How to Find Files with the Sticky Bit Set in Ubuntu (find -perm)

The Deletion Safeguard

In Ubuntu Linux, directories that have rwx global permissions (like the /tmp/ folder) allow absolutely anyone to create, edit, or delete files inside them. However, a major security issue arises if User A deletes a file that User B just created. To prevent this, Linux uses the “Sticky Bit” (represented numerically as 1000 or symbolically as a t in the execution column). When a directory has the sticky bit set, users can create files, but they are strictly restricted to only deleting or renaming the files they personally own. System administrators must regularly audit public-facing directories to ensure the sticky bit is properly enforced.

Using the find Command with -perm

The Linux find command utilizes the -perm flag paired with the exact octal value -1000 to isolate files or directories protected by the sticky bit.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the entire root filesystem (/) and return a list of every directory that currently possesses the sticky bit, type the following command exactly (you will need sudo privileges to search the root level):
  3. sudo find / -type d -perm -1000
  4. Press Enter.

Octal Privilege Forensics

The syntax utilizes the dash (-) before the octal value (-1000) to instruct the search engine to look for files where the sticky bit is at least set, regardless of what the other read/write permissions are. If you omit the dash and type strictly -perm 1000, the command will fail because it will look for files that have the sticky bit set but possess absolutely zero other permissions (no read, no write, no execute). This flag is an absolute necessity for security engineers auditing the integrity of shared network drives or public upload folders.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.