Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipuserpasshashdomainnameemailpassword
nullnullnullCollectionsnullizmit_lakers@windowslive.com1245789630
nullnullnullCollectionsnullleshak77@yandex.ru1qjhbr1qaz
nullnull2f6484a088d70fcfff82c39bdfcd5984cfa70c98linkedin.comnullggarza@servibonos.comnull
nullrenata.eko@hotmail.comc77e54d3f7581762d6ca71992ceb99c3badoo.comnullnullnull
nullnullnulllinkedin.comnullreachramesh13@gmail.comxxx
nullnull1d6f65d10a7eac43dbf2caf3b2a9b76bb7bd6a84linkedin.comnull81866314null
nullnulla9927bc9b800a62b7f141d971f276c9e52669226linkedin.comnullasifgcu629@yahoo.comnull
nullnull3bdab4315b1b183b852eea221fd922aebda49692linkedin.comnull63372879null
nullnullnulllinkedin.comnull125490762xxx
nullnullnullCollectionsnulltnoah52@yahoo.comsuperman101
nullnullnulllinkedin.comnull28482522xxx
nullnullnulllinkedin.comnullis@acculogix.comxxx
nullnull3b0fae506ec6d32e69012514dfa12b1afd21cca5linkedin.comnull153790638null
nullnull$2a$08$HdiwElvUMmkZ0Sal08yDeu8bmTtI0IMBoAgbX4XOQtrU7YoiQ/WKOdropbox.comnullandreas.gather@googlemail.comnull
nullnullbb305a539ac15ac4588224a823e236ed31c4f521dropbox.comnulldcsnode5@datawiz.com.mynull
nullnullbf5903574e1473ea89f786973251479e1fa28299linkedin.comnull149879164null
nullnull$2a$08$OmNZgCz/S/w2XO7bec51RO6jzWQkZKwMcEPQdNdL3IMWX8UMqrb62dropbox.comnullkristine.chatterjie@fedscoop.comnull
nullnullnull7k7k.comnullkenmysonwoaini1314
nullnull217454a97887aad6bfad091babada935c6a23ea3linkedin.comnull148671526null
nullnull912a22454f74bb5ba9c13126a4c2ad13975931bflinkedin.comnullperlrosecambodia@gmail.comnull
nullnull$2a$08$c1v0J1nrC3hy0LwiX5Kg/uI/tDCRSA3gRcprK1ZAXxIvO3XZKGQCidropbox.comnulleseymour@f2p.frnull
nullnull753c44fd3312c67c77d118595c271b56220b18e9linkedin.comnull165030873null
nullnullnulllinkedin.comnull111100641xxx
nullnullnulllinkedin.comnull72875002xxx
nullanica.bernard@gmail.combc7990663c867637d9c66bdf1dd3d454badoo.comnullnullnull
nullnullnulllinkedin.comnull134010222xxx
nullnullnulllinkedin.comnull80556042xxx
nullnullnulllinkedin.comnull50335510xxx
nullnull$2a$08$B2OTY3/PuXzONB.trqVA1egjHY4SUnjoQ.7bV2nzTKbLvpxDTC4Pidropbox.comnullrobinst124@yahoo.comnull
nullnull245f01d167764e69b737e9a94f18ca0ce4c01876linkedin.comnull145126746null
nullnullnulllinkedin.comnullahmed_tito212007@yahoo.comxxx
nullnullc0f029c634805888a1d4a47ed3eb8127461f6823dropbox.comnulla-saito@eandm.co.jpnull
nulljohannam@terra.es68411b189bb42baeba3bcfb9e45822dbbadoo.comnullnullnull
nullkleinerprinz71@web.dee53ff25fbe83624a0aefda2205e54202badoo.comnullnullnull
nullnullnulllinkedin.comnull42635000xxx
nullnulleb6806f40d66de9684f1f83fe526e152f64ce2c4linkedin.comnullfatima.bu@bol.com.brnull
nullljmpcepeda@yahoo.com.ara0b68191536df9457ede24e71a8aa61cbadoo.comnullnullnull
nullnullnulllinkedin.comnull85951231xxx
nullsoussoudbk@hotmail.com5529ec47e04001eea673ecf1203dcc5fbadoo.comnullnullnull
nullnull84b39d9efbb3dc16cf3b9dc3714ba10ce73eccfflinkedin.comnulljuliana.wong@netpoleons.comnull
nullnull9a6ae09fe114db3c93c4f0c262d5439c757c4d08linkedin.comnulljmscnrnr@hotmail.comnull
nullnull29c7af3348410e94bc21e52363a9e7a02fd05861linkedin.comnull7848305null
nullnull$2a$08$rPNFUYljGRJ6TDzhOiCEcuijUtrBien3CreQViwxWVG7RJV7LvzS6dropbox.comnullymarinhermosilla@gmail.comnull
nullnull$2a$08$fgkZsVRvMy/l3jvQjV4aNuKFaHA8rXY2UMA4.UOdzP1ylu2QYvqPOdropbox.comnullsolbreck@gmail.comnull
nullnullf1555eb9782d48c57fcb53a6248d15042229f43bdropbox.comnulllaur.hollenbeck@gmail.comnull
nulljerome647626@yahoo.fr2d2c1c7707509d46cc44ab0601294045badoo.comnullnullnull
nullnullnull7k7k.comnullllwf1975@tom.com54llwf
nullnullnullCollectionsnulla1be1nox@aol.comsamurai
141.0.8.250nullnull000webhost.comkancilkancilkidang@yahoo.commuraibatu1
nullnulldcbe567638254f18a1a891d95ec46aee63fc49dclinkedin.comnull54765769null
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.