LinuxSecurity.com: Linux Data Hiding and Recovery | Linux Today

LinuxSecurity.com: Linux Data Hiding and Recovery

Written By
Web Webster
Web Webster
Mar 13, 2002

[ Thanks to LinuxSecurity Contributors for
this link. ]

“It is common knowledge that what is deleted from the computer
can sometimes be brought back. Recent analysis of security
implications of “alternative datastreams” on Windows NT by Kurt
Seifried has shown that Windows NTFS filesystem allows data hiding
in “alternative datastreams” connected to files. These datastreams
are not destroyed by many file wiping utilities that promise
irrecoverable removal of information. Wiping the file means
‘securely’ deleting it from disk (unlike the usual removal of file
entries from directories), so that file restoration becomes
extremely expensive or impossible.

“Some overview of what remains on disk after file deletion, how
it can be discovered and how such discovery can be prevented are
provided in Secure Deletion of Data from Magnetic and Solid-State
Memory by Peter Gutmann. The author recommends overwriting files
multiple times with special patterns. Against casual adversaries,
simply overwriting the file with zeros once will help.

“Linux has no alternative data streams, but files removed using
/bin/rm still remain on the disk. Most Linux systems uses the ext2
filesystem (or its journaling version, ext3 by Red Hat). A casual
look at the design of the ext2 filesystem shows several places
where data can be hidden…”


Complete Story

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.