The Security Audit
In Ubuntu Linux, system administrators often lock down configuration files to be strictly read-only. However, during software installations or manual debugging, permissions are sometimes accidentally changed, leaving critical files open to modification by standard users. If a malicious script gains execution privileges under a standard user account, it will immediately hunt for any writable configuration files to escalate its attack. To preemptively secure your server, you must regularly audit the file system to determine exactly which files your current user has the power to modify.
Using the find Command with -writable
The Linux find command utilizes the -writable flag to exclusively return files that the currently executing user has the mathematical filesystem permissions to alter or overwrite.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH as a standard user (do not use sudo).
- To scan the entire
/etc/directory and return only the files that your specific user account can overwrite, type the following command exactly: find /etc/ -type f -writable 2>/dev/null- Press Enter.
Targeting Vulnerabilities
The -writable flag forces the engine to evaluate the Write (w) permission bit against your specific User ID (UID). If you run this command on the /etc/ directory as a standard user, the output should ideally be completely blank. If it returns a list of files, it means a system configuration file was accidentally left globally writable, or your user account possesses dangerous elevated group permissions. By appending 2>/dev/null, you hide all the “Permission denied” errors for directories you cannot enter, leaving you with a clean, highly targeted list of potential security vulnerabilities.