chmod.md (8232B)
1 --- 2 title: "chmod & File Permissions" 3 description: "Linux permission model: symbolic/octal chmod, chown, umask, SUID/SGID/sticky bits explained." 4 category: linux-it 5 tags: [linux, permissions, cli] 6 tools: [chmod, chown, umask] 7 difficulty: beginner 8 updated: "2026-08-09" 9 source: "repo:Linux/chmod-cheatsheet.pdf" 10 --- 11 12 # chmod & File Permissions 13 14 Linux file permissions reference — chmod, chown, special bits, ACLs and the security angles for ethical hacking. 15 16 --- 17 18 ## Basic Concepts 19 20 ### Permission Types 21 22 - **r (read)** — Value 4: view file contents 23 - **w (write)** — Value 2: modify files 24 - **x (execute)** — Value 1: run programs 25 26 ### User Categories 27 28 - **u (user/owner)** — file's owner 29 - **g (group)** — group members 30 - **o (others)** — all other users 31 - **a (all)** — all three categories 32 33 ### Viewing Permissions 34 35 ```bash 36 # List with permissions 37 ls -l 38 39 # Show hidden files 40 ls -la 41 42 # Numeric permissions 43 stat -c '%a %n' filename 44 ``` 45 46 --- 47 48 ## CHMOD Syntax 49 50 ### Symbolic Mode 51 52 Format: `chmod [who][operator][perms] file` 53 54 **Operators:** 55 - `+` Add permissions 56 - `-` Remove permissions 57 - `=` Set exact permissions 58 59 ```bash 60 # Add execute for owner 61 chmod u+x script.sh 62 63 # Remove write from group/others 64 chmod go-w config.conf 65 66 # Set exact permissions 67 chmod u=rw,go=r file.txt 68 69 # Add execute for all 70 chmod a+x tool 71 ``` 72 73 ### Numeric Mode 74 75 Format: `chmod [numeric] file` — calculate by adding values: r(4) + w(2) + x(1). 76 77 ### Common Permission Sets 78 79 | Num | Sym | Usage | 80 |:---|:---|:---| 81 | 777 | rwxrwxrwx | DANGER! Full access | 82 | 755 | rwxr-xr-x | Public executables | 83 | 750 | rwxr-x--- | Group-shared tools | 84 | 700 | rwx------ | Private scripts | 85 | 644 | rw-r--r-- | Public config files | 86 | 640 | rw-r----- | Restricted configs | 87 | 600 | rw------- | Private data/keys | 88 | 400 | r-------- | Read-only secrets | 89 90 --- 91 92 ## CHOWN Syntax 93 94 ```bash 95 # Change user owner 96 chown username file 97 98 # Change user and group 99 chown user:group file 100 101 # Change only group 102 chown :groupname file 103 104 # Recursive 105 chown -R user:group dir/ 106 107 # Follow symlinks 108 chown -L user:group link 109 110 # No dereference symlinks 111 chown -h user:group link 112 113 # Reference file ownership 114 chown --reference=ref target 115 116 # Numeric UID/GID 117 chown 1000:1000 file 118 ``` 119 120 --- 121 122 ## Special Permissions 123 124 ### SUID (4000) 125 126 Runs with the owner's permissions. 127 128 ```bash 129 # Set SUID 130 chmod 4755 binary # rwsr-xr-x 131 132 # Find SUID files 133 find / -perm -4000 2>/dev/null 134 ``` 135 136 > **Security risk —** SUID files owned by root are privilege-escalation vectors. 137 138 ### SGID (2000) 139 140 - Files: run with group permissions 141 - Directories: new files inherit the group 142 143 ```bash 144 # Set SGID 145 chmod 2755 file # rwxr-sr-x 146 chmod 2775 dir/ # rwxrwsr-x 147 148 # Find SGID files 149 find / -perm -2000 2>/dev/null 150 ``` 151 152 ### Sticky Bit (1000) 153 154 Users can only delete their own files. 155 156 ```bash 157 # Set sticky bit 158 chmod 1777 /tmp/ # rwxrwxrwt 159 160 # Find sticky directories 161 find / -type d -perm -1000 2>/dev/null 162 ``` 163 164 --- 165 166 ## Security Configurations 167 168 ### Critical Files 169 170 | File | Owner:Group | Perms | 171 |:---|:---|:---| 172 | /etc/passwd | root:root | 644 | 173 | /etc/shadow | root:shadow | 640 | 174 | /etc/sudoers | root:root | 440 | 175 | ~/.ssh/id_rsa | user:user | 600 | 176 | ~/.ssh/authorized_keys | user:user | 600 | 177 178 ### Secure SSH Keys 179 180 ```bash 181 chown user:user ~/.ssh/id_rsa 182 chmod 600 ~/.ssh/id_rsa 183 chmod 700 ~/.ssh/ 184 ``` 185 186 ### Web Application 187 188 ```bash 189 # Set ownership 190 chown -R www-data:www-data /var/www/ 191 192 # Directory permissions 193 chmod 750 /var/www/html/ 194 195 # File permissions 196 find /var/www/ -type f -exec chmod 640 {} \; 197 ``` 198 199 ### Check Critical Files 200 201 ```bash 202 # Verify shadow file perms 203 [ $(stat -c %a /etc/shadow) -ne 640 ] && echo "WARNING!" 204 205 # Check if readable 206 [ -r /etc/shadow ] && echo "Shadow readable!" 207 208 # List critical files 209 ls -la /etc/passwd /etc/shadow /etc/sudoers 210 ``` 211 212 --- 213 214 ## Vulnerability Detection 215 216 ```bash 217 # World-writable files 218 find / -type f -perm -o+w 2>/dev/null 219 220 # SUID binaries 221 find / -perm -4000 -ls 2>/dev/null 222 223 # World-writable dirs w/o sticky 224 find / -type d -perm -o+w ! -perm -1000 2>/dev/null 225 226 # Files with no owner 227 find / -nouser -o -nogroup 2>/dev/null 228 229 # Find by owner 230 find / -user targetuser 2>/dev/null 231 232 # Find by group 233 find / -group groupname 2>/dev/null 234 ``` 235 236 --- 237 238 ## Exploitation Techniques 239 240 ### Privilege Escalation 241 242 ```bash 243 # Writable cron jobs 244 find /etc/cron* -type f -perm -o+w 2>/dev/null 245 246 # Writable service files 247 find /etc/systemd -perm -o+w 2>/dev/null 248 249 # Config files with credentials 250 find / -name "*.conf" -perm -o+r 2>/dev/null | xargs grep -l "password" 251 ``` 252 253 ### Lateral Movement 254 255 ```bash 256 # Readable home directories 257 find /home -maxdepth 1 -type d -perm -o+rx 258 259 # Service account files 260 find /tmp -user www-data 2>/dev/null 261 262 # Check running processes 263 ps aux | grep targetuser 264 ``` 265 266 --- 267 268 ## Permission Interpretation 269 270 ### Symbolic Format 271 272 | String | Numeric | Description | 273 |:---|:---|:---| 274 | rwxrwxrwx | 777 | All permissions | 275 | rwxr-xr-x | 755 | Owner full, others r+x | 276 | rwx------ | 700 | Owner only | 277 | rw-r--r-- | 644 | Owner r+w, others r | 278 | rw-r----- | 640 | Owner r+w, group r | 279 | rw------- | 600 | Owner r+w only | 280 | r-------- | 400 | Owner read-only | 281 | rwsr-xr-x | 4755 | SUID + 755 | 282 | rwxr-sr-x | 2755 | SGID + 755 | 283 | rwxrwxrwt | 1777 | Sticky + 777 | 284 285 ### File Type Indicators 286 287 - `-` Regular file 288 - `d` Directory 289 - `l` Symbolic link 290 - `s` Socket 291 - `p` Named pipe 292 - `c` Character device 293 - `b` Block device 294 295 --- 296 297 ## User & Group Management 298 299 ```bash 300 # Create user 301 useradd -m -s /bin/bash username 302 303 # Change primary group 304 usermod -g groupname user 305 306 # Add to groups 307 usermod -aG group1,group2 user 308 309 # Display user info 310 id username 311 312 # Create group 313 groupadd groupname 314 315 # Add user to group 316 gpasswd -a username group 317 318 # Remove from group 319 gpasswd -d username group 320 321 # Display groups 322 groups username 323 ``` 324 325 --- 326 327 ## ACLs & Extended Attributes 328 329 ### Access Control Lists 330 331 ```bash 332 # View ACLs 333 getfacl filename 334 335 # Set user ACL 336 setfacl -m u:username:rwx file 337 338 # Set group ACL 339 setfacl -m g:groupname:rx file 340 341 # Remove ACLs 342 setfacl -b file 343 ``` 344 345 ### Extended Attributes 346 347 ```bash 348 # View attributes 349 getfattr -d file 350 351 # Make immutable 352 chattr +i critical_file 353 354 # Make append-only 355 chattr +a /var/log/audit.log 356 357 # View file attributes 358 lsattr file 359 ``` 360 361 ### Capabilities 362 363 ```bash 364 # View capabilities 365 getcap file 366 367 # Set capability (bind to port <1024) 368 setcap 'cap_net_bind_service=+ep' /usr/bin/service 369 370 # Find files with capabilities 371 find / -type f -exec getcap {} \; 2>/dev/null 372 ``` 373 374 --- 375 376 ## Advanced Techniques 377 378 ### Recursive Operations 379 380 ```bash 381 # Set dirs only 382 find /path -type d -exec chmod 750 {} \; 383 384 # Set files only 385 find /path -type f -exec chmod 640 {} \; 386 387 # Change ownership recursively 388 chown -R user:group /path/ 389 ``` 390 391 ### Copy Permissions 392 393 ```bash 394 # Copy permissions 395 chmod --reference=source target 396 397 # Copy ownership 398 chown --reference=source target 399 ``` 400 401 ### Default Permissions (umask) 402 403 ```bash 404 # View current umask 405 umask 406 407 # High security (700/600) 408 umask 077 409 410 # Team environment (750/640) 411 umask 027 412 ``` 413 414 Calculate final permissions: Files = 666 − umask, Dirs = 777 − umask. 415 416 --- 417 418 ## Mount Options 419 420 ```bash 421 # Disable execution 422 mount -o noexec /dev/sda2 /mnt/data 423 424 # Disable SUID 425 mount -o nosuid /dev/sda3 /mnt/untrusted 426 427 # Read-only 428 mount -o ro /dev/sda1 /mnt/readonly 429 ``` 430 431 --- 432 433 ## Forensics & Incident Response 434 435 ### Timeline Analysis 436 437 ```bash 438 # Recent permission changes 439 find /etc -type f -mtime -7 -ls 440 441 # New SUID files 442 find / -perm -4000 -mtime -7 2>/dev/null 443 444 # Permission timeline 445 find / -exec stat -c '%y %U:%G %a %n' {} \; 2>/dev/null | sort 446 ``` 447 448 ### Risk Assessment 449 450 - **Critical:** World-writable system files, readable /etc/shadow 451 - **High:** Incorrect SSH key permissions, SUID vulnerabilities 452 - **Medium:** Weak directory permissions, group access issues 453 454 ### Restore Secure Permissions 455 456 ```bash 457 # Reset critical files 458 chmod 644 /etc/passwd 459 chmod 640 /etc/shadow 460 chmod 440 /etc/sudoers 461 462 # Reset home directory 463 chown -R user:user /home/user/ 464 find /home/user -type d -exec chmod 750 {} \; 465 find /home/user -type f -exec chmod 640 {} \; 466 ``` 467 468 --- 469 470 ## Quick Reference 471 472 ```bash 473 # Add execute 474 chmod +x file 475 476 # Private to owner 477 chmod 600 file 478 479 # Secure config 480 chmod 640 file 481 482 # Shared directory 483 chmod 1775 dir 484 485 # Change owner 486 chown user:group file 487 488 # Recursive change 489 chown -R user:group dir/ 490 ```