Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nullnullnullCollectionsnullscorzaz@yahoo.comzack90
nullnull97e667fe46e3e3a81a7cbc98398bd83c926cc1ealinkedin.comnull129730679null
nullnullnullCollectionsnulldjflyest@gmail.com123456
nullnull9f58525dba78e2487dbf8ea85ddbee7433c40f6blinkedin.comnulljsjdemedio@yahoo.com.brnull
nullnullnulllinkedin.comnullnabeel203@yahoo.comxxx
nullnullnullCollectionsnullregs3@gmail.comregs33
nullnullabc136ca66f27e6d1b1d5001234304af92981f6flinkedin.comnullemilien.rasset@hotmail.frnull
nullnull$2a$08$01i8C6yBQVc3U3YirBbxvOmaG92FQMqVWW7Pv7gh5.Mmgksngvf..dropbox.comnulljassin@live.senull
nullnullnulllinkedin.comnullgoitao@oxfam.qc.caxxx
nullnullf4a5693eebd6c536bbc47d140030fd4be655360elinkedin.comnulllcruz@allstates-worldcargo.comnull
nullnullb933192b5780dbd097537e7188a6d8a640dfaee4linkedin.comnull131280617null
nullre_voluscion@hotmail.it61e13dc58238d1be9ddc3dc69e2bdc51badoo.comnullnullnull
nullnullnullCollectionsnull121273180@qq.com911205
nullnull99649c9fa746f4a0f6287b3766acaa5d903871delinkedin.comnull76820613null
nullnull1dc344e770ec4c1fea664eede918f3f9355cf97flinkedin.comnull132311804null
nullnullnull7k7k.comnullwujianfei@tianya.cn19880213
67.142.130.42nullnull000webhost.comvaginaarygirl_77@hotmail.comSoccer!
nullnulla56da592171fea49da64ab61f6627630ebd6f837linkedin.comnull44845589null
nullnull87baa845417c2dff56112e0f1d7f36c981489333dropbox.comnulld.m.macdonald@brighton.ac.uknull
nullnullnull7k7k.comnullrenia99_ruc2006101266
nullnullnulllinkedin.comnullboycottmtv@gmail.comxxx
nullnull7b13d4933e2c1cbe1236cccb8e055e55592b317alinkedin.comnull84409119null
nullyari_balki@hotmail.com03261c7cb73e0074b9a162ba14915208badoo.comnullnullnull
nullnullnull7k7k.comnullbuildmoonlhblhblhb
nullnullnullCollectionsnullsergikmmm@gmail.comtuzobyna
nullnull87fef3d27fcda986fbc244fd66174d4245fc8c2fdropbox.comnullisabelle.gerardin@gmail.comnull
nullnull479b9f22ca9506598d33b72b34ec4d000820a627linkedin.comnull116437154null
nullnullef52a3b54ebe8cc499738e7152e46cd48287f424linkedin.comnull152242186null
nullnulla4d01e9fed0d5a74b601e12363b36f6fc407318clinkedin.comnull132927084null
nullnullnulllinkedin.comnull20151190xxx
nulljerem4113@hotmail.fr6967cabefd763ac1a1a88e11159957dbbadoo.comnullnullnull
nullmarcusnkris@hotmail.com06e208a76aaec81ce483446f33d990c9badoo.comnullnullnull
nullnullnulllinkedin.comnull81253371xxx
nullnullnullCollectionsnullehsan22bcu4
nullnullnulllinkedin.comnull156566782xxx
nullnullnullCollectionsnulledi96@hotmail.com8kichuez3u
nullnull6ca266d5bb3d8b03ffb63fe94ea2e4e8f3437fcflinkedin.comnull59851995null
nullnullnullCollectionsnullpay4justin@gmail.comwjs9200
nullbuqui010@yahoo.it36569e36a447c1756cab8c447514ded8badoo.comnullnullnull
nullnulla9546d8a944778361cdb4b563c27646d7f3261dblinkedin.comnullebnfjn@cox.netnull
nullnullcedf41fccb586dc39e1ce34bb482f0afe557b49flinkedin.comnull18301859null
nullmarcodeleo87@libero.it06efae9f5429e6aaa3f9a1a71febb39cbadoo.comnullnullnull
nullnullnullCollectionsnulls1075@hnu.krre7743
nullnullnulllinkedin.comnullgrosberg@freenet.dexxx
nullnullnullCollectionsnulladul2@list.ru1332719145
nullnull9f17fc14a86137c9feb612d7e7e11d3a6c6ec8efdropbox.comnulljarcbdjunior@hotmail.comnull
nullnullnullCollectionsnullolaewewassi@gmail.comforest002
nullnullnullCollectionsnullitza_gallagher87@hotmail.comaztiza
nullnullnullCollectionsnullkassi3xx@ymail.comkassi3xx
nullnulld619cd83639124fef568c56d2e138b160f599dablinkedin.comnullcarstwall@yahoo.comnull
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.