How to Find Executable Files in Ubuntu Linux (find -executable)

The Rogue Scripts

In Ubuntu Linux, any text file can theoretically be transformed into a runnable program simply by modifying its permissions. This is incredibly powerful for system administration, but it poses a massive security risk. If a compromised web application allows a hacker to upload a malicious Python or bash script and mark it as executable, they can run arbitrary code on your server. When auditing a compromised machine, you cannot simply look for files ending in .exe or .sh, because Linux ignores file extensions. You must instruct the search engine to filter files based entirely on their internal execution permissions.

Using the find Command with -executable

The Linux find command utilizes the -executable flag to instantly isolate files that the operating system is actively allowed to run as programs.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the /var/www/ directory (your web root) explicitly for files that have execute permissions granted, type the following command exactly:
  3. sudo find /var/www/ -type f -executable
  4. Press Enter and provide your administrator password.

Auditing the Results

The search engine will completely ignore static images, standard text files, and standard HTML files. It will only return a list of scripts or binaries that possess the “x” permission. If you find executable files buried deep inside an image upload directory (like /var/www/html/wp-content/uploads/), you have likely found the exact backdoor script a hacker is using to control your server, and you must immediately revoke its permissions using the chmod command.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.