Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipusernameuserpasshashdomainnameemailpassword
nullnullpeppe11790@hotmail.it5dadf1af9d43f2158b377630235d69dbbadoo.comnullnullnull
nullnullleoferdino@hotmail.com438541447d3cf160c32ee0f596353067badoo.comnullnullnull
nullnullnullnullCollectionsnull635057274@qq.com9294781152
nullnullnull66b2798b3dd237ca48bdd53fd14117f79bf7f254dropbox.comnulldanayres2@yahoo.co.uknull
nullnullka_an_can@hotmail.com6864b8aeecd00e012fa1959b8313d177badoo.comnullnullnull
nullnullnull090e1854bde6575cbb84b5a94f95b37d63f8dcdelinkedin.comnull162639457null
nullnullnull12c2f1f0789e9e582fca1f1f4975516710af829blinkedin.comnullstayes@nbpower.comnull
nullmad pk3rnullnullCollection1-grinderscape.orgnullnull76.193.17.231:ryan2018
nullnullnull2a2dccc9fe7a972cdce444b838552b8ce3fd3cc1linkedin.comnull45291188null
nullnullnulleb10dfc47c5a2d4c541c01e151c9545386690119linkedin.comnullnancyndegwa@yahoo.comnull
nullnullnullnullCollectionsnulldavid_20_100po@hotmail.comtygiwuvu
nullnullnullnullCollectionsnullalexa_costa108@yahoo.com123456
nullnullnullnullCollectionsnulldiane.stephenson@att.netdee7711
nullnullnullnullCollectionsnullmarialatoyabrown2004@yahoo.comderrick
nullnullnull$2a$08$FsnhsRQa7Uo.9OTuurRDsOPMIt9Ph1Z8IUn9SerowUsekb.YWmsSOdropbox.comnulljansutheangel@gmail.comnull
nullnullnullc1d1f6a84c40c6804122f4ed5a17595a23f6f8dclinkedin.comnull114694765null
nullnullnull$2a$08$diSyK/7WByocWC0pHYdSmuOY3G/umMdbxTR5T0BGJS2rd18Dd.PDmdropbox.comnullcarry@homatex.comnull
nullnullnull9521dc7f0098a27f718a939e3b1a07f61df2d4dalinkedin.comnull73610174null
nullnullewaherkt@poczta.onet.pl68f69e1e5f4cd340e4f40b28fcde2d3bbadoo.comnullnullnull
nullnullnullnullCollectionsnullvagan3878691@mail.ru44846454
nullnullo_0mega@hotmail.com0ca17647098a7523627a057d1f72bc55badoo.comnullnullnull
nullnullnull6fe4438a8e3ed68927b431a49bef81aa7eaf4b52linkedin.comnull136414943null
nullnullnullnullCollectionsnullsexi@zonby.if.ua123456789qq
nullnullstefaniemareike@hotmail.dedf3b585af228737564df6e5daa309ad6badoo.comnullnullnull
nullnullnullnullCollectionsnullcoe222043@testwww.commandersofevony.com4dad8a64
nullnullnullnullCollectionsnullbabyz@hotmail.comkitten12
nullnullnullc1b2264ac068a1fb297e6fa1e03ffa3172ad3287linkedin.comnull158219615null
nullnullnullnullCollectionsnulllegomine@gmail.comximenaquiroz
nullnullnullnullCollectionsnullghostbusters_p@hotmail.compojk987
nullnullnull$2a$08$bpWRoFWEcefYVWtlhcCQWuRVfq7EJ/VuMN0yWmjLCT8uy1QFf79Iqdropbox.comnullalexvintagee@gmail.comnull
nullnullnullnullCollectionsnulldanikacolumna@yahoo.comkawaii
nullnullnullnulllinkedin.comnulladrian.leal@3icorp.comxxx
nullnullnullf5be3d28f2eaa54ce2823200fce2bf45a170d321linkedin.comnullpatricialeonorsanchez@gmail.comnull
nullnulllacika_xxl@yahoo.comcf07953a19bf3b0ed758a0ce20a8606abadoo.comnullnullnull
nullnullsbr_andersson@hotmail.comcee3a8f71487a71e56001c9127f8a05fbadoo.comnullnullnull
nullnullnullnullCollectionsnullsestelyuk@yandex.ua801016
nullnullnullnulllinkedin.comnull29977569 9f273e321a1d1ea40251ab0a45f8ca8cbdd135da -> lukestreet@gmail.com
nullnullnullb94957fe4d2a88761026cac67868963d8f4ba802dropbox.comnullkillua0809@hotmail.comnull
nullnullpouilloux.fabien@hotmail.come048fea6bd77a8182918adfd4a992d5abadoo.comnullnullnull
nullnullnullefc9aaa3e428415aaad469d3d9c174c00fe7db77linkedin.comnull90096365null
nullnullnulla212e11842752c0be0846d565e031f2d2c426c49linkedin.comnull131471563null
37.78.255.133nullnullnull000webhost.comHopewhqdoqwh75@mail.rujUwaBABIDAvO122
nullnullnullnulllinkedin.comnull88202582xxx
nullnullnull6bc996d99d71ca45b0ddd0c8c1f4138715028248linkedin.comnull103882706null
nullnullnull552be053f3962e6e4a9ddf3ec754065da80d796flinkedin.comnull123309437null
nullnullnull81b2c2742909f3f44bdf2970e4e6cc82e7658d16linkedin.comnull10786603null
nullnullnullnullCollectionsnullvictor.risler@gmail.comfuzion
nullnullnullnulllinkedin.comnull32037782xxx
nullnullsc_alguz@yahoo.es4cc8a738c3dbcdd8ee12b6a717c78ffdbadoo.comnullnullnull
nullnullnull44d5072e53959067918170163b43b0727e3f0eaflinkedin.comnull49202476null
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.