Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nullnull55bb4ca105b7ffefe9e7e124339039999022fe00linkedin.comnull46101969null
nullnullnulllinkedin.comnull47813348 2136de5d098ae816101583dd8baabbfbaa1a32f7 -> burroughs_thomas@yahoo.co.uk
nullnullnullCollectionsnullcatia@mail.ru07789236
nullnullnullCollectionsnulld056601917@126.comzxy226500
nullnull03dae2db28dd0d6c56a48e2f4fd8a5884e0aff89linkedin.comnull56952527null
nullbarisik.mustafa@hotmail.com5e9c893fa0b1975027adfe45054850f0badoo.comnullnullnull
nullnullb6e6b0a24be4cb673db2c64407a158b577c0c3edlinkedin.comnulltucha_bcl@hotmail.comnull
nullnull3fb98fd3457923f58e615c90ec8bd23df9ac7be4dropbox.comnullmeysing@oszhandel.denull
nullnullf1a37fbd227bbeedc8739c80e7433ad0ad387a66linkedin.comnull5583479null
nullnullc0b1e339759baa19b71b502268e53becb35ea5a0linkedin.comnull2193836null
nullwubaz_00@hotmail.com259da33b61249e0e6171a957f54ced1dbadoo.comnullnullnull
nullnulle09f075ab653beb99b7742974ec2264761528ef7dropbox.comnulltriana.wjayanti@gmail.comnull
nullnull01addcc7c7486f65007b4062e6a6619b8648204fdropbox.comnullbdreed.85@gmail.comnull
nullnull267c33224b3e0299371797f8c9c63ae8b81ccbdcdropbox.comnullraphael.darius@t-online.denull
nullnull$2a$08$xAoTbDQlrg4sEQz8w1JIj.F83O8Bvd2hQJ9aabmAz5w963fIszLpedropbox.comnulljofupa@hotmail.comnull
nullnullnulllinkedin.comnull17115302xxx
nullnullnullCollectionsnullcoe1424141@testwww.commandersofevony.com2366d3e5
nullnullnulllinkedin.comnull166685740xxx
nullnullnulllinkedin.comnull159095370xxx
nullnull3df22e040d10ac703e5ebc121f7c995b8e9b8f8bdropbox.comnullblake@math.wustl.edunull
nulllebron92@hotmail.de57e3f789e710a65daadb43c9f8f03e2fbadoo.comnullnullnull
nullnullnulllinkedin.comnull55635492xxx
nullnulla5cdf3ade504838d52782bec021c14b6da7c386blinkedin.comnulllhough@cogeco.canull
nullnullnullCollectionsnulltriple_xxx2004@yahoo.com12345
nullbahauddin_ghauri@yahoo.com089007ad61f75f50037be857e964ec7ebadoo.comnullnullnull
nullnullnulllinkedin.comnull152691401xxx
nullnull19447cde52baf82816b278e12ff4b8a9c62590bclinkedin.comnull99019593null
nullnullnullCollectionsnulljewels.meyer2003@gmail.comlovem
nullnulle32ec3bd57a06cd22240c7d891aaaa211f1680a0linkedin.comnull50649788null
nullnullnulllinkedin.comnullliam@allnations.org.ukxxx
nulllaikuccia61@yahoo.it33be7c7984080b5c9e76bd2d4e103b60badoo.comnullnullnull
nullnull7c4a8d09ca3762af61e59520943dc26494f8941blinkedin.comnull120115375null
nullajitopati@yahoo.es0e8f0555599253cb910cdfaa5d248049badoo.comnullnullnull
nullkurikos@wp.pl6dee5b57fbfdf6f561740cd9b3d35089badoo.comnullnullnull
nullnulldf2e495b80a0680464a12449efe2239ee9d432d8dropbox.comnullsimipperoi@hotmail.co.jpnull
nullnull5e5d409dba6592bcccc6630ae23dbf19aaa2124ddropbox.comnullwalter.speranzini@gmail.comnull
nullnullnulllinkedin.comnull118369271xxx
nullhofmanntanya@ymail.com9124de6638b01bb48ed06b0f7c4ac448badoo.comnullnullnull
nullnullnulllinkedin.comnull43737350xxx
nullnulla2672857221c8e244d1fb1b7b989b9ae9b01a355linkedin.comnulljennifer_t3@hotmail.comnull
195.22.104.29nullnull000webhost.comVadim20lx7l09@gmail.comQpwoeiruty666
nullm.yurduseven@hotmail.com643dd63894784a795b320e9552079255badoo.comnullnullnull
nullnull8ccc2723c4724b6b47ba5f3ddca90ac20a0119falinkedin.comnull143266785null
nullddffffgh@gghhhj.comb92f838f071a6d707e93820b7a258e56badoo.comnullnullnull
nullnullnulllinkedin.comnull18693632xxx
nullnull$2a$08$XU/xZqw66nKDtx44zWSfD.xW6OAGcDMBhqwsVL1te/a9kolpUu4Gudropbox.comnullanamarifanti@gmail.comnull
nullhkn_gz_84@hotmail.com75e8fc888eafc3b5659d3e4591446913badoo.comnullnullnull
nullnullnulllinkedin.comnull5442421xxx
nulltrmalkamil@seznam.cz271db5fdbc9afc992278a49efbbb0139badoo.comnullnullnull
nullnullnulllinkedin.comnullmartina.marzahn@liquidcampaign.comxxx
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.