Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nullnullnulllinkedin.comnull53335281xxx
88.169.20.246nullnull000webhost.comAntoine WODEYantoinewod@hotmail.com1ba23YgD
nullnullc673de3e556e1997eb1a21e1e8ce89c341f592e0linkedin.comnullSandeep.Gopalan@asu.edunull
nullnull5c001360e58d54f17477688bc9d87a7033f2bfa5linkedin.comnull24152598null
nullnullnulllinkedin.comnull57430441xxx
nullsav.9@hotmail.ita2750d694307232f86da12a0685a9676badoo.comnullnullnull
nullnullnullCollectionsnulljackalba@neuf.frzexybive
nullnullnullCollectionsnullGrozco28@yahoo.com60874
nullnullnullCollectionsnullxstarz-@hotmail.co.ukjustdoit
nullnulla7382604f3c3fbb48e349bc56093c43a13344c93dropbox.comnulldominique.verlegh@peer.benull
nullnullnullCollectionsnull805369325@qq.con123456
nullnullnulllinkedin.comnulljabb55@verizon.netxxx
nulldelikanlim_251@hotmail.com4adbd696700e8ece23ff78182203a310badoo.comnullnullnull
nulljmr09@live.fr69f883a4dcd8b69bff8639c5e12c73f2badoo.comnullnullnull
nulldailanmagic@hotmail.comeabae631e6393b98f5ad1f11beba5335badoo.comnullnullnull
nullnull03e6939b37d9b07074d17a8a44cf30e1d02723felinkedin.comnull166988378null
nullnullnull7k7k.comnullzxmzcc@QQ.com18344703zx
nullosti7@wp.plc124458baef552f590da136c57e24407badoo.comnullnullnull
nullnullb160bc40f1f274d49ef7a3253114632f350e9cb3dropbox.comnullemi@livingsocial.comnull
nullnullnulllinkedin.comnull91781640xxx
nullnullnullCollectionsnullcoe1053495@testwww.commandersofevony.com43307168
nullnull63dacbb2e37e7567faf1dbde273011fff5573e8blinkedin.comnullneverendingflight@yahoo.co.jpnull
nullnullnulllinkedin.comnull149781752xxx
nullnull$2a$08$eBVtZfotii8J3oN/52zcmuExlv3qfxJp3G4OWvtj.AMJMA4OhzFOSdropbox.comnullgeorgie87.gf@gmail.comnull
125.163.230.200nullnull000webhost.comrintis dinarrintis_3e3@yahoo.comb141548*
nullnulla6c861f74df12ced51a38f93c2559fdcb20ea7ealinkedin.comnullmint_love_404@hotmail.comnull
nullnullnulllinkedin.comnull134460951xxx
nullnullaf41202ca92ee26a7c5aab7c515cbde63b85e14elinkedin.comnull133415548null
nullnull219950297ee3d83f2648d532694dbad7752c87dblinkedin.comnullnelson_ehizojie@heineken.nlnull
nullnullnullCollectionsnullelrayman555@gmail.commatrixjuan999
nullnullnulllinkedin.comnull69242901xxx
nullnullnullCollectionsnulldionesuc@hotmail.com250430
nullnullnullCollectionsnullisabelmr83@hotmail.comraqequhi
nullnullnulllinkedin.comnull155986482xxx
nulllittle_sexy_lolita@hotmail.com13e72c514b3b0160fde8b9b3ca2c35ddbadoo.comnullnullnull
nullnulleb2f66339480c560904bdc1a8770216ee0907157linkedin.comnull125266554null
nullnullnulllinkedin.comnullarunsharma_29@yahoo.comxxx
nullnull$2a$08$gb9sO/OS56uUjE4AHdP3JOQmtbVfxY5CXZzQWUebOrAb8S5nEgoF.dropbox.comnullduraid007@yahoo.comnull
nullnullnulllinkedin.comnullkarin.vivian@hotmail.comxxx
nullnullnullCollectionsnullhalla_devil@hotmail.comlaithoo
nullnull365339da4d04449f8050750d1dc312fbed8d1207linkedin.comnull101256449null
nullnull649cb7d439325b647e84e94063385e0ad147be7alinkedin.comnull115249768null
nullnullnullCollectionsnulljunpink@163.com4327828
nullnulle3d6832c8336157731c0db376629fef79cda57b0linkedin.comnull42170939null
nullnullnullCollectionsnulltempbox33@gmail.coma123456
nullnull1e5ef04daaf94ec4a758459f7948e872fb3d92a5linkedin.comnull25064533null
nullnullnulllinkedin.comnullpusch_michaela@hotmail.comxxx
113.64.227.205nullnull000webhost.comchangchangy@ta.cnchang123
nullnull12c06c8b12588c9d1ade0b6162393e29a5cce5celinkedin.comnull49627368null
79.107.70.135nullnull000webhost.comjossoojossakos@in.gromg 3lol
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.