daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

dd-tool.md (16127B)


      1 ---
      2 title: "dd tool"
      3 description: "⚠️ Warning: dd can permanently destroy data if used incorrectly. Always double-check your commands, especially the if= (input) and of= (output) parameters."
      4 category: tools
      5 tags: ["tools", "adcs", "forensics"]
      6 tools: []
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Tools/dd tool.md"
     10 ---
     11 # Linux `dd` Command: Complete Guide and Cheat Sheet
     12 
     13 ## Reference Table
     14 
     15 | Topic | Description | Reference Type |
     16 |:---|:---|:---|
     17 | GNU Coreutils dd | Official documentation for dd utility | Official Documentation |
     18 | Linux man pages | Complete dd manual page | Manual/Documentation |
     19 | Disk cloning and imaging | Techniques for full disk backup and restoration | Tutorial/Guide |
     20 | Bootable USB creation | Creating bootable media from ISO images | Practical Guide |
     21 | Data recovery and forensics | Using dd for data recovery operations | Advanced Guide |
     22 | Security and data wiping | Secure deletion and data sanitization | Security Guide |
     23 | Performance optimization | Block size tuning and I/O optimization | Performance Guide |
     24 | Network backups | Remote backup using SSH and compression | Network Administration |
     25 
     26 ---
     27 
     28 ## Overview
     29 
     30 **dd** is a powerful low-level data copying and conversion utility in Linux, nicknamed both "**data duplicator**" and "**data destroyer**" (due to its potential for catastrophic data loss if used incorrectly). It performs bit-by-bit copies of files, devices, and partitions.
     31 
     32 ⚠️ **Warning**: dd can permanently destroy data if used incorrectly. Always double-check your commands, especially the `if=` (input) and `of=` (output) parameters.
     33 
     34 ---
     35 
     36 ## Basic Syntax
     37 
     38 ```bash
     39 dd if=[input] of=[output] [options]
     40 ```
     41 
     42 **Note**: dd uses unique `option=value` syntax instead of standard `-option` or `--option` format.
     43 
     44 ---
     45 
     46 ## Core Options Reference
     47 
     48 | Option | Description | Example |
     49 |:---|:---|:---|
     50 | `if=FILE` | Input file/device (source) | `if=/dev/sda` |
     51 | `of=FILE` | Output file/device (destination) | `of=/dev/sdb` |
     52 | `bs=SIZE` | Block size (read and write) | `bs=4M` |
     53 | `ibs=SIZE` | Input block size | `ibs=512` |
     54 | `obs=SIZE` | Output block size | `obs=4096` |
     55 | `count=N` | Copy only N input blocks | `count=100` |
     56 | `skip=N` | Skip N blocks at input start | `skip=10` |
     57 | `seek=N` | Skip N blocks at output start | `seek=5` |
     58 | `status=LEVEL` | Transfer information display | `status=progress` |
     59 | `conv=CONV` | Conversion options (comma-separated) | `conv=noerror,sync` |
     60 | `iflag=FLAGS` | Input flags (comma-separated) | `iflag=direct,fullblock` |
     61 | `oflag=FLAGS` | Output flags (comma-separated) | `oflag=sync,direct` |
     62 
     63 ---
     64 
     65 ## Block Size Guide
     66 
     67 | Block Size | Use Case | Performance |
     68 |:---|:---|:---|
     69 | `512` | Default (legacy compatibility) | Slow ⚠️ |
     70 | `4K` (4096) | Standard sector size | Moderate |
     71 | `64K` | Network transfers, older HDDs | Good |
     72 | `1M` | General purpose, HDDs | Very Good ✓ |
     73 | `4M` | SSDs, modern drives | Excellent ✓✓ |
     74 
     75 **Recommendations**:
     76 * **SSDs**: Use `bs=4M` for optimal performance
     77 * **HDDs**: Use `bs=1M` or `bs=64K`
     78 * **Network transfers**: Use `bs=64K` for reliability
     79 * **Always use** `conv=fsync` or `oflag=direct` with block sizes ≥ 4096 for proper error detection
     80 
     81 ---
     82 
     83 ## Common Conversion Options (conv=)
     84 
     85 | Option | Description |
     86 |:---|:---|
     87 | `noerror` | Continue operation on read errors (essential for recovery) |
     88 | `sync` | Pad input blocks with nulls to match block size |
     89 | `fsync` | Physically write output data before finishing |
     90 | `notrunc` | Do not truncate the output file |
     91 | `sparse` | Try to seek rather than write null blocks (saves space) |
     92 | `ucase` | Convert lowercase to uppercase |
     93 | `lcase` | Convert uppercase to lowercase |
     94 | `ascii` | Convert EBCDIC to ASCII |
     95 | `ebcdic` | Convert ASCII to EBCDIC |
     96 | `block` | Pad newline-terminated records with spaces |
     97 | `unblock` | Replace trailing spaces with newline |
     98 
     99 **Most Important**: `conv=noerror,sync` for recovering data from failing drives
    100 
    101 ---
    102 
    103 ## Input/Output Flags
    104 
    105 | iflag/oflag | Description |
    106 |:---|:---|
    107 | `direct` | Use direct I/O (bypass cache) |
    108 | `sync` | Use synchronized I/O |
    109 | `fullblock` | Accumulate full blocks of input (iflag only) |
    110 | `append` | Append mode (oflag only) |
    111 | `nonblock` | Use non-blocking I/O |
    112 | `count_bytes` | Treat count as bytes, not blocks |
    113 | `skip_bytes` | Treat skip as bytes, not blocks (iflag) |
    114 | `seek_bytes` | Treat seek as bytes, not blocks (oflag) |
    115 
    116 ---
    117 
    118 ## Status Display Options
    119 
    120 | Status Level | Description |
    121 |:---|:---|
    122 | `none` | No output at all |
    123 | `noxfer` | Suppress final transfer statistics |
    124 | `progress` | Show periodic transfer statistics (recommended ✓) |
    125 
    126 **Example**: `status=progress` shows real-time progress like:
    127 ```
    128 524288000 bytes (524 MB, 500 MiB) copied, 10 s, 52.4 MB/s
    129 ```
    130 
    131 ---
    132 
    133 ## Common Use Cases with Examples
    134 
    135 ### 1. Full Disk Cloning
    136 
    137 Clone entire disk (including all partitions and boot sectors):
    138 
    139 ```bash
    140 # Identify source and destination
    141 lsblk
    142 
    143 # Unmount all partitions on destination
    144 sudo umount /dev/sdb*
    145 
    146 # Clone disk
    147 sudo dd if=/dev/sda of=/dev/sdb bs=4M status=progress conv=fsync
    148 
    149 # Flush cache
    150 sync
    151 ```
    152 
    153 **Verification**:
    154 ```bash
    155 # Hash both disks and compare
    156 sudo md5sum /dev/sda
    157 sudo md5sum /dev/sdb
    158 ```
    159 
    160 ---
    161 
    162 ### 2. Create Bootable USB from ISO
    163 
    164 ```bash
    165 # Verify ISO integrity first
    166 sha256sum ubuntu-22.04.iso
    167 
    168 # Identify USB device (NOT partition!)
    169 lsblk
    170 
    171 # Unmount USB
    172 sudo umount /dev/sdb*
    173 
    174 # Write ISO to USB (use device /dev/sdb, NOT /dev/sdb1)
    175 sudo dd if=ubuntu-22.04.iso of=/dev/sdb bs=4M status=progress oflag=sync
    176 
    177 # Verify USB
    178 sudo file -s /dev/sdb
    179 ```
    180 
    181 **Important Notes**:
    182 * Write to the device (`/dev/sdb`), NOT to a partition (`/dev/sdb1`)
    183 * No need to format USB beforehand—dd overwrites everything
    184 * To reuse USB after: `sudo fdisk /dev/sdb` then `sudo mkfs.vfat /dev/sdb1`
    185 
    186 ---
    187 
    188 ### 3. Create Disk Image (Backup)
    189 
    190 ```bash
    191 # Backup entire disk to image file
    192 sudo dd if=/dev/sda of=~/backup_disk.img bs=4M status=progress
    193 
    194 # Backup single partition
    195 sudo dd if=/dev/sda1 of=~/backup_partition.img bs=4M status=progress
    196 
    197 # Compressed backup (saves space)
    198 sudo dd if=/dev/sda bs=4M status=progress | gzip > backup_disk.img.gz
    199 
    200 # Backup with progress using pv
    201 sudo dd if=/dev/sda bs=4M | pv | gzip > backup_disk.img.gz
    202 ```
    203 
    204 ---
    205 
    206 ### 4. Restore from Disk Image
    207 
    208 ```bash
    209 # Restore from image
    210 sudo dd if=backup_disk.img of=/dev/sda bs=4M status=progress
    211 
    212 # Restore from compressed backup
    213 gunzip -dc backup_disk.img.gz | sudo dd of=/dev/sda bs=4M status=progress
    214 
    215 # Alternative decompression
    216 zcat backup_disk.img.gz | sudo dd of=/dev/sda bs=4M status=progress
    217 ```
    218 
    219 ---
    220 
    221 ### 5. MBR (Master Boot Record) Backup/Restore
    222 
    223 ```bash
    224 # Backup entire MBR (512 bytes: boot code + partition table)
    225 sudo dd if=/dev/sda of=mbr_backup.img bs=512 count=1
    226 
    227 # Backup only boot code (446 bytes, excluding partition table)
    228 sudo dd if=/dev/sda of=mbr_boot.img bs=446 count=1
    229 
    230 # Restore MBR
    231 sudo dd if=mbr_backup.img of=/dev/sda bs=512 count=1
    232 ```
    233 
    234 ---
    235 
    236 ### 6. GPT Partition Table Backup/Restore
    237 
    238 For GPT disks, use `sgdisk` (not dd):
    239 
    240 ```bash
    241 # Backup GPT
    242 sudo sgdisk --backup=/path/to/backup.gpt /dev/sda
    243 
    244 # Restore GPT
    245 sudo sgdisk --load-backup=backup.gpt /dev/sda
    246 ```
    247 
    248 ---
    249 
    250 ### 7. Secure Data Wiping
    251 
    252 **Method 1: Fill with zeros (fastest)**
    253 ```bash
    254 sudo dd if=/dev/zero of=/dev/sda bs=4M status=progress
    255 ```
    256 
    257 **Method 2: Fill with random data (more secure)**
    258 ```bash
    259 sudo dd if=/dev/urandom of=/dev/sda bs=4M status=progress
    260 ```
    261 
    262 **Method 3: Using shred (multiple passes)**
    263 ```bash
    264 sudo shred -vfz -n 3 /dev/sda
    265 ```
    266 
    267 **Wipe specific partition**:
    268 ```bash
    269 sudo dd if=/dev/zero of=/dev/sda1 bs=4M status=progress
    270 ```
    271 
    272 ---
    273 
    274 ### 8. Create Fixed-Size File
    275 
    276 ```bash
    277 # Create 100MB file filled with zeros
    278 dd if=/dev/zero of=testfile.dat bs=1M count=100
    279 
    280 # Create 1GB file
    281 dd if=/dev/zero of=largefile.dat bs=1M count=1024
    282 
    283 # Create sparse file (faster, uses less disk space)
    284 dd if=/dev/zero of=sparse.dat bs=1M count=1024 conv=sparse
    285 ```
    286 
    287 ---
    288 
    289 ### 9. Data Recovery from Failing Drive
    290 
    291 ```bash
    292 # Use conv=noerror,sync to skip bad sectors
    293 sudo dd if=/dev/sda of=recovery.img bs=4M conv=noerror,sync status=progress
    294 
    295 # Better: Use ddrescue for recovery (not standard dd)
    296 sudo ddrescue /dev/sda recovery.img recovery.log
    297 ```
    298 
    299 **Why `conv=noerror,sync`?**
    300 * `noerror`: Don't stop on read errors
    301 * `sync`: Pad failed blocks with zeros to maintain alignment
    302 
    303 **Note**: For serious data recovery, use `ddrescue` instead—it's specifically designed for this purpose with features like:
    304 * Log file to track progress
    305 * Resume capability
    306 * Multiple retry attempts with varying block sizes
    307 
    308 ---
    309 
    310 ### 10. Network Backup via SSH
    311 
    312 **Remote backup (local to remote)**:
    313 ```bash
    314 # Basic remote backup
    315 sudo dd if=/dev/sda bs=4M | ssh user@remote 'dd of=backup.img'
    316 
    317 # With compression (faster transfer)
    318 sudo dd if=/dev/sda bs=4M | gzip | ssh user@remote 'gunzip | dd of=backup.img'
    319 
    320 # With progress monitoring
    321 sudo dd if=/dev/sda bs=4M | pv | gzip | ssh user@remote 'gunzip | dd of=backup.img'
    322 ```
    323 
    324 **Remote restore (remote to local)**:
    325 ```bash
    326 ssh user@remote 'dd if=backup.img' | sudo dd of=/dev/sda bs=4M status=progress
    327 ```
    328 
    329 ---
    330 
    331 ### 11. Copy Partial Data
    332 
    333 **Skip first 100 blocks, copy 50 blocks**:
    334 ```bash
    335 dd if=input.dat of=output.dat bs=1M skip=100 count=50
    336 ```
    337 
    338 **Write at specific offset (seek)**:
    339 ```bash
    340 dd if=data.bin of=output.dat bs=1M seek=10 conv=notrunc
    341 ```
    342 
    343 **Byte-level precision**:
    344 ```bash
    345 dd if=input.dat of=output.dat bs=1 skip=1024 count=512 iflag=skip_bytes,count_bytes
    346 ```
    347 
    348 ---
    349 
    350 ### 12. Benchmarking Disk Performance
    351 
    352 **Write performance**:
    353 ```bash
    354 dd if=/dev/zero of=testfile bs=1M count=1024 oflag=direct
    355 ```
    356 
    357 **Read performance**:
    358 ```bash
    359 dd if=testfile of=/dev/null bs=1M count=1024 iflag=direct
    360 ```
    361 
    362 **Test different block sizes**:
    363 ```bash
    364 for bs in 512 4K 64K 1M 4M; do
    365   echo "Block size: $bs"
    366   dd if=/dev/zero of=testfile bs=$bs count=10000 oflag=direct 2>&1 | grep copied
    367 done
    368 ```
    369 
    370 ---
    371 
    372 ## Progress Monitoring Techniques
    373 
    374 ### 1. Built-in Progress (Recommended)
    375 
    376 ```bash
    377 dd if=/dev/sda of=/dev/sdb bs=4M status=progress
    378 ```
    379 
    380 ### 2. Send Signal to Running dd
    381 
    382 Find the dd process ID:
    383 ```bash
    384 ps aux | grep dd
    385 ```
    386 
    387 Send USR1 signal to show progress:
    388 ```bash
    389 kill -USR1 [dd_pid]
    390 ```
    391 
    392 Or use `watch`:
    393 ```bash
    394 watch -n 5 'kill -USR1 [dd_pid]'
    395 ```
    396 
    397 ### 3. Using pv (Pipe Viewer)
    398 
    399 Install pv first: `sudo apt install pv` or `sudo yum install pv`
    400 
    401 ```bash
    402 # With size known
    403 dd if=/dev/sda bs=4M | pv -s 500G | dd of=/dev/sdb bs=4M
    404 
    405 # Without knowing size
    406 dd if=/dev/sda bs=4M | pv | dd of=/dev/sdb bs=4M
    407 ```
    408 
    409 ### 4. Using dcfldd (Enhanced dd)
    410 
    411 `dcfldd` is an enhanced version with built-in progress and hashing:
    412 
    413 ```bash
    414 dcfldd if=/dev/sda of=/dev/sdb bs=4M hash=md5,sha256 hashwindow=1G
    415 ```
    416 
    417 ---
    418 
    419 ## Verification Methods
    420 
    421 ### Before and After Checksums
    422 
    423 ```bash
    424 # Before operation
    425 sudo md5sum /dev/sda > checksum_before.txt
    426 # or
    427 sudo sha256sum /dev/sda > checksum_before.txt
    428 
    429 # After operation
    430 sudo md5sum /dev/sdb > checksum_after.txt
    431 
    432 # Compare
    433 diff checksum_before.txt checksum_after.txt
    434 ```
    435 
    436 ### Verify ISO Integrity
    437 
    438 ```bash
    439 # Check ISO before creating bootable USB
    440 sha256sum ubuntu-22.04.iso
    441 
    442 # Compare with official checksum from download page
    443 ```
    444 
    445 ### Verify Bootable USB
    446 
    447 ```bash
    448 sudo file -s /dev/sdb
    449 ```
    450 
    451 Expected output: Should show filesystem or ISO 9660 information
    452 
    453 ---
    454 
    455 ## Safety Checklist ⚠️
    456 
    457 Before running dd, **ALWAYS**:
    458 
    459 1. ✓ **Identify devices correctly**:
    460    ```bash
    461    lsblk
    462    sudo fdisk -l
    463    ```
    464 
    465 2. ✓ **Unmount target device**:
    466    ```bash
    467    sudo umount /dev/sdb*
    468    ```
    469 
    470 3. ✓ **Double-check if= (source) and of= (destination)**
    471    * `if=` is what you're copying FROM (source)
    472    * `of=` is what you're copying TO (destination)
    473    * Reversing these will destroy your data!
    474 
    475 4. ✓ **Verify you have correct device names**:
    476    * `/dev/sda` vs `/dev/sdb` confusion is common
    477    * `/dev/sdb` (device) vs `/dev/sdb1` (partition)
    478 
    479 5. ✓ **Ensure sufficient space on destination**
    480 
    481 6. ✓ **Run with sudo/root permissions** (most operations require it)
    482 
    483 7. ✓ **Use `status=progress`** to monitor operation
    484 
    485 8. ✓ **Run `sync` after dd** to flush cached writes:
    486    ```bash
    487    sync
    488    ```
    489 
    490 9. ✓ **Verify with checksums** after critical operations
    491 
    492 10. ✓ **Have backups** before overwriting any device
    493 
    494 ---
    495 
    496 ## Common Errors and Troubleshooting
    497 
    498 | Error | Cause | Solution |
    499 |:---|:---|:---|
    500 | `Permission denied` | Insufficient privileges | Use `sudo` |
    501 | `Device or resource busy` | Device is mounted | `sudo umount /dev/sdX*` |
    502 | `No space left on device` | Destination too small | Use larger destination or compress |
    503 | `Input/output error` | Failing drive or bad sectors | Use `conv=noerror,sync` or `ddrescue` |
    504 | `dd: invalid number` | Wrong syntax for size | Use correct format: `1M`, `4K`, `512` |
    505 
    506 ### Check for Errors
    507 
    508 ```bash
    509 # View kernel-level errors
    510 dmesg | grep -i error
    511 
    512 # Check SMART data on drives
    513 sudo smartctl -a /dev/sda
    514 ```
    515 
    516 ---
    517 
    518 ## Performance Optimization Tips
    519 
    520 1. **Use appropriate block size**:
    521    * SSDs: `bs=4M`
    522    * HDDs: `bs=1M` or `bs=64K`
    523    * Network: `bs=64K`
    524 
    525 2. **Use direct I/O for benchmarking**:
    526    ```bash
    527    oflag=direct iflag=direct
    528    ```
    529 
    530 3. **Ensure physical writes with**:
    531    ```bash
    532    conv=fsync
    533    # or
    534    oflag=sync
    535    ```
    536 
    537 4. **Minimize system load**:
    538    * Close unnecessary applications
    539    * Avoid running multiple disk operations simultaneously
    540 
    541 5. **Use compression for network transfers**:
    542    ```bash
    543    dd if=/dev/sda bs=4M | gzip | ssh user@remote 'gunzip > backup.img'
    544    ```
    545 
    546 6. **Consider hardware factors**:
    547    * Check cables and ports (intermittent errors)
    548    * USB 2.0 vs 3.0 speed differences
    549    * SATA II vs III capabilities
    550 
    551 ---
    552 
    553 ## Advanced Features
    554 
    555 ### Create Sparse Files
    556 
    557 ```bash
    558 dd if=/dev/zero of=sparse.dat bs=1M count=1024 conv=sparse
    559 ```
    560 
    561 ### Append to Existing File
    562 
    563 ```bash
    564 dd if=new_data.bin of=existing_file.dat bs=1M oflag=append conv=notrunc
    565 ```
    566 
    567 ### Read Special System Files
    568 
    569 ```bash
    570 # Read first 1KB of RAM (requires root)
    571 sudo dd if=/dev/mem of=mem_sample.bin bs=1K count=1
    572 
    573 # Note: Modern systems may restrict /dev/mem access for security
    574 ```
    575 
    576 ### Network Transfer with Netcat
    577 
    578 **Sender (server)**:
    579 ```bash
    580 nc -l 9999 | dd of=/dev/sdb bs=4M
    581 ```
    582 
    583 **Receiver (client)**:
    584 ```bash
    585 dd if=/dev/sda bs=4M | nc server_ip 9999
    586 ```
    587 
    588 ---
    589 
    590 ## Alternative Tools
    591 
    592 | Tool | Purpose | When to Use |
    593 |:---|:---|:---|
    594 | `ddrescue` | Data recovery | Failing drives, bad sectors |
    595 | `dcfldd` | Enhanced dd | Need built-in hashing, better progress |
    596 | `partclone` | Partition cloning | Only copy used blocks, faster backups |
    597 | `rsync` | File synchronization | File-level backups, incremental updates |
    598 | `clonezilla` | Disk imaging GUI | User-friendly disk cloning |
    599 | `shred` | Secure deletion | Multi-pass overwriting for security |
    600 
    601 ---
    602 
    603 ## Quick Reference Card
    604 
    605 ### Most Common Commands
    606 
    607 ```bash
    608 # Full disk clone with progress
    609 sudo dd if=/dev/sda of=/dev/sdb bs=4M status=progress conv=fsync
    610 
    611 # Create bootable USB from ISO
    612 sudo dd if=linux.iso of=/dev/sdb bs=4M status=progress oflag=sync
    613 
    614 # Backup disk to compressed image
    615 sudo dd if=/dev/sda bs=4M status=progress | gzip > backup.img.gz
    616 
    617 # Restore from compressed image
    618 gunzip -dc backup.img.gz | sudo dd of=/dev/sda bs=4M status=progress
    619 
    620 # Backup MBR
    621 sudo dd if=/dev/sda of=mbr_backup.img bs=512 count=1
    622 
    623 # Secure wipe
    624 sudo dd if=/dev/zero of=/dev/sda bs=4M status=progress
    625 
    626 # Check device list
    627 lsblk
    628 sudo fdisk -l
    629 ```
    630 
    631 ---
    632 
    633 ## Final Notes
    634 
    635 * **dd** is an extremely powerful tool—respect its capabilities
    636 * **Always double-check** your commands before pressing Enter
    637 * **Test on non-critical data** first if you're learning
    638 * **Keep backups** of important data before any dd operation
    639 * **Use `status=progress`** to avoid blind operations
    640 * **Verify operations** with checksums when possible
    641 * Consider **alternatives** like `ddrescue` for data recovery scenarios
    642 * **dd** stands for "data duplicator" (or "disk dump"), not "destroy disk"—but it can do both!
    643 
    644 ---
    645 
    646 *This guide covers dd usage as of GNU Coreutils 8.x and later. Older versions may lack some features like `status=progress`. Check your version with: `dd --version`*