How to Find Files by Permissions in Ubuntu Linux

The Security Audit

File permissions are the foundation of Linux security. Every file is assigned a three-digit numerical code dictating exactly who can read, write, or execute it. For example, a permission of 777 grants absolute control to every single user on the system, which is a massive security vulnerability if applied to a sensitive database or an executable script. If you are hardening an Ubuntu Linux server against attackers, you cannot manually check the properties of every file. You must instruct the filesystem to hunt down and expose files based entirely on their security clearance.

Using the find Command with -perm

The Linux find command utilizes the -perm (Permissions) flag to filter the hard drive strictly by the assigned three-digit octal code.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To search the entire /var/www/ directory for any highly insecure files possessing absolute 777 permissions, type the following command exactly:
  3. sudo find /var/www/ -type f -perm 0777
  4. Press Enter and provide your administrator password.

Broadening the Search

The command above looks for an exact match. If a file is 775, it will be ignored. If you want to find any file that is writable by anyone in the public group (regardless of the owner’s specific permissions), you can add a hyphen before the number to search for minimum matching bits: sudo find /var/www/ -type f -perm -0002. This allows administrators to quickly locate incredibly dangerous files and lock them down before a malicious actor discovers them.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.