How to Find Files Owned by a Specific User in Ubuntu (find -user)

The Ownership Audit

Every single file and directory in an Ubuntu Linux file system is strictly assigned to a specific user account. When auditing a web server, isolating files based on their owner is a critical security step. For example, if your web server application (which usually runs as the www-data user) has somehow become the owner of critical bash scripts or root configuration files, a hacker who compromises your website could potentially rewrite those scripts to take over the entire server. To hunt down these permission leaks, you must instruct the Linux engine to filter out all files except those owned by a specific account.

Using the find Command with -user

The Linux find command utilizes the -user flag to instantly isolate files belonging to a specific username.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the entire /etc/ configuration directory and explicitly return only the files owned by the www-data user, type the following command exactly:
  3. sudo find /etc/ -type f -user www-data
  4. Press Enter and provide your administrator password.

Cleaning Up Deleted Users

This command is also essential for system cleanup. If you delete an old employee’s user account, their files are not automatically deleted. Instead, the files become “orphaned” and simply display the old user’s numerical ID instead of a name. You can use a variation of this command—sudo find / -nouser—to scan the entire hard drive for any file that belongs to a deleted user account, allowing you to quickly wipe their remaining data.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.