How to Find Orphaned Files in Ubuntu (find -nouser)

The Ghost File Problem

Every file in Ubuntu Linux is strictly owned by a specific user account and a specific group. However, if an administrator uses the userdel command to permanently delete an employee’s account from the server, the files that user created do not automatically disappear. Instead, they become “orphaned.” They still exist on the hard drive, but the operating system can no longer map their ownership ID to a valid username. From a security perspective, orphaned files are highly dangerous because if a new user is created and happens to be assigned the same numerical ID as the deleted user, they will instantly inherit ownership of those abandoned files. You must hunt down and secure these ghosts.

Using the find Command with -nouser

The Linux find command utilizes the highly specific -nouser and -nogroup flags to isolate files that possess numerical ownership IDs that no longer exist in the system’s registry.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the entire server starting from the root directory to locate all orphaned files, type the following command exactly:
  3. sudo find / -nouser -o -nogroup
  4. Press Enter and provide your administrator password.

Reassigning Ownership

The command will output the absolute path to every orphaned file on your system. Because these files technically have no owner, regular users cannot touch them. You must use your administrator privileges and the chown command (e.g., sudo chown root:root /path/to/orphan.txt) to reassign ownership of these files to the root account, or you must simply delete them to plug the security vulnerability.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.