Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nullnull$2a$08$pCMZsyLt2M8JCExRliqfU.pqRfxFu1o09sp/aNyyhdQV/GjoFV/eidropbox.comnullilago@hotmail.itnull
nulldavidtubis@w.cn494c2779c990240e6ea0bd797b6b0e19badoo.comnullnullnull
nullnull$2a$08$us0ssPVeeayT8CWJldFAquVY.xIghGWWt.I5FSxTFZ13BiiK/K2OSdropbox.comnullkvv_84_ua@mail.runull
nullnull4f6c4a58eea803fe7f1ffd5c5e927db30c91053elinkedin.comnull60953266null
nullnull23815984e3727ea38ae17fd86866f09e9fe8453elinkedin.comnull93157967null
nullfelmygenin@aol.com93fdb1cd0d25bc5290f83f7a070dd432badoo.comnullnullnull
nullnullnulllinkedin.comnull9318152xxx
nulladzik996@interia.eu29433ff2aa1c23617fec283e8d4a4112badoo.comnullnullnull
nullnull$2a$08$cufm0TDLh3rygnWaEsjJUe3qTBZQqCTAYIbPoL3QPXmDDHoQzYiACdropbox.comnullmooon-bb@hotmail.comnull
nullnull2d5edacea0e08c8906ac7b07824844fcc45a06dflinkedin.comnull114248186null
nullnullnulllinkedin.comnull152156012xxx
nullnullnulllinkedin.comnull148016071xxx
nullnull199ad8f65b4aae536ac96d1cedf598ca7e8d9710linkedin.comnull62848583null
nullnullnullCollectionsnullCaptainMassacre@freenet.de3531201
nullvillaverderamos@hotmail.comf3449cae87a2496a445063a73495be22badoo.comnullnullnull
null621180306@facebook.com397b86f51391ccde605cab92804b9105badoo.comnullnullnull
nullnullfff2162c36f7c8159102d0efd5d6847f2e0e0b0adropbox.comnullrafael.sanchez.pena@gmail.comnull
nullnulla33e8600b9e3cfb114d5d124cbeee4788810bb76linkedin.comnullcotibrod@gmail.comnull
nullnullnullCollectionsnullmakemomoney2007@aol.comdopeboi1
nullnullnullCollectionsnull0408197713032008@mail.ruFUNTIK130308
nullnullnulllinkedin.comnull163830771xxx
nullmaja0812@azet.skc9dea3a117e3f11abd6a4c8a8dc24df3badoo.comnullnullnull
nullnullnulllinkedin.comnullseanmoore70@hotmail.comxxx
nullbabaaslan@live.comd4f031ad63f5d4ddd8ec7466d769a7ccbadoo.comnullnullnull
nullnull7d6536f007aab4142e1df324a2fa0d79c9b75358linkedin.comnullHelene_Brown81@yahoo.comnull
nullnull0213c72d0bc9584e824909fd3a887e0afe81982edropbox.comnullkswanhbic@gmail.comnull
nullnull5097270d54e9b16ee6063dea9f83e5c5bfec708blinkedin.comnull127583059null
nullnullnullCollectionsnullchavezpollo@hotmail.comtootsieroll
nullnullnullCollectionsnulla7xflameboy@aim.comxm+k12x
nullnullnullCollectionsnulltantuzun@gmail.comtanaldo2003
nulluntiltheend_snowboarder1@hotmail.com7b3bac002bdfbf55135a7a9a1dbac784badoo.comnullnullnull
nullran_papisanchez@hotmail.com64d0a516e1c4870272d126ccbaed3f8fbadoo.comnullnullnull
nullnullnullCollectionsnullsssfbfb@hotmail.com.auyomama69
nullnullb1285d4b43914cc9980ff65d3f54031d0f908e72linkedin.comnull156951848null
nullnull32b15bf04add447c026ff2321b9c566582b37ea9dropbox.comnulljames.chae@jacobs.comnull
125.164.237.38nullnull000webhost.comsatriyo mahardikosatriovk@yahoo.co.idsatria75
nullnullnulllinkedin.comnull140403480xxx
nullnullebb8d0a0ef7382e0b594600513363fcc8360b388linkedin.comnull29208745null
nullnullnullCollectionsnull931256881@qq.com3173009
nullnulld2765ad730ce07ff02fd1803f76ac6aab72320falinkedin.comnull29025763null
nullnull5009c8e190ee49b3785c61b658c1a999e3510a6elinkedin.comnull38683423null
nullnullb1d3b355ab4c7c2fa9a2d5ae2caf23d8b8e79312dropbox.comnulljason@spunlite.co.nznull
188.190.126.25nullnull000webhost.comRodelhaticbelen@yandex.ru12qw23we
nullnullnulllinkedin.comnulljohnlilly955@btinternet.comxxx
nullnullb1f45ed147d6803ac1a2a91bdea1fab603f910a5linkedin.comnull74122467null
nullsevi_baran@live.de8744d41f8ef1a37fccadec0d731e0554badoo.comnullnullnull
nullnull031b195d385618ab465ec462f45b8975122498cflinkedin.comnull107205878null
nullhas_galstyan@yahoo.comc3a2de74dcd14561b08acfc5f6062970badoo.comnullnullnull
nullnull$2a$08$igDr5WZFBIw7qXgU16cEU.FkhNrFWgAdOyOAXsQrVRMZHKUARTZnKdropbox.comnullkathryn1217us@gmail.comnull
nullnullnullCollectionsnullizmit_lakers@windowslive.com1245789630
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.