The Hard Link Audit
In Ubuntu Linux, a “hard link” is a direct pointer to the physical inode (the actual data blocks) on the hard drive. Unlike a symbolic link (which is just a shortcut pointing to a file name), a hard link is indistinguishable from the original file. A file is only truly deleted from the disk when its hard link count reaches zero. If a malicious actor creates a hidden hard link to a massive database file, deleting the original database file will not actually free up any disk space. System administrators must routinely audit the filesystem to locate files with an abnormally high number of hard links.
Using the find Command with -links
The Linux find command utilizes the -links flag to explicitly search for files that possess a specific mathematical count of hard links.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To scan the
/var/www/directory and locate any file that possesses exactly two hard links, type the following command exactly: find /var/www/ -links 2- Press Enter.
Link Count Forensics
The syntax requires an integer representing the exact number of links. You can also use comparative operators. For example, typing -links +2 will instruct the search algorithm to only return files that have strictly more than two hard links pointing to their inode. (Note: Directories in Linux inherently have a link count of at least two, plus one for every subdirectory they contain. Therefore, this command is almost always paired with -type f to restrict the search exclusively to regular files, ignoring directory structures entirely).