Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

userpasshashdomainemailpassword
nullnulllinkedin.com31935070xxx
fouzibourisia@hotmail.com69c7b4fefacd0125cb94828e3de94e98badoo.comnullnull
nullccde44ac2ff6edb353c58533266570054d932056linkedin.comshinychristlina@gmail.comnull
nullca67848f1260a09c1c8861cd8adc5917d133f0ablinkedin.com49647609null
nullb57fde0f33cbfcaaae26961cb51fcfb44221db0alinkedin.comregis_martin@hotmail.co.uknull
nullnulllinkedin.com89570032xxx
null9e09e4fe505ad0498ce216ab68db864291ca6caelinkedin.com6420323null
null5655bb3e0db00183dc06a8befdd4b5a40d3abe43linkedin.com92668769null
nullnullCollectionspyzd200lovemn
melasballo@hotmail.itbbac7c725eb741ec17179c660cd466a6badoo.comnullnull
nullnulllinkedin.com13548371xxx
null$2a$08$r9pv8XgMo/z4rRd9EJI4duu4D.NymCiVhWIvNJZcUn9zx1mqeR6JKdropbox.comclairehlee516@gmail.comnull
ciza11@hotmail.com17244bfeac450322ab75643b9cf1f885badoo.comnullnull
nullnulllinkedin.com46478062xxx
nullcfbcc814f03543ef38fe70a456e1f83e3bb61cf5linkedin.com89263378null
nullnullCollectionskirysha.z1@yandex.ru12345678
null01a98b648eb7c5c54e55d115be13a709ae687685dropbox.comhotbar744@hotmail.comnull
nullnulllinkedin.com56260120xxx
nullnullCollectionselisavicari@live.comhello
nullf5c99097b666716900b76c127d80e127dfb51bd2linkedin.com143497617null
null5b3e9e7e0c12730fd4f1ad26997ca45b1a5faa39linkedin.com23804954null
null81c01b657c8c724e8a0d85332e3e9f1ebb576efddropbox.comphyllis.kho@gmail.comnull
nullnulllinkedin.com64841510xxx
null6adbd62d70f3d35978c750508d968b156bf69c22linkedin.com77617047null
ivo.toth@centrum.skb493c7efce36434eeaf38fde716c1b1abadoo.comnullnull
nullbbb81601b60f033d6c11d9f9abe9247bd52cc2e0linkedin.com76311876null
null00894312149ac160922e1ecb82fde2a05544002ddropbox.comshimadakazu3@gmail.comnull
null1394567981ed4839551ab232beae32e8548f0e19linkedin.comccantioquia@ptcc.com.phnull
nullnullCollectionskarma0404@yahoo.comxenozane04
nullnulllinkedin.com162526970xxx
null02c4443edf0a5cf488f07d95457142d89a1a8e8adropbox.comsgt_rf@coral.broba.ccnull
null039ce057239426724c5017ee2fc291b47fb3a432dropbox.comblack_fang4445@hotmail.comnull
nullnulllinkedin.com85566572xxx
nullc6fe84641ad84f74b66b489a3feb46f1e2226b01linkedin.comdblanks322@gmail.comnull
nullnulllinkedin.com153750080xxx
nullnullCollectionsabo0odi77@hotmail.com123456123
null$2a$08$uDiblCp414lfbk.YDBon1.VP2uWxVFphIRFck9IjXQzMWGmfZVEaGdropbox.comjaygibson@gmail.comnull
nullnullCollectionskevin.mano2013@hotmail.commano2010
nullnullCollectionstimofeev.sined@mail.ruytpfdbcbvjcnm
nullnullCollectionscoralliter@gmail.compercent1
null3db9aef00f872828ca4000345699b3d02ed2205blinkedin.com119646957null
nullnullCollectionsandersonlucas3d@gmail.com300389ALcr
nulld27f4469be6eadfde078a1e371c9d67d3f7512c7linkedin.comswetea1@yahoo.comnull
nullnullCollectionswangmeng9528@sina.com5gurkrzc
nullnullCollectionskasen@emaildienst.de1922219222
nullnullCollectionswwwdotcom5010@gmail.comtitman1
nulld6a41f4679cd17992436ff3d5156b44d3f90a46clinkedin.com49685575null
nullnullCollectionsgrey_ness@hotmail.co.uklozzeh
nullnullCollections842221425@qq.com137727213184
null$2a$08$ug8gYsEG3hSRq5RIZO3qyOMgdRP0ue0h8HcCCgOOJuRMwmStFSvRydropbox.comrobbio80@alice.itnull
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.