Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nullnullnullCollectionsnullpurple_daisys91@yahoo.comflowers
nullrfps@live.fr73a6511b932ba38b2469c67566f567a9badoo.comnullnullnull
nullnull79dc75a60c811b84722b36b2ebe20e562e43b89elinkedin.comnulludayrajuri@yahoo.comnull
nullnullnullCollectionsnullPoKaDoTscutiex0x@aol.comsprouse7
nullnull$2a$08$dNxJjUDoqBntYYrnIrZpdOncO3lAykjLpXdb7XwgIhPzxQgh.OSSadropbox.comnullfabrice_walle@euskalnet.netnull
nullolga.72@hotmail.it3765e3c1a11584925db85a313ac47376badoo.comnullnullnull
nullletycia11@hotmai.comcb6499747b04e3d3b857490fd20c1fb8badoo.comnullnullnull
nullnullf7f23068a96c8bc0a86f06869a4d636d7c6faf09linkedin.comnull80517249null
nullnullnulllinkedin.comnull51507772xxx
nullnullnulllinkedin.comnullpaulaminetti@gmail.comxxx
nullnullnullCollectionsnullKasey923@aol.comkasey923
nullnullnulllinkedin.comnulldeborah.leigh@my.sinclair.eduxxx
nullnull3f2c919380801a136d8011ac2237084f8073976dlinkedin.comnull82972926null
nullnull26c09d656dde0f27622628b47fff29ccbc874fe0linkedin.comnullWASHBOARD9405@ATT.NETnull
nullnullnulllinkedin.comnull147320231xxx
nullnullf3dabe4f6f10f123b44e0634184d9c6e7b7777b2linkedin.comnull70709744null
nullnull89447df7af766546022e12dedff478a971f992c3dropbox.comnulljeff.lund@energynet.comnull
nullnull30fa38d5ca9c292e857e68b6733ac31753d52c62dropbox.comnulljbe@edc.dknull
nullnulle7003aaa507f78d673a0e6fb5bb85a8d85bb1a7blinkedin.comnullnicole.rueeger@ksw.chnull
nulle_dis_berk@hotmail.com878458f6d15f7e6c2f4d07ab67badcdabadoo.comnullnullnull
nullnullnullCollectionsnulleduard_sukaru2000@yahoo.comeduard
nullnullnulllinkedin.comnull5506210xxx
nullnitanita_es@hotmail.com80c40d195f671d54ceb378d43e104bcebadoo.comnullnullnull
nullnulld6f8cdd522e4013ea482c6dfb3154c086b627eeclinkedin.comnulljim@dolan.ccnull
nullnull933d23cc31b40728b4d7af0b94fd91676097abedlinkedin.comnull150224986null
nullnull0878a2de347c5e89e910d774cfe8ff9a72ba2211linkedin.comnull168324419null
nullnull$2a$08$h5pn7RILAhGoGpDhBFBo3e45BFuZ5z3Kb292mzWTcbttcbBJKUPR2dropbox.comnullmonica_mayers@yahoo.comnull
78.57.141.20nullnull000webhost.comdragasdragotas@gmail.comdvynys1
nullnullnullCollectionsnull395862524@qq.comjcy38128396
nullvalev86@libero.it2430906731a238669aa9eff1f15bbe59badoo.comnullnullnull
nullluisjonny@hotmail.com04ba41e77469df11efbb019489a2e55bbadoo.comnullnullnull
nullyagachi_6@msn.comf8ee02dbb3eda2b2455c0b4022ad72bcbadoo.comnullnullnull
nullnullnullCollectionsnullkadir.caliskan@iserv-tarmstedt.ded8impl7iqu
nullnull9281301397d80e1da0647ac91cb80c7efcf66eb7dropbox.comnullluigimuzzica@interfree.itnull
nullnulle5e9fa1ba31ecd1ae84f75caaa474f3a663f05f4linkedin.comnull137042169null
nullnulleab54f997f2a00049a766a320fa6766235f5faa9linkedin.comnull144099626null
nullnullnullCollectionsnulldakidgotg12@gmail.comfalcon51
190.79.73.191nullnull000webhost.comLavana Jbonillaiqytylof@aol.comjnglurvtz8
nullnull7c67df211551f08ede6f1fdf6cfffc9a09ecebaalinkedin.comnull36826766null
nullnull14ae2cb0b8101578614192567cd8622ce783a875linkedin.comnull8337383null
nullnullnullCollectionsnull123tachka123@gmail.comsasha987
nullnullnullCollectionsnullting-1990@live.com5201314
nullnull$2a$08$6njqoOCDvGIT8mu3MAEKweV/TMxWViZwvNKhnjFzkJjxSaaTOJQKydropbox.comnullchrisramseyquick@gmail.comnull
nullnullnulllinkedin.comnullteamolaurinha@hotmail.comxxx
nullhmcg@blackberry.orange.co.ukb74204ee3f416a0dc520127eab73d33cbadoo.comnullnullnull
nullnullnullCollectionsnullkazaf1102@gmail.comaptx4869
nullnull601ec216e29c42c0630a9fd78465631d9dc40d72linkedin.comnulldlcarlyon@gmail.comnull
nullnullnulllinkedin.comnull71236839 f21ebcbf88644a8c7dd79be7356d12ad4ff3dc39 -> bshah121180@yahoo.co.in
nullnull$2a$08$mMLExlRyXkaQBt0V0V7MzeOIlg618s3hecECogveHSpLTgpnx8jb.dropbox.comnulltw1x109l4@163.comnull
nullnullnulllinkedin.comnull137706172xxx
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.