How to Find Files with the Sticky Bit Set in Ubuntu (find -perm -1000)

The Shared Directory Protector

In Ubuntu Linux, the “Sticky Bit” is a specialized permission most commonly applied to shared directories, like /tmp/. When a directory has the sticky bit set, any user can create files inside it, but users are strictly prevented from deleting or renaming files owned by other users. This prevents malicious actors from deleting a temporary file created by the root user. However, if the sticky bit is applied to an individual file or placed on the wrong directory, it can cause severe application errors or block backup scripts from running. You must know how to audit your file system to locate where this unique permission is active.

Using the find Command with -perm -1000

The Linux find command utilizes the -perm flag combined with the numerical value -1000 to explicitly hunt for directories or files carrying the Sticky permission bit.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the entire server starting from the root directory to locate every sticky bit assignment, type the following command exactly:
  3. sudo find / -perm -1000
  4. Press Enter and provide your administrator password.

Auditing the Output

Because the sticky bit can exist anywhere, you must prefix the command with sudo. The search engine will output a list of absolute paths. You should expect to see standard system directories like /tmp and /var/tmp. However, if you see standard files or custom application folders (like /var/www/uploads/) carrying the sticky bit unintentionally, you must investigate immediately and remove it using chmod -t to prevent unexpected file-locking behavior.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.