The Accessibility Audit
When auditing a multi-user Ubuntu Linux server, administrators frequently need to determine exactly which files a specific user can successfully open and read. If you log in as a standard, unprivileged user, running a blind search across the /var/log/ directory will result in a massive wall of “Permission denied” errors, obscuring the actual files you are permitted to view. To perform a clean, error-free search of data you actually have access to, you must filter the search engine based on your current user’s read privileges.
Using the find Command with -readable
The Linux find command utilizes the -readable flag to exclusively return files that the currently executing user has the mathematical filesystem permissions to read.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH as a standard user (do not use sudo).
- To scan the entire
/etc/directory and return only the configuration files that your specific user account is allowed to read, type the following command exactly: find /etc/ -type f -readable 2>/dev/null- Press Enter.
Silencing the Errors
The -readable flag forces the engine to evaluate the Read (r) permission bit on every file against your specific User ID (UID). However, because you are scanning a system directory without root privileges, the find command will still print “Permission denied” errors for directories you cannot even enter. By appending 2>/dev/null to the end of the command, you instruct the Linux shell to take all the standard error messages (file descriptor 2) and throw them into the digital trash can (/dev/null). This results in a perfectly clean, easy-to-read list of exactly what files you are legally allowed to open on the server.