Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

usernameuserpasshashdomainemailpassword
nullcherazade-59@hotmail.fr14635f3b6f6bf5dbabdaa62f51fb4e59badoo.comnullnull
nullcnmi_dz@hotmail.comaebe1f40ce4d213fe8ad00d782aa37a9badoo.comnullnull
nullnull70a606b0b81e562ce1872adb3fe2b2d1b947bca6linkedin.com132254909null
nullnullf94ffdee9670fdb8b7e16846a962a071e343fb3alinkedin.com25268103null
nullmirko.greco3@hotmail.it13592f2caf86af30572a825229a2a8dcbadoo.comnullnull
nullnullnullCollectionsdinah.dezac@gmx.dectm2692
nullnull$2a$08$uK1cqgoRnDLaI6uh.JmtHek6iogjnutzFA1vHVMCE1pl8dYsRg70Sdropbox.comdlubin@gmail.comnull
nullnull$2a$08$F0ILh3SF.UWEVuCnju9LRuTA/QYm/Q7uabMLWbovR5xtG6BOwV8zOdropbox.comberaphae@gmail.comnull
nullnullnullCollectionsrobcat@smartchat.net.aupioneers1
nullnullnullCollectionsclyw.max98@mail.rumax12051998
nullnull15e91f8d4bdc75997fe9236d333561d01104f15clinkedin.com53119836null
nullnull90d014520eed41efb06dc1736acb362a613988eelinkedin.com53756286null
nullnullnulllinkedin.com24497421xxx
nullnull4f4ff956842123bfcc494bc40f58dde36d064c62linkedin.com106276124null
nullnullnulllinkedin.com94298450xxx
nullnullnullCollectionsfeichonger2@126.comchenbi8626317
nullnullnulllinkedin.com160534660xxx
nullnull8300a4b4fbfe6aba0c61a881b0dc5d4629e22da1dropbox.comtimdoherty007@gmail.comnull
nullnull604f7d0c789f79b50303c9df83f405adf3007955linkedin.com148424999null
nullnulla9c9b322f29810a1f7d36117e0382b2237818d92dropbox.comsuperpigan_89@hotmail.comnull
nullnullbd280208e8c5cb7ffbedb2e5caa80e310123b576dropbox.comgerardo@neiraelviejo.comnull
nullnull$2a$08$x4CheA68fnUNSUbDwPP6buF1/o9dVJCwoWzBSWJqx6GSeJZgjVm7ydropbox.comgreenman-gardening@hotmail.comnull
nulldmurka7@hotmail.comfcd938a279aa960a9b2a2a68f9d4cf23badoo.comnullnull
nullnullnulllinkedin.com67273441xxx
nullnullf17a58a1bd231e38a556598f4cb16b0ed7084f86linkedin.com92301736null
nullnullnulllinkedin.com54534042xxx
nulldominika.pek@vp.plb54bf4b117e55c055cc9b6f75a2706a4badoo.comnullnull
nullnullnulllinkedin.com159783822xxx
nullnullnullCollectionssuperced_of_fire@hotmail.comad1550a2
nullnullnullCollectionsstevenfranco2012@gmail.comsteven2012
gismonicnullnullCollection1-grinderscape.orgnull62.45.247.92:ben2000
nullhikmetrasulov@yahoo.com4d19093d49c2421f235bfac8070612c5badoo.comnullnull
nullnullnulllinkedin.com120158011xxx
nullnullbf920d631e535afeb65ea21f32d143433fe5ce8alinkedin.com39429778null
nullnull2fb203119bf2fbb3968b2048f7a34096bebb1700linkedin.com19852226null
nullnull9918faf5cbd54ee242f78a1ed841dc1acebc0971linkedin.com16759749null
nullnull10778cfe415ca000a7a91146160e219581328fe5dropbox.comdirken.number-s.filth-hi-hi-hi@ezweb.ne.jpnull
nullnullc40245bc209f71fe61141ec5d6bd52eb0047671dlinkedin.com27628889null
nullnull$2a$08$j/02d5JeXK7f7KsSAkt44.AA2K9CkgmhTgQ21FUjYAEsBcVYGy5madropbox.comdsavedbo@gmail.comnull
nullerikadahlberg79@hotmail.com2a59ed8bb79f711e7c2cf74da0131ef7badoo.comnullnull
nullemsven@hotmail.fr3441a22568b9b9ed25599f4559ffd27fbadoo.comnullnull
nullnull3fb78c3b6f52134bddf8b0644395839b09fccb9clinkedin.comkhushi09081990@rediffmail.comnull
nullnull$2a$08$1V0iDnJQe36KGdv7tVb7AO8LJEdVeNHuoO7nTFaFfRgvDTYWDADNGdropbox.comastridmasse@live.benull
nullnull142a2965e43fa00f924ca149979664f3aa152fd6linkedin.com146686307null
nullnull$2a$08$WwWU7MmY9djFP/jDmssuvuv/JBwfvPFHfWzI3wvAIyrkht0NjMhf6dropbox.comc.avci@o2pp.denull
nullnullnullCollections272439199@qq.com76752694
nulljohannes-butsch@gmx.def81bef337f6dfc4ac68e82c656ce974abadoo.comnullnull
nullnullnullCollections470290311@qq.com470290311
nullgojidanjuma@yahoo.comffd2d6e666a3cb88b984d682e6b20f98badoo.comnullnull
nullnullnulllinkedin.com29563182xxx
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.