0 / 5
Slack Space
A disk reads and writes only in whole sectors. A file system gives space to files in clusters, which are larger than sectors. A file rarely fills its clusters exactly, so part of its last cluster holds no file data. That part is slack space.
Example: even the 640B report.txt gets a whole cluster (2048B). 1408B are left after the file data.
1 / 5
Allocate a cluster
The file system gives report.txt one cluster (4 sectors, 2048B) and writes its name and its size, 640B, in the file system record. This cluster used to belong to a deleted file. Deleting a file only marks its space as free; the content is not erased. So all four sectors still hold the deleted file's content.
2 / 5
Write the file data
The 640B of report.txt are written from the start of the cluster. They fill sector 1 (512B), and the remaining 128B go at the front of sector 2.
3 / 5
RAM slack: the rest of sector 2 (384B)
A disk can write only whole sectors, so sector 2 is written in full too. The operating system fills the 384B after the 128B of file data with zeros. These 384B are RAM slack, also called sector slack. The name comes from older operating systems that filled this space with whatever was in memory (RAM).
4 / 5
Drive slack: unwritten sectors 3 and 4
The file data ends in sector 2, so nothing is written to sectors 3 and 4. They are not zeroed either, so 1024B of the deleted file's content stay as they were. This part is drive slack.
5 / 5
Slack space: 1408B
Of the 2048B allocated, only 640B are file data. The other 1408B (384B of RAM slack and 1024B of drive slack) are slack space. The operating system reads only up to the 640B size in the file system record, so opening the file never shows what comes after.
1 / 3
Find a hiding place
The attacker finds the drive slack (sectors 3 and 4, 1024B) in the last cluster of report.txt. The cluster is allocated to report.txt, so no other file overwrites this space unless report.txt is deleted or changed.
2 / 3
Write straight to the sectors
The attacker uses a tool that writes sectors directly to put the customer list into sectors 3 and 4. Because this skips the normal way of saving files, the file system record does not change.
3 / 3
Stay out of sight
The size in the file system record is still 640B. Opening report.txt shows only the original content, and neither the file list nor the free disk space changes. So the hidden data goes unnoticed.
1 / 3
Find where the file ends
The investigator checks the size of report.txt, 640B, in the file system record. The file data in the cluster stops at 640B.
2 / 3
Read to the end of the cluster
In the disk image, the investigator also reads the 1408B from after 640B to the end of the cluster (2048B). This is the slack space that opening the file never shows.
3 / 3
Find what was left
The 384B of RAM slack are filled with zeros, so nothing is left there. The 1024B of drive slack turn up part of the deleted file's content. If someone had hidden data, it would show up here too.