How to Find Files NOT Owned by a Specific User in Ubuntu (find -not -user)

The Inverted Security Search

In Ubuntu Linux, it is common to search for files owned by a specific user to clean up their home directory. However, a much more powerful security technique is the “inverted search.” If you have a highly secure directory, such as a web root (/var/www/), you expect every single file inside it to be owned by the www-data user. If a hacker uploads a malicious script using a compromised FTP account, that script will likely be owned by a completely different user. To instantly spot the anomaly, you must instruct the Linux search engine to find files that do not belong to the expected owner.

Using the find Command with -not -user

The Linux find command utilizes the logical -not operator (or the exclamation point !) placed immediately before the -user flag to invert the search criteria.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the entire /var/www/ directory and return every file that is not owned by the user www-data, type the following command exactly:
  3. find /var/www/ -type f -not -user www-data
  4. Press Enter.

Rapid Anomaly Detection

The search engine will recursively dig through all subdirectories and output the absolute path of every file that fails to match the specified owner. In a perfectly configured web directory, this command should return absolutely nothing. If it spits out a list of PHP files owned by “root” or an obscure FTP user, you have instantly identified a major security violation or a broken deployment script, allowing you to rapidly correct the ownership permissions before the server is compromised.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.