Home Help Me Help You Want your own scylla?
Follow @_hyp3ri0n

0-day Hunting

Though this project is personally mine (_hyp3ri0n) I have a super exciting project I wanted to point people to from my company Hyperion Gray. Please note it is non-free (not trying to bait and switch you). If you use this project you're likely interested in this :). Information can be found here

Want to help?

Hey folks! Thanks for using scylla.sh and welcome! This is and always will be free. Direct donations to scylla.sh are on hold, If you want to help me out personally because you use or like this project, my father has a side project for an app-based automated drip irrigation system for growing plants in your house (hint: it works well for weeds of a certain nature in legal states). Instead of support to scylla check out and donate to his Kickstarter if it looks interesting to you. Every tiny bit helps! Thanks everyone!

Why Scylla?

scylla.sh has two major goals. One is to have a community-oriented database leak community and make a useful tool for security researchers

The other major goal is to undercut those people that are selling databases. If we can provide a free product here, we are eating into the bottom-line of those people selling leaked dbs for thousands of dollars. This de-incentivises buying of those DBs and therefore posting them in the first place. Even places that are supposedly "ethical" (looking at you HIBP) still have no problem selling your data. scylla.sh is and *will always* be free with an open API.

*Search is in beta, please report bugs to the scylla github repo

ipusernameuserpasssaltpasshashdomainemailpassword
nullnullnullnullnulllinkedin.com163668872xxx
nullnullnullnull3e2573a75821576a00dae928f8a77e35ef60e176linkedin.comsweenemi@udmercy.edunull
nullnullnullnull852993a6b7997c9ab528989ce5f6f26b91abac7blinkedin.com57240038null
nullnullnullnullnullCollectionssammyc704@gmail.comfluffymonkey
nullnullnullnullnullCollectionsmishany978@mail.ru05041997
nullnullnullnull60013cec59b1ffef3f69d31a23a8d4a75697f2eblinkedin.com110766699null
nullnullnullnull81cd5e567b4d5376157be7a141d58510ed6162cflinkedin.com4524005null
nullnullnullnull7ba93424f4ea644ee3d2a24981fd52eda75ea1c0linkedin.commandust@aol.comnull
109.64.60.35ourgreennullux|IV413aa2e53029fa8c079a85960d25b8d9nullrostont@mail.comnull
nullnullnullnullnullCollectionsgmoscosoherrera@hotmail.comcartagena
nullnullmonica@aghemoluca.comnull7f7fbd8d437281bd96f9a439b452f322badoo.comnullnull
nullnullnullnull2aa54a893c2e3c940e3ea251752572e0dfb66d9dlinkedin.com115491468null
nullnullnullnull52aa7e4771a31a4279327adb5e462d1c06984eb8linkedin.com58385048null
nullnullnullnullnulllinkedin.com165018871xxx
nullnullnullnullnullCollectionsanageop@hotmail.comjorj1212
nullnullseminayilmaz@hotmail.comnulldbafb1aef35ca355ffed02d847c132fcbadoo.comnullnull
nullnullnullnullbe1232dcef9fddbea243e07203a7208fc52095delinkedin.com79127128null
nullnullpailok@live.comnull3a3b6544c027db30851c23aab3532633badoo.comnullnull
nullnullnullnullnulllinkedin.com27880078 86cd0b20c980e918d0b767e278ae4677e26ab661 -> hawkshaw@eircom.net
nullnullgeo.taglioni@sajv.chnullaaed94b9049839021ae6eea6ca47285fbadoo.comnullnull
nullnullhayatbosgonlumserhos@hotmail.comnull8de5decebb072cf198e40758fd3d413dbadoo.comnullnull
nullnullnullnullnulllinkedin.com128192362xxx
nullnullnullnullnullCollectionsj.r.s@sol.dkdillerdaller
nullnullplay82@free.frnull05aba02fae208bcdb6afe02947bf036dbadoo.comnullnull
nullnullaleksandrasobiech1@wp.plnullb1c6d46e1fb6791954841857f30eb3a9badoo.comnullnull
nullnullnullnullnullCollectionsbazcolorado@hotmail.itgermagna
nullnullnullnullnullCollectionse_io969@hotmail.comapocalipsis
nullnullnullnull91ea151a068147d7cf862e64878604ac15210a53linkedin.com63374504null
nullnullnullnullnullCollectionsthejacksood@gmail.comgetwin10
nullnullnullnulldfbbfffca785c4e75126441330f3f6329a2eac73linkedin.commarta.freilino@hotmail.itnull
nullnullnullnull8a44ce2350357c1d49b37562c8ecdcbb5f7219c1linkedin.com167481300null
nullnullnullnull$2a$08$68DY.C4iW9NdQ8mL7QbMY.iSs6wdP9SD7wUJuYB9I1fqW8X65T5Pedropbox.comdimikazazi@gmail.comnull
nullnullandresnerva@hotmail.comnulle4da4bae56ab301b3e186404b26d1b8bbadoo.comnullnull
nullnullnullnulld0fb04d91f6c39ab483b4af069aea80b630572b6linkedin.com30869006null
nullnullnullnullnulllinkedin.com149454051xxx
nullnullnullnullnullCollections0ca32e5a-5bb3-4973-ad76-e02b32e6a672@xiaonei.com233950984xiaonei
nullnullnullnullfdfb30e5aac4071983bb59b730444316e870edf5linkedin.com4600896null
nullnullnullnullnullCollectionsfaisal_nero@rocketmail.comgundam31
nullnullnullnullc4fe6488f97950c32882579fb584b6bfb30178dddropbox.comrachel1605@msn.comnull
nullnullmichaelhappy@hotmail.frnullda4c5332661cad24dc34553651312cdabadoo.comnullnull
nullnullhamdi96@live.frnullec23eac77574515761a49dee4377cff8badoo.comnullnull
nullnullnullnull$2a$08$ZrOFnk57IP8tLww0Ve1WAeRoxNwDXwgayoBhuayfAndFDYso/WSbGdropbox.comwilfried.pfanner@vol.atnull
nullnullnullnullb0ce6f76aae0bfdbc8ba38d9613dfb27abace3c8linkedin.commoulik.solanki@gmail.comnull
nullnullnullnullnulllinkedin.com139426381xxx
nullnullnullnullb89b70446b26f6358d569dc8424c931f8cd40bf0dropbox.commiodon@gmx.denull
nullnullnullnullnulllinkedin.com65365780xxx
nullnullnullnullnullCollectionssmigystar@yahoo.comadgjl'sfhk
nullnullnullnullb76b20d04720c83ab4e78c126a9f2fe82a4f9a92linkedin.compatriciosantangelo@gmail.comnull
nullnullnullnull1bd713cdce8179eb1f40c8cc56726e68c5a708c1linkedin.commelaniecaseykc@yahoo.comnull
nullnulltami951@web.denull425915c64dd81d29267755e3aa3d4f41badoo.comnullnull
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99



Queries

Queries use Lucene query syntax. Please note that queries have changed, you no longer need to capitalize the first letter of each field, scylla will rectify automatially if you do use the capital letter. You will get a 500 error if your query is incorrect. Use the fields listed above to guide you. Full query syntax (including wildcards) are supported

Example search for passwords that start with ff
    
      password:ff*
    
  
This would match any passwords with a d in them and the username dave, dale, dane, etc.
    
      name:da?e password:*d*
    
  

API

The search API can be accessed by sending a GET request to this page with the Accept header set to Accept: application/json

GET https://scylla.sh/search?q=your_query&num=100&from=200

The above GET request grabs 1000 results of your_query starting at the 200th record. Pagination can be done using the "from" parameter. Queries return the first 10,000 hits.

Data is returned in JSON format like the following:

[
   {
      "_id":"hKW8WWsBBGJneKoTbFS-",
      "_index":"pw_data",
      "_score":19.8656,
      "_source":{
         "Domain":"exploit.in",
         "Email":"marin.vardic@zzf.hr",
         "Password":"freeshit"
      },
      "_type":"_doc"
   },
   {
      "_id":"_3PgVGsBBGJneKoTof0e",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"linkedin.com",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "PassHash":"a3f5b3b7c790e397b2d77eca31cd96bcd57c8700"
      },
      "_type":"_doc"
   },
   {
      "_id":"dBmbWmsBBGJneKoTZ5Wk",
      "_index":"pw_data",
      "_score":16.46111,
      "_source":{
         "Domain":"exploit.in",
         "Email":"jasna.cajsa-beber@zzf.hr",
         "Password":"vili2005"
      },
      "_type":"_doc"
   }
]



Note you may use the fields below to guide you, but not all fields are returned with each query, only available fields. If fields are added, they will be appended to the list of available fields for query.

ToS

The information on this website is intended only for research purposes. Access has been given to security or other researchers for the purposes of research ONLY. Other than that I sincerely hope this data helps you with your projects and aids in your understanding of your or your organization's security posture. Much love.

- _hyp3ri0n

ToS Enforcement

The information on this website is intended only for research purposes. We search common database leak sites to ensure this is not being circulated for malicious use. We do have default logging turned on for this website which likely includes IP addresses and other identifiers. Please don't misuse this information as we will cooperate with law enforcement if it is.

By the way, for old users, by popular request there is no longer a cryptominer on this website.

- _hyp3ri0n

Donations

Donations for scylla.sh are currently on hold! If you want to help please donate to my father's kickstarter project as described above.

Issues and Bugs

Scylla is currently in beta-v0.1. There will be bugs, Please report bugs to the scylla open github repo. Here you will also find the scylla code, please feel free to open feature requests here as well. These let me know what the community wants out of this site and is supremely useful to me.