How to Find Writable Files in Ubuntu Linux (find -writable)

The Security Vulnerability

In Ubuntu Linux, file permissions are the primary defense against unauthorized modifications. If a critical configuration file (like /etc/passwd) or a web server script is accidentally marked as “writable” by any standard user on the system, a malicious actor can easily overwrite the file to inject malicious code or elevate their privileges. When performing a security audit on a server, one of the first steps is to hunt down these vulnerable files. You must instruct the search engine to filter the filesystem specifically for files that your current user account has the explicit permission to alter or delete.

Using the find Command with -writable

The Linux find command utilizes the -writable flag to instantly isolate files that are open to modification by the user executing the search.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the entire /var/www/ web directory and explicitly return only the files that you have the permission to write to or edit, type the following command exactly:
  3. find /var/www/ -type f -writable
  4. Press Enter. (Notice we do not use sudo here, as running it as root would simply return every file on the system, since root can write to anything).

Patching the Leaks

The search engine will completely ignore files that are locked to “read-only” status. The resulting output is a targeted list of files that you can actively modify. If you are logged in as a low-level guest user and this command reveals that you have write access to critical root binaries or configuration directories, your server’s security is fundamentally broken, and you must immediately repair the permissions using the chmod command to revoke the write access.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.