daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

chmod.md (8232B)


      1 ---
      2 title: "chmod & File Permissions"
      3 description: "Linux permission model: symbolic/octal chmod, chown, umask, SUID/SGID/sticky bits explained."
      4 category: linux-it
      5 tags: [linux, permissions, cli]
      6 tools: [chmod, chown, umask]
      7 difficulty: beginner
      8 updated: "2026-08-09"
      9 source: "repo:Linux/chmod-cheatsheet.pdf"
     10 ---
     11 
     12 # chmod & File Permissions
     13 
     14 Linux file permissions reference — chmod, chown, special bits, ACLs and the security angles for ethical hacking.
     15 
     16 ---
     17 
     18 ## Basic Concepts
     19 
     20 ### Permission Types
     21 
     22 - **r (read)** — Value 4: view file contents
     23 - **w (write)** — Value 2: modify files
     24 - **x (execute)** — Value 1: run programs
     25 
     26 ### User Categories
     27 
     28 - **u (user/owner)** — file's owner
     29 - **g (group)** — group members
     30 - **o (others)** — all other users
     31 - **a (all)** — all three categories
     32 
     33 ### Viewing Permissions
     34 
     35 ```bash
     36 # List with permissions
     37 ls -l
     38 
     39 # Show hidden files
     40 ls -la
     41 
     42 # Numeric permissions
     43 stat -c '%a %n' filename
     44 ```
     45 
     46 ---
     47 
     48 ## CHMOD Syntax
     49 
     50 ### Symbolic Mode
     51 
     52 Format: `chmod [who][operator][perms] file`
     53 
     54 **Operators:**
     55 - `+` Add permissions
     56 - `-` Remove permissions
     57 - `=` Set exact permissions
     58 
     59 ```bash
     60 # Add execute for owner
     61 chmod u+x script.sh
     62 
     63 # Remove write from group/others
     64 chmod go-w config.conf
     65 
     66 # Set exact permissions
     67 chmod u=rw,go=r file.txt
     68 
     69 # Add execute for all
     70 chmod a+x tool
     71 ```
     72 
     73 ### Numeric Mode
     74 
     75 Format: `chmod [numeric] file` — calculate by adding values: r(4) + w(2) + x(1).
     76 
     77 ### Common Permission Sets
     78 
     79 | Num | Sym | Usage |
     80 |:---|:---|:---|
     81 | 777 | rwxrwxrwx | DANGER! Full access |
     82 | 755 | rwxr-xr-x | Public executables |
     83 | 750 | rwxr-x--- | Group-shared tools |
     84 | 700 | rwx------ | Private scripts |
     85 | 644 | rw-r--r-- | Public config files |
     86 | 640 | rw-r----- | Restricted configs |
     87 | 600 | rw------- | Private data/keys |
     88 | 400 | r-------- | Read-only secrets |
     89 
     90 ---
     91 
     92 ## CHOWN Syntax
     93 
     94 ```bash
     95 # Change user owner
     96 chown username file
     97 
     98 # Change user and group
     99 chown user:group file
    100 
    101 # Change only group
    102 chown :groupname file
    103 
    104 # Recursive
    105 chown -R user:group dir/
    106 
    107 # Follow symlinks
    108 chown -L user:group link
    109 
    110 # No dereference symlinks
    111 chown -h user:group link
    112 
    113 # Reference file ownership
    114 chown --reference=ref target
    115 
    116 # Numeric UID/GID
    117 chown 1000:1000 file
    118 ```
    119 
    120 ---
    121 
    122 ## Special Permissions
    123 
    124 ### SUID (4000)
    125 
    126 Runs with the owner's permissions.
    127 
    128 ```bash
    129 # Set SUID
    130 chmod 4755 binary   # rwsr-xr-x
    131 
    132 # Find SUID files
    133 find / -perm -4000 2>/dev/null
    134 ```
    135 
    136 > **Security risk —** SUID files owned by root are privilege-escalation vectors.
    137 
    138 ### SGID (2000)
    139 
    140 - Files: run with group permissions
    141 - Directories: new files inherit the group
    142 
    143 ```bash
    144 # Set SGID
    145 chmod 2755 file   # rwxr-sr-x
    146 chmod 2775 dir/   # rwxrwsr-x
    147 
    148 # Find SGID files
    149 find / -perm -2000 2>/dev/null
    150 ```
    151 
    152 ### Sticky Bit (1000)
    153 
    154 Users can only delete their own files.
    155 
    156 ```bash
    157 # Set sticky bit
    158 chmod 1777 /tmp/   # rwxrwxrwt
    159 
    160 # Find sticky directories
    161 find / -type d -perm -1000 2>/dev/null
    162 ```
    163 
    164 ---
    165 
    166 ## Security Configurations
    167 
    168 ### Critical Files
    169 
    170 | File | Owner:Group | Perms |
    171 |:---|:---|:---|
    172 | /etc/passwd | root:root | 644 |
    173 | /etc/shadow | root:shadow | 640 |
    174 | /etc/sudoers | root:root | 440 |
    175 | ~/.ssh/id_rsa | user:user | 600 |
    176 | ~/.ssh/authorized_keys | user:user | 600 |
    177 
    178 ### Secure SSH Keys
    179 
    180 ```bash
    181 chown user:user ~/.ssh/id_rsa
    182 chmod 600 ~/.ssh/id_rsa
    183 chmod 700 ~/.ssh/
    184 ```
    185 
    186 ### Web Application
    187 
    188 ```bash
    189 # Set ownership
    190 chown -R www-data:www-data /var/www/
    191 
    192 # Directory permissions
    193 chmod 750 /var/www/html/
    194 
    195 # File permissions
    196 find /var/www/ -type f -exec chmod 640 {} \;
    197 ```
    198 
    199 ### Check Critical Files
    200 
    201 ```bash
    202 # Verify shadow file perms
    203 [ $(stat -c %a /etc/shadow) -ne 640 ] && echo "WARNING!"
    204 
    205 # Check if readable
    206 [ -r /etc/shadow ] && echo "Shadow readable!"
    207 
    208 # List critical files
    209 ls -la /etc/passwd /etc/shadow /etc/sudoers
    210 ```
    211 
    212 ---
    213 
    214 ## Vulnerability Detection
    215 
    216 ```bash
    217 # World-writable files
    218 find / -type f -perm -o+w 2>/dev/null
    219 
    220 # SUID binaries
    221 find / -perm -4000 -ls 2>/dev/null
    222 
    223 # World-writable dirs w/o sticky
    224 find / -type d -perm -o+w ! -perm -1000 2>/dev/null
    225 
    226 # Files with no owner
    227 find / -nouser -o -nogroup 2>/dev/null
    228 
    229 # Find by owner
    230 find / -user targetuser 2>/dev/null
    231 
    232 # Find by group
    233 find / -group groupname 2>/dev/null
    234 ```
    235 
    236 ---
    237 
    238 ## Exploitation Techniques
    239 
    240 ### Privilege Escalation
    241 
    242 ```bash
    243 # Writable cron jobs
    244 find /etc/cron* -type f -perm -o+w 2>/dev/null
    245 
    246 # Writable service files
    247 find /etc/systemd -perm -o+w 2>/dev/null
    248 
    249 # Config files with credentials
    250 find / -name "*.conf" -perm -o+r 2>/dev/null | xargs grep -l "password"
    251 ```
    252 
    253 ### Lateral Movement
    254 
    255 ```bash
    256 # Readable home directories
    257 find /home -maxdepth 1 -type d -perm -o+rx
    258 
    259 # Service account files
    260 find /tmp -user www-data 2>/dev/null
    261 
    262 # Check running processes
    263 ps aux | grep targetuser
    264 ```
    265 
    266 ---
    267 
    268 ## Permission Interpretation
    269 
    270 ### Symbolic Format
    271 
    272 | String | Numeric | Description |
    273 |:---|:---|:---|
    274 | rwxrwxrwx | 777 | All permissions |
    275 | rwxr-xr-x | 755 | Owner full, others r+x |
    276 | rwx------ | 700 | Owner only |
    277 | rw-r--r-- | 644 | Owner r+w, others r |
    278 | rw-r----- | 640 | Owner r+w, group r |
    279 | rw------- | 600 | Owner r+w only |
    280 | r-------- | 400 | Owner read-only |
    281 | rwsr-xr-x | 4755 | SUID + 755 |
    282 | rwxr-sr-x | 2755 | SGID + 755 |
    283 | rwxrwxrwt | 1777 | Sticky + 777 |
    284 
    285 ### File Type Indicators
    286 
    287 - `-` Regular file
    288 - `d` Directory
    289 - `l` Symbolic link
    290 - `s` Socket
    291 - `p` Named pipe
    292 - `c` Character device
    293 - `b` Block device
    294 
    295 ---
    296 
    297 ## User & Group Management
    298 
    299 ```bash
    300 # Create user
    301 useradd -m -s /bin/bash username
    302 
    303 # Change primary group
    304 usermod -g groupname user
    305 
    306 # Add to groups
    307 usermod -aG group1,group2 user
    308 
    309 # Display user info
    310 id username
    311 
    312 # Create group
    313 groupadd groupname
    314 
    315 # Add user to group
    316 gpasswd -a username group
    317 
    318 # Remove from group
    319 gpasswd -d username group
    320 
    321 # Display groups
    322 groups username
    323 ```
    324 
    325 ---
    326 
    327 ## ACLs & Extended Attributes
    328 
    329 ### Access Control Lists
    330 
    331 ```bash
    332 # View ACLs
    333 getfacl filename
    334 
    335 # Set user ACL
    336 setfacl -m u:username:rwx file
    337 
    338 # Set group ACL
    339 setfacl -m g:groupname:rx file
    340 
    341 # Remove ACLs
    342 setfacl -b file
    343 ```
    344 
    345 ### Extended Attributes
    346 
    347 ```bash
    348 # View attributes
    349 getfattr -d file
    350 
    351 # Make immutable
    352 chattr +i critical_file
    353 
    354 # Make append-only
    355 chattr +a /var/log/audit.log
    356 
    357 # View file attributes
    358 lsattr file
    359 ```
    360 
    361 ### Capabilities
    362 
    363 ```bash
    364 # View capabilities
    365 getcap file
    366 
    367 # Set capability (bind to port <1024)
    368 setcap 'cap_net_bind_service=+ep' /usr/bin/service
    369 
    370 # Find files with capabilities
    371 find / -type f -exec getcap {} \; 2>/dev/null
    372 ```
    373 
    374 ---
    375 
    376 ## Advanced Techniques
    377 
    378 ### Recursive Operations
    379 
    380 ```bash
    381 # Set dirs only
    382 find /path -type d -exec chmod 750 {} \;
    383 
    384 # Set files only
    385 find /path -type f -exec chmod 640 {} \;
    386 
    387 # Change ownership recursively
    388 chown -R user:group /path/
    389 ```
    390 
    391 ### Copy Permissions
    392 
    393 ```bash
    394 # Copy permissions
    395 chmod --reference=source target
    396 
    397 # Copy ownership
    398 chown --reference=source target
    399 ```
    400 
    401 ### Default Permissions (umask)
    402 
    403 ```bash
    404 # View current umask
    405 umask
    406 
    407 # High security (700/600)
    408 umask 077
    409 
    410 # Team environment (750/640)
    411 umask 027
    412 ```
    413 
    414 Calculate final permissions: Files = 666 − umask, Dirs = 777 − umask.
    415 
    416 ---
    417 
    418 ## Mount Options
    419 
    420 ```bash
    421 # Disable execution
    422 mount -o noexec /dev/sda2 /mnt/data
    423 
    424 # Disable SUID
    425 mount -o nosuid /dev/sda3 /mnt/untrusted
    426 
    427 # Read-only
    428 mount -o ro /dev/sda1 /mnt/readonly
    429 ```
    430 
    431 ---
    432 
    433 ## Forensics & Incident Response
    434 
    435 ### Timeline Analysis
    436 
    437 ```bash
    438 # Recent permission changes
    439 find /etc -type f -mtime -7 -ls
    440 
    441 # New SUID files
    442 find / -perm -4000 -mtime -7 2>/dev/null
    443 
    444 # Permission timeline
    445 find / -exec stat -c '%y %U:%G %a %n' {} \; 2>/dev/null | sort
    446 ```
    447 
    448 ### Risk Assessment
    449 
    450 - **Critical:** World-writable system files, readable /etc/shadow
    451 - **High:** Incorrect SSH key permissions, SUID vulnerabilities
    452 - **Medium:** Weak directory permissions, group access issues
    453 
    454 ### Restore Secure Permissions
    455 
    456 ```bash
    457 # Reset critical files
    458 chmod 644 /etc/passwd
    459 chmod 640 /etc/shadow
    460 chmod 440 /etc/sudoers
    461 
    462 # Reset home directory
    463 chown -R user:user /home/user/
    464 find /home/user -type d -exec chmod 750 {} \;
    465 find /home/user -type f -exec chmod 640 {} \;
    466 ```
    467 
    468 ---
    469 
    470 ## Quick Reference
    471 
    472 ```bash
    473 # Add execute
    474 chmod +x file
    475 
    476 # Private to owner
    477 chmod 600 file
    478 
    479 # Secure config
    480 chmod 640 file
    481 
    482 # Shared directory
    483 chmod 1775 dir
    484 
    485 # Change owner
    486 chown user:group file
    487 
    488 # Recursive change
    489 chown -R user:group dir/
    490 ```