The Rogue User Problem
In a multi-user Ubuntu Linux environment, proper file ownership is critical for security and organization. If an employee leaves the company, or if you suspect a specific user account (like a rogue FTP user) has been compromised and is hiding malicious scripts across your server, you need to instantly locate every single file owned by that specific account. Manually checking the ownership of thousands of directories using the ls -l command is impossible. Instead, you can use the terminal to globally scan the filesystem and filter the results based exclusively on the owner’s username.
Using the find Command with -user
The standard Linux find command includes a highly specific -user flag that allows you to isolate files based on ownership.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- Decide where to start the search. To search the entire server, use the root directory (
/). - To find every single file owned by a user named “john”, type the following command:
sudo find / -type f -user john- Press Enter and provide your administrator password.
Refining the Search and Transferring Ownership
The command above will generate a raw list of files. You can refine this using other flags:
- Find Directories: Change
-type fto-type dto only find folders owned by “john”. - Find by Group: If you want to find files owned by a specific user group (like the “www-data” web server group) rather than an individual, use the
-groupflag instead (e.g.,sudo find / -group www-data).
If John has left the company and you need to immediately transfer ownership of all his files to the new administrator (named “sarah”), you can pipe the search results directly into the chown (change owner) command:
sudo find / -user john -exec chown sarah {} +
This single command will instantly reassign ownership of thousands of files across the entire server, ensuring data is never orphaned.