The Invisible Configuration
In Ubuntu Linux, hiding a file from standard directory listings is incredibly simple: you just add a period (a “dot”) to the very beginning of the filename. Because of this, almost all critical software configuration files (like .bashrc or .ssh) are intentionally hidden to prevent accidental deletion. However, if you are attempting to clean up a compromised server, malicious scripts will frequently utilize this dot-prefix to hide their payloads from casual observation. If you type the standard ls command, these files are completely invisible. You must instruct the search engine to look explicitly for filenames beginning with a dot.
Using the find Command for Dot Files
The Linux find command utilizes the -name flag combined with wildcard characters to hunt down hidden data.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To search a specific user’s home directory for all hidden files, type the following command exactly:
find /home/user/ -type f -name ".*"- Press Enter.
Searching for Hidden Directories
The command above only finds individual hidden files (like .bash_history). If a hacker has created an entire hidden folder to store stolen data, the previous command will miss it. To search specifically for hidden directories, change the type flag to d:
find /home/user/ -type d -name ".*"
This will output a list of invisible folders (such as .config or .cache), allowing you to audit the contents of the entire directory tree.