Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nullnullnulllinkedin.comnull5083351xxx
nullnullc9994659af6513f081ad29cd011f912b94c8209ddropbox.comnullkpicker13@hotmail.comnull
nullnull2cf49d7802fade80335488d44bf95d07943248eflinkedin.comnullkip@tinyfootprintdistribution.comnull
nullnull757f429de5659f0fa181c50474b1290e95b994f1linkedin.comnull15297396null
nullnullnullCollectionsnulltemplarios68@hotmail.comfredy68
nullnullnullCollectionsnulllfauci@att.netsally2
nullnullnullCollectionsnullr3actii0nz@live.canzrm9012765
nullnull075968d5d2f92f890e27c496964eb68247eb0b1flinkedin.comnull22770474null
nullnull046919100e32b3700e93e3bbae22d85fac352031linkedin.comnull6871997null
nullnull2e72fef764c11c4467a52a091b044b52dc5632delinkedin.comnull42115745null
nullnull54e48e9affb8695a5d64a71f21554823406a6a29dropbox.comnullmalagaojoao@gmail.comnull
nullnullnulllinkedin.comnull106344981xxx
nullheasham@hotmail.comfcea920f7412b5da7be0cf42b8c93759badoo.comnullnullnull
nullnullnulllinkedin.comnull157789752xxx
nullnullnulllinkedin.comnullprad.rk@gmail.comxxx
nullnull67a1808004542f9639646f3ed0f06326335da2f0linkedin.comnull84723057null
nullnullnullCollectionsnullmikal_kragor@yahoo.commikeys
nullnullnulllinkedin.comnulllmcabrera3@yahoo.com.mxxxx
nullnullnullCollectionsnullgreenp1c@mail.rulbvf1999
nulljakob.dahl@hotmail.se439be33aae6c38e5420d105214613826badoo.comnullnullnull
nullnullnulllinkedin.comnull48793680xxx
nullnullnulllinkedin.comnull166112742xxx
119.93.59.203nullnull000webhost.comSJDEFI HOSPITALsjdefi_hospital@hotmail.comstjohnofg0d
nullnullnullCollectionsnulladmin22@o2.plderbyon111
nullnull9554deced2dd84945f3e9d868f46aa94dd192feblinkedin.comnullerod0180@yahoo.comnull
nullnull$2a$08$yOSl2eD8m8c1NQFx1Dzz/.lzdCt/qbi2mOghssIa8CADCIdn9rpRudropbox.comnullsmithjack57@gmail.comnull
nullnullb4f30295f9e0fa5d3e935783cebafb162dc26fd8linkedin.comnullcorsetto@terra.com.brnull
nullnullnullCollectionsnullold.samurai@yahoo.comGheorghe8815
nullnull12ac7c3b9ddcf678e07799675138f4667271eeb8linkedin.comnull155178528null
nullnull43405497e747d8bac3f7a8a80c596fed30c5ea1edropbox.comnullivegac@credomatic.comnull
nullnullnullCollectionsnullbiancafare@YAHOO.COMANASTASYA
117.221.129.20nullnull000webhost.comJagangsjagannath@gmail.comjanani@1997
nullnullnulllinkedin.comnull140084230xxx
nullnullf381a21021d4532ade50095977a57d4ec47b32d5linkedin.comnull155833328null
nullnullc28cadd17a4ca11b494c5c62f6bee0155f401663linkedin.comnull30544254null
nullnullnulllinkedin.comnull160758820xxx
nullnullnullCollectionsnullgrande.pc@outlook.com1235789
nullnullnullCollectionsnullcarterhawk@ymail.comsadie99
nullnull485fcef31cf6102d16abafa905834e88135bc421dropbox.comnulljessica.martin@bmc.orgnull
nullnulle11ad7116a9caf220f35f6dc15ff8156aad6d441linkedin.comnull11165396null
nullnullnullCollectionsnulltausifsiraz4@gmail.com103brook
nullnull26d796fbda598513db2cdaf60208fcc80120cffadropbox.comnullmabry.greg@gmail.comnull
nullnullnulllinkedin.comnulllizzybee72678@yahoo.comxxx
nullsuiten2@hotmail.it2d1aa197addd682a24201c45f62c60b5badoo.comnullnullnull
nullnullfafd7683bacfe7b2a9e6efe49c100265dc8f7035linkedin.comnull15293304null
nullnullnullCollectionsnullcoe1006395@testwww.commandersofevony.com47bdef96
nullbeanjuice78@yahoo.co.uk98cee3d68dbe9da6467c889d7a0e1f0ebadoo.comnullnullnull
nullnullnull7k7k.comnulljacklw@126.com425797685
nulloctavito.jr@gmail.coma74d0161c5022cb051eb76304d440f4dbadoo.comnullnullnull
nullnull3b655f8eec091c833cb61e00d4aeff33195f9273linkedin.comnullveragreg@terra.com.brnull
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.