Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nullcycloman53@live.fr9d3ee0b458e1ade5469a5d5361a1dd9bbadoo.comnullnullnull
nullnull164531eeebb954691383e4a30d0294363e1882f0dropbox.comnullvon-forster@gmx.denull
nullnullnull7k7k.comnullhuasong19870326
nullolivier.moulard@wanadoo.fr63b4349d7573620b51ca4b2a5e68758abadoo.comnullnullnull
nullnull9784d6e5d0521878907a587a55ab0596204cb518dropbox.comnullmanju.meti@gmail.comnull
nullnullnulllinkedin.comnull42183972xxx
nullnullnulllinkedin.comnull26064830xxx
nulldaisy1928@hotmail.co.ukfe05af1aa776d49ec80d02746a1a0baabadoo.comnullnullnull
nulljuanluserquera48@gmail.com9545506429705f30336d6f0f57b9d008badoo.comnullnullnull
nullnullnulllinkedin.comnull125525610xxx
nullnullfed765d5f0d0029125d0a0da6c91e77fdeacfef4linkedin.comnull28074864null
nullformaro_luigi@libero.itb89dc80fb627dbdcfe7d8e03876985d8badoo.comnullnullnull
nullnull8fe5e1b55047b40842aee8e9f6a37088270bde5flinkedin.comnulltom.duncan@gmail.comnull
nullnullnullCollectionsnullISKANDAR.5@MAIL.RUI19935999R
nullnull26f975832ed720491c37e3f337d089fecb7873c6dropbox.comnullronny.lenzer@blaklader.comnull
nullnull1f5523a8f535289b3401b29958d01b2966ed61d2linkedin.comnulljohnkingslyn@gmail.comnull
nulldeli_manyak_cocuk_33@hotmail.come10adc3949ba59abbe56e057f20f883ebadoo.comnullnullnull
41.232.189.246nullnull000webhost.commohamed hemmoh.hem11@googlemai.commoh2641986
nullnullnullCollectionsnulldeniseprc93@gmail.com167989
nulledwin.urrea@hotmail.comd2b72ba2145bc2c21e7037b8e7027006badoo.comnullnullnull
nullnull$2a$08$afeLp6InDZh1zzdmqlHUpOl8YaHTgvcNVg4sYSS0WjLNdiYpDpRP.dropbox.comnullbrodriguez@dirnea.orgnull
nullnull$2a$08$G/12q1DeUO6V0R0.L8a/tOYEyq4kMUvJxua7PLWIDG8Y/1iN8xXKqdropbox.comnulljulyate@openmrt.co.zanull
nullnullnulllinkedin.comnulllakshmisherlymanohar@gmail.comxxx
nullabdelladjal@yahoo.fr367ad5b36700281066eee6aa2a18d9e9badoo.comnullnullnull
nullnullnull7k7k.comnullgongtengyian@qq.comgongteng
nullcw@peepoople.com20785f836407ca2e71d304f2351f2698badoo.comnullnullnull
nullscherensatz@msn.com5f78c80d79bbe9b9b2f0035d98cf19eabadoo.comnullnullnull
nullsanja.colic72@gmail.com44316e64136882ea7e210ac281005dfebadoo.comnullnullnull
nullnullnulllinkedin.comnull145758050xxx
nullnull57e20e7f2246a5161443851f62e4253fd8d7b7f9linkedin.comnull79448009null
nullnullnull7k7k.comnullgongqiquangong5201314guo
nullnullb2f860b5bd577417f2cfe06137b30e11ccc7c198linkedin.comnull59599063null
nullnullaef464f56ccac1833652f61d884823239fe501a7dropbox.comnulladdiemayrn@yahoo.comnull
nullnull422b0975360ee6ced4699d4803410031813f47d7linkedin.comnull68018754null
nullnullnullCollectionsnullflatblocker17747@yahoo.comflatblocker
nullnull36ac6d6926b95f46942890ecdd4bac362ed2380flinkedin.comnull19783748null
nullnullnullCollectionsnullthomas.conrads@hotmail.beazerty1994
nullnullb9512e58dcc6d376fa14870c20a3dc18d97eafe5linkedin.comnull107483484null
nullnull2f21272a6493effbd9cad3cb0aa5b1e433b7e023linkedin.comnull16849987null
nullnullnulllinkedin.comnullpaguirre73@hotmail.comxxx
nullnulle2872afb1a67eb40e54e2ae101d2003b8da143d3linkedin.comnullh15828635676@163.comnull
nullnullnull7k7k.comnulldongjieyeye19840725
109.156.28.227nullnull000webhost.comRichardhail_kingface@hotmail.com1ntercircuit05
nullnull001c8cef8e4bdca618f3b5522712ed952c30d44ddropbox.comnullpschapero@tsgins.comnull
nullnullnulllinkedin.comnull147262210xxx
nulldjjandro@hotmail.com82363325dca174117cbdef6500003706badoo.comnullnullnull
nullnull6dcf6121f186a82f4bc5336878ba182771e82b7bdropbox.comnulllinda@lindalongmeyer.comnull
nullnull052af667d95d19fc4d0c83b1ab679492751fc819linkedin.comnullsilver.turyahikayo@eadairyuganda.orgnull
nulldamian_lichwa@o2.plc19523a8142339d13d908c2ab1371d9cbadoo.comnullnullnull
nullnullf7c3bc1d808e04732adf679965ccc34ca7ae3441linkedin.comnullmejd555@yahoo.comnull
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.