The Permissions Audit
When auditing the security of an Ubuntu Linux server, one of the most critical tasks is locating files that have overly permissive access rights. If a junior developer accidentally grants “777” (read, write, and execute for everyone) permissions to a critical configuration file, an attacker who gains low-level access to the server can instantly modify that file to escalate their privileges. You cannot manually check the properties of thousands of files; you must instruct the Linux search engine to filter files based entirely on their numerical permission matrix.
Using the find Command with -perm
The Linux find command utilizes the -perm (permissions) flag to isolate files that precisely match a specific security string.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To search the entire
/var/www/web directory specifically for files that are completely open to the public (777 permissions), type the following command exactly: sudo find /var/www/ -type f -perm 0777- Press Enter and provide your administrator password.
Exact vs. Partial Matches
By default, -perm 0777 looks for an exact, perfect match. It will only return files that are exactly 777. If you want to find files that have at least a certain permission (even if they have others), you use a minus sign. For example, running sudo find /etc/ -type f -perm -0002 instructs the server to find all files in the /etc/ directory where the “world” (public) has write access, regardless of what other permissions the owner or group might possess. This is an incredibly powerful tool for locating security vulnerabilities.