Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nullbeatad@pino.plaa6c0c4f2a08f59b1156cf22b5d6af66badoo.comnullnullnull
nullnull909efa05db6c2bc0c07a84f5d517cfecb8853f5clinkedin.comnullJoshb60796@gmail.comnull
nullnullnulllinkedin.comnullasmparks@comcast.netxxx
nullnemwaks@yahoo.com73127d198dde8a23e9666b7d8b7c504ebadoo.comnullnullnull
201.235.80.170nullnull000webhost.commartin ayalaps2xtremo@gmail.comgonzalo2001
nullnullnullCollectionsnullkliodnamayfair@gmail.comqwe123
nullnull2ec58b9d7f27a24f1dbad4600e85dd1d27c8a4cblinkedin.comnullsaina_sidharthan1988@yahoo.comnull
nullnullf4ad9c78f15245a168d2eb80ee5cd9d5b6374aeclinkedin.comnulls.trifonova@triangleconsulting.runull
nullnullcd94c3c1d837a08f896bd8868a260ce28667cce0linkedin.comnull32452875null
nullnullnullCollectionsnullarena-2@mail.ru1234567
nullmouss128@hotmail.fr57d995b555bed40d55c5868aaaf9fa05badoo.comnullnullnull
nullnullnullCollectionsnullfriend.kyle@gmail.comquicksand1
nullnull85f15bc57d6c4e8a3a00b5f5c72a639f5f734f32linkedin.comnull9237514null
nullnullnullCollectionsnullglorimy@gmail.comfabinho7
nullnullnulllinkedin.comnullr.mahmoud@itc.net.saxxx
nullnull697f7926a70f060eb88e873e034270cd7d59e7a4dropbox.comnulljfgignac@protected.canull
nullnullnulllinkedin.comnull141300362xxx
nullnull095d5043a0e03bf482a4378fde041838b3ba9952linkedin.comnull96808359null
nullmamacretas@gmail.comfcc485fb15bced91f107f8aef81d4d17badoo.comnullnullnull
nullshimiken@abox2.so-net.ne.jpf04d94de927cfd954eee265117f6e89dbadoo.comnullnullnull
nullnull816dfb1743e4b9af055388fa697ba3e741ec0000dropbox.comnullrdeneys@imaginer.chnull
nullnull$2a$08$Ko/eqNqdavicidmDsaNGXeTVnpYf/BEcXAVCBYPrcEirHPo9zq.Yidropbox.comnulls-7010@softbank.ne.jpnull
nullnullnullCollectionsnullpenzadoom@yandex.ru697865
nullnull3e3c94ffc031a6dc11e6e591482109f20e040ec6linkedin.comnullsunil_semta@yahoo.innull
nullnullnullCollectionsnullout.cast@hotmail.comthelife101
nullnullnulllinkedin.comnullnokiasx@yahoo.co.ukxxx
nullnull6db71117f221eeebd21fc1268444becadd856842dropbox.comnulltopoema@gmail.comnull
nullnull$2a$08$FBnX/KeogadOfINkUQOLBOzU.nlD4921ZXKE1oHG.tDIRmu2IV4Qadropbox.comnulltrongduc14@gmail.comnull
nullreginald.khumalo@integrat.co.zab7482022c75cb991b46f619f4943fa4bbadoo.comnullnullnull
nullnullnullCollectionsnullalan8@hotmail.comjahqja
nullnull8e197bd65a617bc6fdb66d9f65642b579ab32350linkedin.comnullcarlo.desio@gmail.comnull
nullnull5830af933272b01a306e1844f3d15c9fd1d26a46linkedin.comnull153317336null
nullnull39693fd4a45b386c28c63100cc930238259891a2linkedin.comnullchenlixue2008@hotmail.comnull
nullnullnullCollectionsnulllitvinovakristina2014@yandex.ruehiset13
nullnullnullCollectionsnullea.net2011@yandex.ru79548621
nullnull$2a$08$c8Sc6Zid0RLyldMjbyFhfe/9J30PWk.dWr3uLmLGxdRoHlJfMhBu6dropbox.comnullhugegrant@me.hunull
nullnull840f392563451838e0a74d4065b7693bb97bacb5linkedin.comnull27416866null
nullnullnullCollectionsnulldoxerass@mail.ruexenik341256
nullnullc33f059b0ca7725fbfd6c9ea4f2f012cc7ac5a74linkedin.comnullmanishparikh242@yahoo.co.innull
nullnullnulllinkedin.comnulljoelkwilson@yahoo.comxxx
nulldruman_8@hotmail.comb71a46cb237312e03be9bfcb8aae0a91badoo.comnullnullnull
125.161.200.175nullnull000webhost.comMas Pry Supriyatnomaspri.tazq@gmail.commaspry123
190.100.39.163nullnull000webhost.comLucianolucianex100@hotmail.comqwert6yu
nullnullnullCollectionsnullfahadsadah@gmail.comflashing39
nullmagassoubanamori@yahoo.frb9f0e367103eb074df6826dbab21405ebadoo.comnullnullnull
nulltetracops@msn.com3b51a4cfdc7c77ac69bacb734e9c2359badoo.comnullnullnull
nullnull$2a$08$c0NfFXlXNaXl4y/zYpoPR.eeQBqy8p356kAbsuwSpdWr1PDYHaKdmdropbox.comnullafe@bk.runull
nullnull$2a$08$LeaK0jBaDWCk6OPT2jHF4uCnWFOKvW.XLbDGaxB/uQ0goxsb1RtRWdropbox.comnulljohn.boet@gmail.comnull
nullnullnullCollectionsnullesteban.eusebio@hotmail.comtereza
nullnull8aaf2eee3fdfab1312e5c1501639e6aa4f4423c9linkedin.comnull136889896null
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.