Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasssaltpasshashdomainemailpassword
nullnullnullnullCollectionszactheright@yahoo.comkeepout
nullnullnullcd42f9ed18890bcbddeed7ce2ce0e4dfaf032f03linkedin.comwhmbreeze@hotmail.comnull
nullchiche1225@hotmail.comnull166ce01123e172f4e3f18b794496fb38badoo.comnullnull
nullmintcookie@web.denullbef57905103e4d7751fd872a80f966c0badoo.comnullnull
nullnullnull18d4d39941669ea408eb2b0828199c7f347cde57linkedin.com91276629null
nullnullnull65702f12fb2e2b4722930762c9fa0d57c0c0ae34dropbox.comgattu8.cfsn11@gmail.comnull
nullnullnullnullCollectionsgangster-chesssoviet
nullnullnullnull7k7k.com396798999@qq.com2611231
nullnullnulle2d41471b6665e4d8b0085f9f1049c45a9291877linkedin.comtimothy.j.werner@jpl.nasa.govnull
nullnullnull$2a$08$CNO/QCdvp4k2HYjfKREDn.Hk7.gRgw4RrifYEUiYPwVUJrIxU1vuedropbox.comk.strato@gmail.comnull
nullnullnullfe1fb20ff84babba7e6ea3dcc4d1ad541d52a675linkedin.combelltell1@frontier.comnull
nullnullnullnullCollectionstriggers0@yahoo.comdogged
nullstefan-2901@hotmail.denulla16eb6dfcb1ecbde8e174ee11c3068dfbadoo.comnullnull
nullnullnullnullCollectionsSpamme8296@hotmail.comnubia7
nullnullnull5bd8cfcd0234237d65e309d4c97026db503ace47linkedin.com48182166null
nullnullnullnulllinkedin.com78566712xxx
nullnullnullnullCollectionsslemderman99@hotmail.comslemderman99
nullnullnullnullCollectionsmaizylind@hotmail.comsoccer
nullkerry90@alice.itnull88682c9b624bb8f89f8f8ae11419f3dcbadoo.comnullnull
nullnullnullnulllinkedin.com90488292xxx
nullnullnull2120f1f9a8fe29e36ebabe4f9cc994b3152df923linkedin.com124468105null
nullramazan_07_73@hotmail.comnull64148dc1ac82c806e5ea43ffa5b664b4badoo.comnullnull
nullnullnull435510560cbfb0c4c587884ef62138f325b5933dlinkedin.com152426848null
nullsteph19777@yahoo.frnullf04ff00a78726a2b9575f8946ad1576dbadoo.comnullnull
nullzorge@yuurok.comnulle43bfba83ee76df02152c309dbf7ceeebadoo.comnullnull
nullnullnull44abbc3cc1ce368c748c7d337d77a46480330df2linkedin.com62889564null
182.177.3.65delete6warmea7b8511c807565b81112d1f3ffc0c4496cabandonia.comiwBeverlujeyDahietrich@hotmail.comnull
nullnullnullnulllinkedin.comrstutzman@southeast.eduxxx
nullnullnullnull7k7k.comwulala100@tianya.cn21021021
nullnullnull00186f5a2786be0d7c961017074bb6056f919f28linkedin.com156033377null
nullmetin_korhan@hotmail.comnull5c066bf7126922cb65cfda2220af38bcbadoo.comnullnull
nullnullnull6d82233408f529807a1dd7878757456aa4e67188linkedin.comdagobertobrito8@gmail.comnull
nullnullnullnullCollectionsturkce_bensu@hotmail.commabopady
nullnullnull8153c6cea3729430471044a86e0315303ba71a76dropbox.comxime_xe@hotmail.comnull
nullnullnullnulllinkedin.com147824062xxx
nullnullnull330e4651aebb1971185c12a7014a24796813af70linkedin.compmpraba88@gmail.comnull
nullfugitibo12@hotmail.comnulla9cf753a69c9e7467277a147e813f78bbadoo.comnullnull
nullnullnullf8eb4bab178092b714a3429a2df5b52a136778d0linkedin.comrizwan_karim@hotmail.comnull
nullnullnullnulllinkedin.com21881630xxx
nullnullnullnullCollectionsjason1998loo@hotmail.comjayjay1998
nullnullnull3d5c0bc0e06f3927175c00cf75fc9ea91f9dfbd8linkedin.com138018339null
nullnullnullnulllinkedin.comssueli50@yahoo.com.brxxx
nullnullnull$2a$08$uThOSXz8bTj4bk/AACmZieRsBLtmkRzl2LKN9IkvVP4qQjGdehNkydropbox.comralf@geyers.denull
nullnullnull0c67a87317289c2b35e28ea2d0651853d2901e92linkedin.com160166587null
nullnullnulldfba4e0e49b95f8539a32cb4a94441d2c4e3988clinkedin.com35003574null
nullnullnullff1e7543d41ae7fe7d8015cbe91e9d34770e9ebclinkedin.com24746287null
nullnullnullnullCollectionsmaksimchaiko_1@mail.ru159753er
nullnullnull4dda0651164070f61be6297704f2a603da76f035linkedin.com5010357null
nullnullnullb46a35936e051d30a6c6844738bf7d8994799a71linkedin.com45370213null
nullnullnull608bfe577cc0125447418a2adc9ebe026cb24061linkedin.comrob.dixon@motorola.comnull
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.