How to Find Hard Links to a Specific File in Ubuntu (find -samefile)

The Inode Duplication Audit

In the Ubuntu Linux filesystem, multiple filenames in entirely different directories can point to the exact same underlying block of data on the hard drive. These are called “hard links.” If you need to securely delete a highly sensitive file (like an old private key or a confidential database dump), simply running the rm command on the original filename is insufficient if hard links exist, because the data remains accessible via the alternate paths. To guarantee total eradication, you must track down every single filename across the filesystem that resolves to that specific chunk of data.

Using the find Command with -samefile

The Linux find command utilizes the -samefile flag to perform a strict inode-matching search based on a reference file.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. Assume your sensitive file is located at /home/user/secret.txt. To recursively scan the entire filesystem (starting at the root /) for any other file that points to the exact same data, type the following command exactly:
  3. sudo find / -type f -samefile /home/user/secret.txt
  4. Press Enter.

Raw Data Tracing

The syntax utilizes a direct file path (/home/user/secret.txt). The engine first extracts the raw integer inode number of the reference file. It then recursively scans every directory on the system, reading the inode metadata of every encountered file. If it finds a file (no matter what it is named or where it is hidden) that shares the exact same inode number as your reference file, it is returned as a positive hit. This command is an absolute necessity for security administrators ensuring that redundant access points to sensitive data are completely severed before purging a payload.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.