How to Find Executable Files in Ubuntu Linux

The Security Hunt

In Ubuntu Linux, not all files are created equal. A text file containing a shopping list is harmless, but a bash script or a compiled binary file possesses the “executable” permission, meaning it has the power to actually run code and alter the operating system. If a hacker manages to upload a malicious payload to your web server (such as a PHP shell hidden inside an image directory), that payload must be executable to function. To audit a directory for potential security threats or simply to find a custom script you misplaced, you must instruct the kernel to find files based strictly on this execution permission.

Using the find Command with -executable

The Linux find command utilizes the -executable flag to filter the filesystem, ignoring millions of standard text documents and returning only files capable of running code.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the main Apache web directory for any executable files, type the following command exactly:
  3. sudo find /var/www/html/ -type f -executable
  4. Press Enter and provide your administrator password.

Cleaning Up the Output

If you run this command against a large directory, you might still get hundreds of results. You can combine flags to narrow the search. For example, if you know the malicious script was uploaded recently, you can combine the executable flag with the modified time flag:

sudo find /var/www/html/ -type f -executable -mtime -3

This incredibly powerful command will instantly return a list of files that are both capable of executing code and were modified within the last three days, making it trivial to hunt down a fresh security breach.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.