Hi folks
can anyone give me an idea of how dd command works in terms of implementation details rather than commands .. plzzz... plzzzzz..if u hav ny links to forums i would appreciate it..
Hi folks
can anyone give me an idea of how dd command works in terms of implementation details rather than commands .. plzzz... plzzzzz..if u hav ny links to forums i would appreciate it..
dd is rather simple, as far as commands go.
1. allocate buffer (controlled by options bs (bytes to read at a time), ibs (input buffer size) obs (output buffer size) and cbs (convert bytes)
2. open I/O files
3. seek to input/output (seek and skip options) by the buffer size
4. read data, convert if necessary and pack output buffer, write output (see manpage for conv options).
5. close input/output
6. report status unless status option specifies noxfer
It really is just a read/write loop. The only thing is , it provides optimization
for buffer handling. This gives a significant speed boost.
Can you ask a more specific question ?
BTW the entire source for 'dd' is easily downloaded and installed.
JP got it, except There are a couple options that cause it to 'diddle' the data', these are the "conv" options.
@jp -- i know that but what i wanted to know is that how data can be retreaved even after writin zeros to an entire disk(not just partiotion table) ..
@stevea -- i think it gav u the correct thing im lookin for ..
plzz explain it conceptually as im not so familiar with commands...
Without a laboratory and specialized instruments - you can't.
Even with the lab and instruments you won't get it all back.
It is also VERY expensive.
The key phrase is "writing zeros to an entire disk".
In the old days, a disk was written by first seeking to the known
location. That "known location" is not precisely located due to
mechanical jitter, gear movement. Also drivers had the ability
to offset from this "known location" by a small amount to either
side of the "known location". This meant that a sector was not
a single track - but a collection of up to about 40 tracks that
could overlap. This overlap allowed for old data to be detected.
In addition, the recording was horizontal (north-south magnetic
domains). This horizontal recording gives a third dimension to
the data. In some cases, polishing off the top layer would expose
old data that was still present, but obscured by new data.
The combination was the source of secure deletes by writing
zeros, writing ones, alternating 1s/0s, then 0s/1s, and lastly
by writing zeros again. The multiple passes would tend to cover
a wider strip of the sector, making it harder to detect old data.
New disks use vertical recording - this makes the third dimension
unavailable. Side tracks may still exist, but software drivers
in the OS are no longer doing it - the formatter card on the disk
does it instead.
It is actually easier to recover data from bad sectors - when they
get remapped to good sectors, old data remains in the bad sector,
damaged, but still there.
For the most part, it is just not practical to recover data from a
disk once it is cleared.
@jpollard -- thank u very much for ur time and help ..
my whole point is im working on a project to securely deleting data from an abandoned disk ..
plzzz refer me somethin so that i can giv a litttle more time.
u gav me a gud look at what is what ... but i need a little more exercise to get ur points correctly i think ...
If you're interested in secure deletion, you could also look at the command shred, and at Darik's Boot and Nuke.
some references:
http://en.wikipedia.org/wiki/Data_remanence
Though the reference of the "18 1/2 minute" data being recoverable - not a chance, but not because of the authors assumed "should be easy".
Erasure of audio tapes is done via degaussing, not through overwrite. The
erasure is done via a AC signal being recorded to leave the data with
random magnetic domains as the tape moves much slower than the AC
signal...
https://ssd.eff.org/tech/deletion
These appear to cover the basics.
I have been experimenting with the dd command and find same very useful. If you are interested in my experiments please have a look at my web site www.thelinuxman.eu
Let me know if you find same useful to you
@helden -- i got that stuff as a pre-search over net .. but thanks for ur help ..
Linux has a per-file "shred" command in coreutils.
The thread has absolutely nothing to do with 'dd' - the title is nonsense. Even 'cat' works basically the same. Se helden is veering off course.
You cannot generally recover overwritten data using the common data access methods of the kernel. You (or the CIA) can certainly try to do so by reading the analog signals off the heads and estimating the residual magnetization. Also by diddle the heads to the inter-track spaces. JP has covered this.
/If you are worried about someone reading data off your rotating disk by just reading from a PC, then zeroing it once is sufficient there may be exceptional cases for remapped blocks or hidden tracks.
/If you re-write random data about 7x times then the original signal will decline to the point where even the police will probably not be able to recover it.
/If you want to be certain- pull the platters and bring them up to the curie temperature of the magnetic material.
The exception to the above is that modern SSD drives remap block addresses (as they are written) dynamically. So merely zeroing a few blocks does not necessarily zero the data you previously wrote. It may still be there intact. Filling the entire volume should solve this limitation. This is why some sources claim SSDs "cannot be encrypted". I think that estimation is pretty weak.
Last edited by stevea; 19th October 2010 at 02:41 PM.