f2de985ae4cef2623aa2f582fb69173693435dropbox.comnulltastingroom10@gmail.comnull
nullnull1d7325aa7ebcd4d6089fc8267b18bcce98eb2c19linkedin.comnull88284277null
nullnullnullCollectionsnullhoney.y10@mail.ru1998nike
nullnull1d9baea96efc7472dbdb811eabe09849c604e0d4dropbox.comnullsalin.dileep@gmail.comnull
nullnullnullCollectionsnull18767126567@139.com12345
nullnullnullCollectionsnullLZX5411@126.netts4227371
nullnullnullCollectionsnulllyudmila.gontaruk@mail.rupiRF0tso
nullnullffa4f17d64ac78b83197fa9f41db8a37745d1a06linkedin.comnull155107714null
nullnullnulllinkedin.comnullkevin@kevinz.comxxx
nullnullnullCollectionsnulljaja11@hotmail.co.uksandiago10
nullselcuk-gulnur@live.comdb3a512ee8280d5a8de67bb007b779b9badoo.comnullnullnull
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.