How to Find Files by Specific Permissions in Ubuntu Linux

The Security Audit

In Ubuntu Linux, file permissions dictate exactly who is allowed to read, modify, or execute a file. These permissions are often represented mathematically using a three-digit octal code (like 755 or 644). One of the most dangerous permissions you can assign is 777, which grants absolute read, write, and execute permissions to every single user on the system, including guests. If you suspect a rogue script or an inexperienced developer has accidentally exposed critical configuration files by assigning them 777 permissions, you must immediately audit the entire filesystem to find and secure them.

Using the find Command with -perm

The Linux find command utilizes the -perm (Permissions) flag to filter the filesystem strictly by its octal security code.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To search the main web directory for any dangerous files possessing absolute 777 permissions, type the following command exactly:
  3. sudo find /var/www/ -type f -perm 777
  4. Press Enter and provide your administrator password.

Exact vs. Partial Matches

The command above finds files that are exactly set to 777. If a file is set to 776, it will be ignored. To find files that simply contain any specific permission bit (for example, finding any file that is executable by the general public, regardless of its other permissions), you prepend a minus sign (-) to the octal code, like this: find /var/www/ -type f -perm -001. This allows for incredibly advanced security audits, helping you locate potentially dangerous executables hiding in plain sight.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.