dd-tool.md (16127B)
1 --- 2 title: "dd tool" 3 description: "⚠️ Warning: dd can permanently destroy data if used incorrectly. Always double-check your commands, especially the if= (input) and of= (output) parameters." 4 category: tools 5 tags: ["tools", "adcs", "forensics"] 6 tools: [] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Tools/dd tool.md" 10 --- 11 # Linux `dd` Command: Complete Guide and Cheat Sheet 12 13 ## Reference Table 14 15 | Topic | Description | Reference Type | 16 |:---|:---|:---| 17 | GNU Coreutils dd | Official documentation for dd utility | Official Documentation | 18 | Linux man pages | Complete dd manual page | Manual/Documentation | 19 | Disk cloning and imaging | Techniques for full disk backup and restoration | Tutorial/Guide | 20 | Bootable USB creation | Creating bootable media from ISO images | Practical Guide | 21 | Data recovery and forensics | Using dd for data recovery operations | Advanced Guide | 22 | Security and data wiping | Secure deletion and data sanitization | Security Guide | 23 | Performance optimization | Block size tuning and I/O optimization | Performance Guide | 24 | Network backups | Remote backup using SSH and compression | Network Administration | 25 26 --- 27 28 ## Overview 29 30 **dd** is a powerful low-level data copying and conversion utility in Linux, nicknamed both "**data duplicator**" and "**data destroyer**" (due to its potential for catastrophic data loss if used incorrectly). It performs bit-by-bit copies of files, devices, and partitions. 31 32 ⚠️ **Warning**: dd can permanently destroy data if used incorrectly. Always double-check your commands, especially the `if=` (input) and `of=` (output) parameters. 33 34 --- 35 36 ## Basic Syntax 37 38 ```bash 39 dd if=[input] of=[output] [options] 40 ``` 41 42 **Note**: dd uses unique `option=value` syntax instead of standard `-option` or `--option` format. 43 44 --- 45 46 ## Core Options Reference 47 48 | Option | Description | Example | 49 |:---|:---|:---| 50 | `if=FILE` | Input file/device (source) | `if=/dev/sda` | 51 | `of=FILE` | Output file/device (destination) | `of=/dev/sdb` | 52 | `bs=SIZE` | Block size (read and write) | `bs=4M` | 53 | `ibs=SIZE` | Input block size | `ibs=512` | 54 | `obs=SIZE` | Output block size | `obs=4096` | 55 | `count=N` | Copy only N input blocks | `count=100` | 56 | `skip=N` | Skip N blocks at input start | `skip=10` | 57 | `seek=N` | Skip N blocks at output start | `seek=5` | 58 | `status=LEVEL` | Transfer information display | `status=progress` | 59 | `conv=CONV` | Conversion options (comma-separated) | `conv=noerror,sync` | 60 | `iflag=FLAGS` | Input flags (comma-separated) | `iflag=direct,fullblock` | 61 | `oflag=FLAGS` | Output flags (comma-separated) | `oflag=sync,direct` | 62 63 --- 64 65 ## Block Size Guide 66 67 | Block Size | Use Case | Performance | 68 |:---|:---|:---| 69 | `512` | Default (legacy compatibility) | Slow ⚠️ | 70 | `4K` (4096) | Standard sector size | Moderate | 71 | `64K` | Network transfers, older HDDs | Good | 72 | `1M` | General purpose, HDDs | Very Good ✓ | 73 | `4M` | SSDs, modern drives | Excellent ✓✓ | 74 75 **Recommendations**: 76 * **SSDs**: Use `bs=4M` for optimal performance 77 * **HDDs**: Use `bs=1M` or `bs=64K` 78 * **Network transfers**: Use `bs=64K` for reliability 79 * **Always use** `conv=fsync` or `oflag=direct` with block sizes ≥ 4096 for proper error detection 80 81 --- 82 83 ## Common Conversion Options (conv=) 84 85 | Option | Description | 86 |:---|:---| 87 | `noerror` | Continue operation on read errors (essential for recovery) | 88 | `sync` | Pad input blocks with nulls to match block size | 89 | `fsync` | Physically write output data before finishing | 90 | `notrunc` | Do not truncate the output file | 91 | `sparse` | Try to seek rather than write null blocks (saves space) | 92 | `ucase` | Convert lowercase to uppercase | 93 | `lcase` | Convert uppercase to lowercase | 94 | `ascii` | Convert EBCDIC to ASCII | 95 | `ebcdic` | Convert ASCII to EBCDIC | 96 | `block` | Pad newline-terminated records with spaces | 97 | `unblock` | Replace trailing spaces with newline | 98 99 **Most Important**: `conv=noerror,sync` for recovering data from failing drives 100 101 --- 102 103 ## Input/Output Flags 104 105 | iflag/oflag | Description | 106 |:---|:---| 107 | `direct` | Use direct I/O (bypass cache) | 108 | `sync` | Use synchronized I/O | 109 | `fullblock` | Accumulate full blocks of input (iflag only) | 110 | `append` | Append mode (oflag only) | 111 | `nonblock` | Use non-blocking I/O | 112 | `count_bytes` | Treat count as bytes, not blocks | 113 | `skip_bytes` | Treat skip as bytes, not blocks (iflag) | 114 | `seek_bytes` | Treat seek as bytes, not blocks (oflag) | 115 116 --- 117 118 ## Status Display Options 119 120 | Status Level | Description | 121 |:---|:---| 122 | `none` | No output at all | 123 | `noxfer` | Suppress final transfer statistics | 124 | `progress` | Show periodic transfer statistics (recommended ✓) | 125 126 **Example**: `status=progress` shows real-time progress like: 127 ``` 128 524288000 bytes (524 MB, 500 MiB) copied, 10 s, 52.4 MB/s 129 ``` 130 131 --- 132 133 ## Common Use Cases with Examples 134 135 ### 1. Full Disk Cloning 136 137 Clone entire disk (including all partitions and boot sectors): 138 139 ```bash 140 # Identify source and destination 141 lsblk 142 143 # Unmount all partitions on destination 144 sudo umount /dev/sdb* 145 146 # Clone disk 147 sudo dd if=/dev/sda of=/dev/sdb bs=4M status=progress conv=fsync 148 149 # Flush cache 150 sync 151 ``` 152 153 **Verification**: 154 ```bash 155 # Hash both disks and compare 156 sudo md5sum /dev/sda 157 sudo md5sum /dev/sdb 158 ``` 159 160 --- 161 162 ### 2. Create Bootable USB from ISO 163 164 ```bash 165 # Verify ISO integrity first 166 sha256sum ubuntu-22.04.iso 167 168 # Identify USB device (NOT partition!) 169 lsblk 170 171 # Unmount USB 172 sudo umount /dev/sdb* 173 174 # Write ISO to USB (use device /dev/sdb, NOT /dev/sdb1) 175 sudo dd if=ubuntu-22.04.iso of=/dev/sdb bs=4M status=progress oflag=sync 176 177 # Verify USB 178 sudo file -s /dev/sdb 179 ``` 180 181 **Important Notes**: 182 * Write to the device (`/dev/sdb`), NOT to a partition (`/dev/sdb1`) 183 * No need to format USB beforehand—dd overwrites everything 184 * To reuse USB after: `sudo fdisk /dev/sdb` then `sudo mkfs.vfat /dev/sdb1` 185 186 --- 187 188 ### 3. Create Disk Image (Backup) 189 190 ```bash 191 # Backup entire disk to image file 192 sudo dd if=/dev/sda of=~/backup_disk.img bs=4M status=progress 193 194 # Backup single partition 195 sudo dd if=/dev/sda1 of=~/backup_partition.img bs=4M status=progress 196 197 # Compressed backup (saves space) 198 sudo dd if=/dev/sda bs=4M status=progress | gzip > backup_disk.img.gz 199 200 # Backup with progress using pv 201 sudo dd if=/dev/sda bs=4M | pv | gzip > backup_disk.img.gz 202 ``` 203 204 --- 205 206 ### 4. Restore from Disk Image 207 208 ```bash 209 # Restore from image 210 sudo dd if=backup_disk.img of=/dev/sda bs=4M status=progress 211 212 # Restore from compressed backup 213 gunzip -dc backup_disk.img.gz | sudo dd of=/dev/sda bs=4M status=progress 214 215 # Alternative decompression 216 zcat backup_disk.img.gz | sudo dd of=/dev/sda bs=4M status=progress 217 ``` 218 219 --- 220 221 ### 5. MBR (Master Boot Record) Backup/Restore 222 223 ```bash 224 # Backup entire MBR (512 bytes: boot code + partition table) 225 sudo dd if=/dev/sda of=mbr_backup.img bs=512 count=1 226 227 # Backup only boot code (446 bytes, excluding partition table) 228 sudo dd if=/dev/sda of=mbr_boot.img bs=446 count=1 229 230 # Restore MBR 231 sudo dd if=mbr_backup.img of=/dev/sda bs=512 count=1 232 ``` 233 234 --- 235 236 ### 6. GPT Partition Table Backup/Restore 237 238 For GPT disks, use `sgdisk` (not dd): 239 240 ```bash 241 # Backup GPT 242 sudo sgdisk --backup=/path/to/backup.gpt /dev/sda 243 244 # Restore GPT 245 sudo sgdisk --load-backup=backup.gpt /dev/sda 246 ``` 247 248 --- 249 250 ### 7. Secure Data Wiping 251 252 **Method 1: Fill with zeros (fastest)** 253 ```bash 254 sudo dd if=/dev/zero of=/dev/sda bs=4M status=progress 255 ``` 256 257 **Method 2: Fill with random data (more secure)** 258 ```bash 259 sudo dd if=/dev/urandom of=/dev/sda bs=4M status=progress 260 ``` 261 262 **Method 3: Using shred (multiple passes)** 263 ```bash 264 sudo shred -vfz -n 3 /dev/sda 265 ``` 266 267 **Wipe specific partition**: 268 ```bash 269 sudo dd if=/dev/zero of=/dev/sda1 bs=4M status=progress 270 ``` 271 272 --- 273 274 ### 8. Create Fixed-Size File 275 276 ```bash 277 # Create 100MB file filled with zeros 278 dd if=/dev/zero of=testfile.dat bs=1M count=100 279 280 # Create 1GB file 281 dd if=/dev/zero of=largefile.dat bs=1M count=1024 282 283 # Create sparse file (faster, uses less disk space) 284 dd if=/dev/zero of=sparse.dat bs=1M count=1024 conv=sparse 285 ``` 286 287 --- 288 289 ### 9. Data Recovery from Failing Drive 290 291 ```bash 292 # Use conv=noerror,sync to skip bad sectors 293 sudo dd if=/dev/sda of=recovery.img bs=4M conv=noerror,sync status=progress 294 295 # Better: Use ddrescue for recovery (not standard dd) 296 sudo ddrescue /dev/sda recovery.img recovery.log 297 ``` 298 299 **Why `conv=noerror,sync`?** 300 * `noerror`: Don't stop on read errors 301 * `sync`: Pad failed blocks with zeros to maintain alignment 302 303 **Note**: For serious data recovery, use `ddrescue` instead—it's specifically designed for this purpose with features like: 304 * Log file to track progress 305 * Resume capability 306 * Multiple retry attempts with varying block sizes 307 308 --- 309 310 ### 10. Network Backup via SSH 311 312 **Remote backup (local to remote)**: 313 ```bash 314 # Basic remote backup 315 sudo dd if=/dev/sda bs=4M | ssh user@remote 'dd of=backup.img' 316 317 # With compression (faster transfer) 318 sudo dd if=/dev/sda bs=4M | gzip | ssh user@remote 'gunzip | dd of=backup.img' 319 320 # With progress monitoring 321 sudo dd if=/dev/sda bs=4M | pv | gzip | ssh user@remote 'gunzip | dd of=backup.img' 322 ``` 323 324 **Remote restore (remote to local)**: 325 ```bash 326 ssh user@remote 'dd if=backup.img' | sudo dd of=/dev/sda bs=4M status=progress 327 ``` 328 329 --- 330 331 ### 11. Copy Partial Data 332 333 **Skip first 100 blocks, copy 50 blocks**: 334 ```bash 335 dd if=input.dat of=output.dat bs=1M skip=100 count=50 336 ``` 337 338 **Write at specific offset (seek)**: 339 ```bash 340 dd if=data.bin of=output.dat bs=1M seek=10 conv=notrunc 341 ``` 342 343 **Byte-level precision**: 344 ```bash 345 dd if=input.dat of=output.dat bs=1 skip=1024 count=512 iflag=skip_bytes,count_bytes 346 ``` 347 348 --- 349 350 ### 12. Benchmarking Disk Performance 351 352 **Write performance**: 353 ```bash 354 dd if=/dev/zero of=testfile bs=1M count=1024 oflag=direct 355 ``` 356 357 **Read performance**: 358 ```bash 359 dd if=testfile of=/dev/null bs=1M count=1024 iflag=direct 360 ``` 361 362 **Test different block sizes**: 363 ```bash 364 for bs in 512 4K 64K 1M 4M; do 365 echo "Block size: $bs" 366 dd if=/dev/zero of=testfile bs=$bs count=10000 oflag=direct 2>&1 | grep copied 367 done 368 ``` 369 370 --- 371 372 ## Progress Monitoring Techniques 373 374 ### 1. Built-in Progress (Recommended) 375 376 ```bash 377 dd if=/dev/sda of=/dev/sdb bs=4M status=progress 378 ``` 379 380 ### 2. Send Signal to Running dd 381 382 Find the dd process ID: 383 ```bash 384 ps aux | grep dd 385 ``` 386 387 Send USR1 signal to show progress: 388 ```bash 389 kill -USR1 [dd_pid] 390 ``` 391 392 Or use `watch`: 393 ```bash 394 watch -n 5 'kill -USR1 [dd_pid]' 395 ``` 396 397 ### 3. Using pv (Pipe Viewer) 398 399 Install pv first: `sudo apt install pv` or `sudo yum install pv` 400 401 ```bash 402 # With size known 403 dd if=/dev/sda bs=4M | pv -s 500G | dd of=/dev/sdb bs=4M 404 405 # Without knowing size 406 dd if=/dev/sda bs=4M | pv | dd of=/dev/sdb bs=4M 407 ``` 408 409 ### 4. Using dcfldd (Enhanced dd) 410 411 `dcfldd` is an enhanced version with built-in progress and hashing: 412 413 ```bash 414 dcfldd if=/dev/sda of=/dev/sdb bs=4M hash=md5,sha256 hashwindow=1G 415 ``` 416 417 --- 418 419 ## Verification Methods 420 421 ### Before and After Checksums 422 423 ```bash 424 # Before operation 425 sudo md5sum /dev/sda > checksum_before.txt 426 # or 427 sudo sha256sum /dev/sda > checksum_before.txt 428 429 # After operation 430 sudo md5sum /dev/sdb > checksum_after.txt 431 432 # Compare 433 diff checksum_before.txt checksum_after.txt 434 ``` 435 436 ### Verify ISO Integrity 437 438 ```bash 439 # Check ISO before creating bootable USB 440 sha256sum ubuntu-22.04.iso 441 442 # Compare with official checksum from download page 443 ``` 444 445 ### Verify Bootable USB 446 447 ```bash 448 sudo file -s /dev/sdb 449 ``` 450 451 Expected output: Should show filesystem or ISO 9660 information 452 453 --- 454 455 ## Safety Checklist ⚠️ 456 457 Before running dd, **ALWAYS**: 458 459 1. ✓ **Identify devices correctly**: 460 ```bash 461 lsblk 462 sudo fdisk -l 463 ``` 464 465 2. ✓ **Unmount target device**: 466 ```bash 467 sudo umount /dev/sdb* 468 ``` 469 470 3. ✓ **Double-check if= (source) and of= (destination)** 471 * `if=` is what you're copying FROM (source) 472 * `of=` is what you're copying TO (destination) 473 * Reversing these will destroy your data! 474 475 4. ✓ **Verify you have correct device names**: 476 * `/dev/sda` vs `/dev/sdb` confusion is common 477 * `/dev/sdb` (device) vs `/dev/sdb1` (partition) 478 479 5. ✓ **Ensure sufficient space on destination** 480 481 6. ✓ **Run with sudo/root permissions** (most operations require it) 482 483 7. ✓ **Use `status=progress`** to monitor operation 484 485 8. ✓ **Run `sync` after dd** to flush cached writes: 486 ```bash 487 sync 488 ``` 489 490 9. ✓ **Verify with checksums** after critical operations 491 492 10. ✓ **Have backups** before overwriting any device 493 494 --- 495 496 ## Common Errors and Troubleshooting 497 498 | Error | Cause | Solution | 499 |:---|:---|:---| 500 | `Permission denied` | Insufficient privileges | Use `sudo` | 501 | `Device or resource busy` | Device is mounted | `sudo umount /dev/sdX*` | 502 | `No space left on device` | Destination too small | Use larger destination or compress | 503 | `Input/output error` | Failing drive or bad sectors | Use `conv=noerror,sync` or `ddrescue` | 504 | `dd: invalid number` | Wrong syntax for size | Use correct format: `1M`, `4K`, `512` | 505 506 ### Check for Errors 507 508 ```bash 509 # View kernel-level errors 510 dmesg | grep -i error 511 512 # Check SMART data on drives 513 sudo smartctl -a /dev/sda 514 ``` 515 516 --- 517 518 ## Performance Optimization Tips 519 520 1. **Use appropriate block size**: 521 * SSDs: `bs=4M` 522 * HDDs: `bs=1M` or `bs=64K` 523 * Network: `bs=64K` 524 525 2. **Use direct I/O for benchmarking**: 526 ```bash 527 oflag=direct iflag=direct 528 ``` 529 530 3. **Ensure physical writes with**: 531 ```bash 532 conv=fsync 533 # or 534 oflag=sync 535 ``` 536 537 4. **Minimize system load**: 538 * Close unnecessary applications 539 * Avoid running multiple disk operations simultaneously 540 541 5. **Use compression for network transfers**: 542 ```bash 543 dd if=/dev/sda bs=4M | gzip | ssh user@remote 'gunzip > backup.img' 544 ``` 545 546 6. **Consider hardware factors**: 547 * Check cables and ports (intermittent errors) 548 * USB 2.0 vs 3.0 speed differences 549 * SATA II vs III capabilities 550 551 --- 552 553 ## Advanced Features 554 555 ### Create Sparse Files 556 557 ```bash 558 dd if=/dev/zero of=sparse.dat bs=1M count=1024 conv=sparse 559 ``` 560 561 ### Append to Existing File 562 563 ```bash 564 dd if=new_data.bin of=existing_file.dat bs=1M oflag=append conv=notrunc 565 ``` 566 567 ### Read Special System Files 568 569 ```bash 570 # Read first 1KB of RAM (requires root) 571 sudo dd if=/dev/mem of=mem_sample.bin bs=1K count=1 572 573 # Note: Modern systems may restrict /dev/mem access for security 574 ``` 575 576 ### Network Transfer with Netcat 577 578 **Sender (server)**: 579 ```bash 580 nc -l 9999 | dd of=/dev/sdb bs=4M 581 ``` 582 583 **Receiver (client)**: 584 ```bash 585 dd if=/dev/sda bs=4M | nc server_ip 9999 586 ``` 587 588 --- 589 590 ## Alternative Tools 591 592 | Tool | Purpose | When to Use | 593 |:---|:---|:---| 594 | `ddrescue` | Data recovery | Failing drives, bad sectors | 595 | `dcfldd` | Enhanced dd | Need built-in hashing, better progress | 596 | `partclone` | Partition cloning | Only copy used blocks, faster backups | 597 | `rsync` | File synchronization | File-level backups, incremental updates | 598 | `clonezilla` | Disk imaging GUI | User-friendly disk cloning | 599 | `shred` | Secure deletion | Multi-pass overwriting for security | 600 601 --- 602 603 ## Quick Reference Card 604 605 ### Most Common Commands 606 607 ```bash 608 # Full disk clone with progress 609 sudo dd if=/dev/sda of=/dev/sdb bs=4M status=progress conv=fsync 610 611 # Create bootable USB from ISO 612 sudo dd if=linux.iso of=/dev/sdb bs=4M status=progress oflag=sync 613 614 # Backup disk to compressed image 615 sudo dd if=/dev/sda bs=4M status=progress | gzip > backup.img.gz 616 617 # Restore from compressed image 618 gunzip -dc backup.img.gz | sudo dd of=/dev/sda bs=4M status=progress 619 620 # Backup MBR 621 sudo dd if=/dev/sda of=mbr_backup.img bs=512 count=1 622 623 # Secure wipe 624 sudo dd if=/dev/zero of=/dev/sda bs=4M status=progress 625 626 # Check device list 627 lsblk 628 sudo fdisk -l 629 ``` 630 631 --- 632 633 ## Final Notes 634 635 * **dd** is an extremely powerful tool—respect its capabilities 636 * **Always double-check** your commands before pressing Enter 637 * **Test on non-critical data** first if you're learning 638 * **Keep backups** of important data before any dd operation 639 * **Use `status=progress`** to avoid blind operations 640 * **Verify operations** with checksums when possible 641 * Consider **alternatives** like `ddrescue` for data recovery scenarios 642 * **dd** stands for "data duplicator" (or "disk dump"), not "destroy disk"—but it can do both! 643 644 --- 645 646 *This guide covers dd usage as of GNU Coreutils 8.x and later. Older versions may lack some features like `status=progress`. Check your version with: `dd --version`*