← All cheat sheets

CHMOD & CHOWN

Plain-text reference · 7 KB. Read it, search it (Ctrl-F) or print it.

UNDERSTANDING PERMISSIONS#

-rwxrwxrwx   Format: [type][user][group][others]

Type:
-   Regular file
d   Directory
l   Symbolic link
b   Block device
c   Character device

Permissions:
r   Read    (4)
w   Write   (2)
x   Execute (1)
-   None    (0)

NUMERIC (OCTAL) MODE#

chmod 755 file      # rwxr-xr-x
chmod 644 file      # rw-r--r--
chmod 700 file      # rwx------
chmod 600 file      # rw-------
chmod 777 file      # rwxrwxrwx (dangerous!)
chmod 666 file      # rw-rw-rw-

# Calculate: User + Group + Others
# 7 = 4+2+1 = rwx
# 6 = 4+2   = rw-
# 5 = 4+1   = r-x
# 4 = 4     = r--
# 3 = 2+1   = -wx
# 2 = 2     = -w-
# 1 = 1     = --x
# 0 = 0     = ---

COMMON PERMISSION SETS#

chmod 755 script.sh     # Executable script
chmod 644 file.txt      # Regular file
chmod 600 secret.key    # Private file
chmod 700 ~/.ssh        # SSH directory
chmod 600 ~/.ssh/*      # SSH keys
chmod 400 private.pem   # Read-only private key
chmod 755 directory/    # Standard directory
chmod 777 /tmp          # Temp directory (sticky needed)

SYMBOLIC MODE#

# Format: chmod [who][operator][permissions]

# Who:
u   User (owner)
g   Group
o   Others
a   All (user, group, others)

# Operator:
+   Add permission
-   Remove permission
=   Set exact permission

# Permissions:
r   Read
w   Write
x   Execute
X   Execute only if directory or already executable
s   SUID/SGID
t   Sticky bit

SYMBOLIC MODE EXAMPLES#

chmod u+x file          # Add execute for user
chmod g+w file          # Add write for group
chmod o-r file          # Remove read from others
chmod a+r file          # Add read for all
chmod u+x,g+r file      # Multiple changes
chmod u=rwx,g=rx,o=r file   # Set exact permissions
chmod go= file          # Remove all permissions from group/others
chmod +x file           # Add execute for all (same as a+x)
chmod -x file           # Remove execute from all

# Directory execute (enter)
chmod +X file           # Add execute only if directory

RECURSIVE CHANGES#

chmod -R 755 directory/     # Recursive change
chmod -R u+rX directory/    # Recursive, X for directories only

# Files and directories different permissions
find dir/ -type f -exec chmod 644 {} \;
find dir/ -type d -exec chmod 755 {} \;

# Or with chmod
chmod -R a=rX,u+w directory/   # dirs: 755, files: 644

SPECIAL PERMISSIONS#

# SUID (Set User ID) - Run as owner
chmod u+s file          # Symbolic
chmod 4755 file         # Numeric (4xxx)
# Example: /usr/bin/passwd runs as root

# SGID (Set Group ID) - Run as group / inherit group
chmod g+s file          # Symbolic
chmod 2755 directory    # Numeric (2xxx)
# Files created in directory inherit group

# Sticky Bit - Only owner can delete
chmod +t directory      # Symbolic
chmod 1777 directory    # Numeric (1xxx)
# Example: /tmp uses sticky bit

# Combined special permissions
chmod 4755 file         # SUID + rwxr-xr-x
chmod 2755 directory    # SGID + rwxr-xr-x
chmod 1777 directory    # Sticky + rwxrwxrwx
chmod 6755 file         # SUID + SGID + rwxr-xr-x

VIEWING SPECIAL PERMISSIONS#

-rwsr-xr-x    SUID (s in user execute)
-rwxr-sr-x    SGID (s in group execute)
drwxrwxrwt    Sticky (t in others execute)
-rwSr--r--    SUID without execute (S = no underlying x)

CHOWN - CHANGE OWNERSHIP#

chown user file             # Change owner
chown user:group file       # Change owner and group
chown :group file           # Change group only
chown user: file            # Change owner, group to user's default

# Recursive
chown -R user:group dir/    # Recursive ownership change

# Reference file
chown --reference=ref.txt file  # Copy ownership from ref.txt

# Common examples
chown root:root /etc/passwd
chown www-data:www-data /var/www
chown -R $USER:$USER ~/projects

CHGRP - CHANGE GROUP#

chgrp group file            # Change group
chgrp -R group directory    # Recursive
chgrp --reference=ref file  # Copy group from reference

UMASK#

# Umask defines DEFAULT permissions for new files
# Default permissions: files=666, directories=777
# Actual = Default - Umask

umask                   # Show current umask
umask 022               # Set umask

# Common umask values:
# 022 = files: 644, dirs: 755 (default)
# 027 = files: 640, dirs: 750
# 077 = files: 600, dirs: 700

# Set in ~/.bashrc for permanent change
echo "umask 027" >> ~/.bashrc

ACCESS CONTROL LISTS (ACL)#

# View ACLs
getfacl file

# Set ACLs
setfacl -m u:username:rwx file      # User permission
setfacl -m g:groupname:rx file      # Group permission
setfacl -m o::r file                # Others permission
setfacl -m d:u:username:rwx dir/    # Default ACL for new files

# Remove ACLs
setfacl -x u:username file          # Remove specific
setfacl -b file                     # Remove all ACLs

# Recursive
setfacl -R -m u:username:rx dir/

PRACTICAL EXAMPLES#

# Web server files
chown -R www-data:www-data /var/www/html
find /var/www/html -type d -exec chmod 755 {} \;
find /var/www/html -type f -exec chmod 644 {} \;

# SSH security
chmod 700 ~/.ssh
chmod 600 ~/.ssh/id_rsa
chmod 644 ~/.ssh/id_rsa.pub
chmod 600 ~/.ssh/authorized_keys
chmod 644 ~/.ssh/config

# Script executable
chmod +x script.sh
chmod 755 /usr/local/bin/myscript

# Secure config file
chmod 600 config.ini
chown root:root /etc/sensitive.conf

# Shared directory (SGID)
mkdir /shared
chown :developers /shared
chmod 2775 /shared

# Temp-style directory (sticky)
mkdir /project/tmp
chmod 1777 /project/tmp

# Remove all permissions for others
chmod o= sensitive_file

# Make file immutable (even root can't modify)
chattr +i important_file    # Set immutable
chattr -i important_file    # Remove immutable
lsattr file                 # View attributes

SECURITY RECOMMENDATIONS#

# Home directory
chmod 700 ~                 # or 750 if needed

# System files
chmod 644 /etc/passwd       # World readable
chmod 640 /etc/shadow       # Root and shadow group only
chmod 600 /etc/ssh/sshd_config

# Private keys
chmod 400 *.pem             # Read-only for owner
chmod 600 ~/.ssh/id_*       # SSH private keys

# Web application
chmod 750 /var/www/app      # Owner/group access
chmod 640 /var/www/app/config.php

# Avoid
chmod 777                   # Never use this!
chmod 666                   # Avoid for security

QUICK REFERENCE#

Permission  Numeric  Files           Directories
---------   -------  -----           -----------
rwx         7        Full access     Full access
rw-         6        Read/write      List/modify
r-x         5        Read/execute    List/enter
r--         4        Read only       List only
-wx         3        Write/execute   Modify/enter
-w-         2        Write only      Modify only
--x         1        Execute only    Enter only
---         0        No access       No access

Common:
755 = rwxr-xr-x    Standard directories, executables
644 = rw-r--r--    Standard files
700 = rwx------    Private directories
600 = rw-------    Private files

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.