The Ownership Audit
In a multi-user Ubuntu Linux environment, files are strictly bound to the specific user account that created them. If an employee leaves your company and their account is deleted, or if a rogue web service like Apache starts generating files in random directories where it shouldn’t have access, you need a way to audit the filesystem based strictly on ownership. You cannot manually check the properties of every single file on a hard drive. Instead, you must instruct the kernel to scan the filesystem and report back every file owned by a specific username.
Using the find Command with -user
The Linux find command utilizes the -user flag to filter results based entirely on account ownership.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To search the entire server (
/) for every file owned by the user “john”, type the following command exactly: sudo find / -type f -user john- Press Enter and provide your administrator password.
Refining the Search
If you run that command against the root directory, the terminal will print a massive, scrolling list of files. You can refine the search to make it more useful:
- Search a specific directory:
find /var/www/html/ -type f -user apache(This checks if the Apache web server owns any files inside your web directory). - Search by Group instead of User:
find /home/ -type f -group developers(This finds all files belonging to the ‘developers’ permission group).
Once you locate the files, you can use the chown command to forcefully transfer ownership to the correct system administrator.