The Hard Link Audit
Unlike standard Windows shortcuts, Linux utilizes “hard links,” which are multiple independent filenames that point to the exact same physical block of data on the hard drive. If you delete one hard link, the data remains perfectly intact until the very last hard link is deleted. In complex server environments or backup systems (like rsnapshot), administrators often create thousands of hard links to save space. However, if you are attempting to completely purge a secure file from the server, you must ensure it does not have hidden hard links pointing to it from other directories. You must search the file system based on link count.
Using the find Command with -links
The Linux find command utilizes the -links flag to search the file system exclusively for files that possess a specific number of hard links.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To scan the entire server (
/) and return every file that has exactly 2 hard links, type the following command exactly: sudo find / -type f -links 2- Press Enter and provide your administrator password.
Identifying Redundancy
Prefixing the command with sudo is mandatory to scan across system boundaries. Most standard files on a Linux system have exactly 1 link. By searching for -links 2, you are asking the server to reveal files that exist in at least two different locations simultaneously. You can also use mathematical operators: searching for -links +5 will return files that have more than 5 hard links pointing to them. This is a critical forensic tool for ensuring that when you delete a sensitive document, you have actually destroyed the data rather than just removing one of its aliases.