The Security Audit
File permissions are the foundation of Linux security. Every file is assigned a three-digit numerical code dictating exactly who can read, write, or execute it. For example, a permission of 777 grants absolute control to every single user on the system, which is a massive security vulnerability if applied to a sensitive database or an executable script. If you are hardening an Ubuntu Linux server against attackers, you cannot manually check the properties of every file. You must instruct the filesystem to hunt down and expose files based entirely on their security clearance.
Using the find Command with -perm
The Linux find command utilizes the -perm (Permissions) flag to filter the hard drive strictly by the assigned three-digit octal code.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To search the entire
/var/www/directory for any highly insecure files possessing absolute777permissions, type the following command exactly: sudo find /var/www/ -type f -perm 0777- Press Enter and provide your administrator password.
Broadening the Search
The command above looks for an exact match. If a file is 775, it will be ignored. If you want to find any file that is writable by anyone in the public group (regardless of the owner’s specific permissions), you can add a hyphen before the number to search for minimum matching bits: sudo find /var/www/ -type f -perm -0002. This allows administrators to quickly locate incredibly dangerous files and lock them down before a malicious actor discovers them.