Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nullnull$2a$08$4cK3N6qIRh8CgwEjAcF32eOsva335plIigrTDvZ3zlUHzbIX/d5l.dropbox.comnullkhaled-ti@hotmail.comnull
nullnullnullCollectionsnullrichkerri@xtra.co.nzcheese
nullnullnulllinkedin.comnull23255932xxx
nullnull0ae0bae7e34f498b87d16dce5a8cb7b197c9d97dlinkedin.comnullpbakker@iinet.net.aunull
nullmhuescar@enerpal.com79c784cac64a42dcf2e449069aa5cf52badoo.comnullnullnull
nullnullnullCollectionsnullbjosie55@yahoo.com989656
31.59.99.99nullnull000webhost.comMaryam Bimaryam.babeai@gmail.com4WAhlwO9GrWIBCE588YR
nullnullaa60b19cebe595f237f2ca655e4c7611ab1b84f3linkedin.comnull141541895null
nullnullnulllinkedin.comnulljoaquingarridogarcia@gmail.comxxx
nullnullnullCollectionsnullcoe676301@testwww.commandersofevony.comff6029b8
nulllaetytia66@hotmail.frd1cbcc06c38f8570ad2867aad209b125badoo.comnullnullnull
nullnullnulllinkedin.comnull150630230xxx
87.66.116.49nullnull000webhost.comDi Tomassomaximedt@live.beMaiotome01-
nullnullnullCollectionsnulllisaatkinson66@msn.combradzix123456
nullnullnullCollectionsnullgrib.vladimir@mail.ruvovan3185516
nullperiklos@azet.sk496c04e33e85a6edc3d036f66b439698badoo.comnullnullnull
nullnullnulllinkedin.comnull167133580xxx
nullnull9408e341af49030ed003d529b582ca9ca654402blinkedin.comnull136199676null
nullnullnullCollectionsnulltina.jackson@ashford.edudanger
nullnullnullCollectionsnullalina.belozerova12@yandex.ruCalifornia
nullnullnullCollectionsnullpatrickh930@gmail.compatrick
nullnullc1c1b096347e6135f796f05b81dd29f01310e09clinkedin.comnull169388666null
nullnullnullCollectionsnullmjg4711@googlemail.comhure4711
nullnull6206d120dfa9df50109fa191e0f2921486c8c16blinkedin.comnull73817628null
nullnull$2a$08$4HC63knFYy5pA9Tb/gzBr.gROBOZpbJQszVebNF8tKrfJeGbpPDWSdropbox.comnulljamespete1958@gmail.comnull
nullnullcedb8e35863118191529cd57e8cf3a0d7a3b1b7clinkedin.comnull58294076null
nullnull$2a$08$jkcRtm3tWEMTKlvx5bYbIOKBbXCoBDt6cRtzIhqhWoYcAA9hPFa7Cdropbox.comnullhughesc@bvec-mt.orgnull
nullnulla558fe97ae337e27b31906a1eeee383d32cf1d46linkedin.comnull150412829null
nullnullnullCollectionsnulloleg.osipchuk@gmail.com4a7473ca8867ad70f1782617a49d3a5b
nullnull3859f3b1b89a8db2897b2651864e65e62700768clinkedin.comnullrodrigo_cardosso@hotmail.comnull
nullnullnullCollectionsnullswag@aol.comdavid
nullnullnulllinkedin.comnullychailloux@free.frxxx
nullnullnullCollectionsnulljrmjohnryan@yahoo.com
nulloznur672010@hotmail.com23a007a16157b79d4adebf6b4ff55e97badoo.comnullnullnull
nullnullnulllinkedin.comnull68172580xxx
nullnullnullCollectionsnulllamarinefifine
nullmatus.gernex@post.sk6e2e4ccf275450f3aa010b900f936c9abadoo.comnullnullnull
nullm_76120@hotmail.fr4f205447618b488e656654fe342d1d8abadoo.comnullnullnull
nulla_patriciagarcia33@woodenmail.com0689d6baec1043777e7b5073cfef0634badoo.comnullnullnull
nullnullnullCollectionsnullzokirule@hotmail.comb1arumenka
nullnullade4909ee041ae87563720f23c9e80b5e23732bflinkedin.comnullbarry_goion@walla.co.ilnull
nullnullnulllinkedin.comnull134380412xxx
nullnull4a5b218474c0725e3498871a59a06ff83f0c6346linkedin.comnull107286744null
nullnullnulllinkedin.comnull52878250xxx
nullnullnullCollectionsnullRyan1233@hotmail.comfuk19600
nullnull1cd2d716cc1876a4521b1527ffd47d9350a73c0elinkedin.comnulldelonbience@gmail.comnull
nullnullnulllinkedin.comnull125286120xxx
nullnullnulllinkedin.comnullpeter-o-mally@web.dexxx
nullnull10a85d3d0b23d66db5884763f17adccbcc352287linkedin.comnull61779093null
nullnull82b999a1688ded628fbd3ac046231306cd153c70linkedin.comnullcgalbertorio@gmail.comnull
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.