CHMOD & CHOWN
UNDERSTANDING PERMISSIONS#
-rwxrwxrwx Format: [type][user][group][others] Type: - Regular file d Directory l Symbolic link b Block device c Character device Permissions: r Read (4) w Write (2) x Execute (1) - None (0)
NUMERIC (OCTAL) MODE#
chmod 755 file # rwxr-xr-x chmod 644 file # rw-r--r-- chmod 700 file # rwx------ chmod 600 file # rw------- chmod 777 file # rwxrwxrwx (dangerous!) chmod 666 file # rw-rw-rw- # Calculate: User + Group + Others # 7 = 4+2+1 = rwx # 6 = 4+2 = rw- # 5 = 4+1 = r-x # 4 = 4 = r-- # 3 = 2+1 = -wx # 2 = 2 = -w- # 1 = 1 = --x # 0 = 0 = ---
COMMON PERMISSION SETS#
chmod 755 script.sh # Executable script chmod 644 file.txt # Regular file chmod 600 secret.key # Private file chmod 700 ~/.ssh # SSH directory chmod 600 ~/.ssh/* # SSH keys chmod 400 private.pem # Read-only private key chmod 755 directory/ # Standard directory chmod 777 /tmp # Temp directory (sticky needed)
SYMBOLIC MODE#
# Format: chmod [who][operator][permissions] # Who: u User (owner) g Group o Others a All (user, group, others) # Operator: + Add permission - Remove permission = Set exact permission # Permissions: r Read w Write x Execute X Execute only if directory or already executable s SUID/SGID t Sticky bit
SYMBOLIC MODE EXAMPLES#
chmod u+x file # Add execute for user chmod g+w file # Add write for group chmod o-r file # Remove read from others chmod a+r file # Add read for all chmod u+x,g+r file # Multiple changes chmod u=rwx,g=rx,o=r file # Set exact permissions chmod go= file # Remove all permissions from group/others chmod +x file # Add execute for all (same as a+x) chmod -x file # Remove execute from all # Directory execute (enter) chmod +X file # Add execute only if directory
RECURSIVE CHANGES#
chmod -R 755 directory/ # Recursive change
chmod -R u+rX directory/ # Recursive, X for directories only
# Files and directories different permissions
find dir/ -type f -exec chmod 644 {} \;
find dir/ -type d -exec chmod 755 {} \;
# Or with chmod
chmod -R a=rX,u+w directory/ # dirs: 755, files: 644
SPECIAL PERMISSIONS#
# SUID (Set User ID) - Run as owner chmod u+s file # Symbolic chmod 4755 file # Numeric (4xxx) # Example: /usr/bin/passwd runs as root # SGID (Set Group ID) - Run as group / inherit group chmod g+s file # Symbolic chmod 2755 directory # Numeric (2xxx) # Files created in directory inherit group # Sticky Bit - Only owner can delete chmod +t directory # Symbolic chmod 1777 directory # Numeric (1xxx) # Example: /tmp uses sticky bit # Combined special permissions chmod 4755 file # SUID + rwxr-xr-x chmod 2755 directory # SGID + rwxr-xr-x chmod 1777 directory # Sticky + rwxrwxrwx chmod 6755 file # SUID + SGID + rwxr-xr-x
VIEWING SPECIAL PERMISSIONS#
-rwsr-xr-x SUID (s in user execute) -rwxr-sr-x SGID (s in group execute) drwxrwxrwt Sticky (t in others execute) -rwSr--r-- SUID without execute (S = no underlying x)
CHOWN - CHANGE OWNERSHIP#
chown user file # Change owner chown user:group file # Change owner and group chown :group file # Change group only chown user: file # Change owner, group to user's default # Recursive chown -R user:group dir/ # Recursive ownership change # Reference file chown --reference=ref.txt file # Copy ownership from ref.txt # Common examples chown root:root /etc/passwd chown www-data:www-data /var/www chown -R $USER:$USER ~/projects
CHGRP - CHANGE GROUP#
chgrp group file # Change group chgrp -R group directory # Recursive chgrp --reference=ref file # Copy group from reference
UMASK#
# Umask defines DEFAULT permissions for new files # Default permissions: files=666, directories=777 # Actual = Default - Umask umask # Show current umask umask 022 # Set umask # Common umask values: # 022 = files: 644, dirs: 755 (default) # 027 = files: 640, dirs: 750 # 077 = files: 600, dirs: 700 # Set in ~/.bashrc for permanent change echo "umask 027" >> ~/.bashrc
ACCESS CONTROL LISTS (ACL)#
# View ACLs getfacl file # Set ACLs setfacl -m u:username:rwx file # User permission setfacl -m g:groupname:rx file # Group permission setfacl -m o::r file # Others permission setfacl -m d:u:username:rwx dir/ # Default ACL for new files # Remove ACLs setfacl -x u:username file # Remove specific setfacl -b file # Remove all ACLs # Recursive setfacl -R -m u:username:rx dir/
PRACTICAL EXAMPLES#
# Web server files
chown -R www-data:www-data /var/www/html
find /var/www/html -type d -exec chmod 755 {} \;
find /var/www/html -type f -exec chmod 644 {} \;
# SSH security
chmod 700 ~/.ssh
chmod 600 ~/.ssh/id_rsa
chmod 644 ~/.ssh/id_rsa.pub
chmod 600 ~/.ssh/authorized_keys
chmod 644 ~/.ssh/config
# Script executable
chmod +x script.sh
chmod 755 /usr/local/bin/myscript
# Secure config file
chmod 600 config.ini
chown root:root /etc/sensitive.conf
# Shared directory (SGID)
mkdir /shared
chown :developers /shared
chmod 2775 /shared
# Temp-style directory (sticky)
mkdir /project/tmp
chmod 1777 /project/tmp
# Remove all permissions for others
chmod o= sensitive_file
# Make file immutable (even root can't modify)
chattr +i important_file # Set immutable
chattr -i important_file # Remove immutable
lsattr file # View attributes
SECURITY RECOMMENDATIONS#
# Home directory chmod 700 ~ # or 750 if needed # System files chmod 644 /etc/passwd # World readable chmod 640 /etc/shadow # Root and shadow group only chmod 600 /etc/ssh/sshd_config # Private keys chmod 400 *.pem # Read-only for owner chmod 600 ~/.ssh/id_* # SSH private keys # Web application chmod 750 /var/www/app # Owner/group access chmod 640 /var/www/app/config.php # Avoid chmod 777 # Never use this! chmod 666 # Avoid for security
QUICK REFERENCE#
Permission Numeric Files Directories --------- ------- ----- ----------- rwx 7 Full access Full access rw- 6 Read/write List/modify r-x 5 Read/execute List/enter r-- 4 Read only List only -wx 3 Write/execute Modify/enter -w- 2 Write only Modify only --x 1 Execute only Enter only --- 0 No access No access Common: 755 = rwxr-xr-x Standard directories, executables 644 = rw-r--r-- Standard files 700 = rwx------ Private directories 600 = rw------- Private files
CHMOD & CHOWN CHEATSHEET
========================
Source: https://cheatsheet.johlem.net
UNDERSTANDING PERMISSIONS
-------------------------
-rwxrwxrwx Format: [type][user][group][others]
Type:
- Regular file
d Directory
l Symbolic link
b Block device
c Character device
Permissions:
r Read (4)
w Write (2)
x Execute (1)
- None (0)
NUMERIC (OCTAL) MODE
--------------------
chmod 755 file # rwxr-xr-x
chmod 644 file # rw-r--r--
chmod 700 file # rwx------
chmod 600 file # rw-------
chmod 777 file # rwxrwxrwx (dangerous!)
chmod 666 file # rw-rw-rw-
# Calculate: User + Group + Others
# 7 = 4+2+1 = rwx
# 6 = 4+2 = rw-
# 5 = 4+1 = r-x
# 4 = 4 = r--
# 3 = 2+1 = -wx
# 2 = 2 = -w-
# 1 = 1 = --x
# 0 = 0 = ---
COMMON PERMISSION SETS
----------------------
chmod 755 script.sh # Executable script
chmod 644 file.txt # Regular file
chmod 600 secret.key # Private file
chmod 700 ~/.ssh # SSH directory
chmod 600 ~/.ssh/* # SSH keys
chmod 400 private.pem # Read-only private key
chmod 755 directory/ # Standard directory
chmod 777 /tmp # Temp directory (sticky needed)
SYMBOLIC MODE
-------------
# Format: chmod [who][operator][permissions]
# Who:
u User (owner)
g Group
o Others
a All (user, group, others)
# Operator:
+ Add permission
- Remove permission
= Set exact permission
# Permissions:
r Read
w Write
x Execute
X Execute only if directory or already executable
s SUID/SGID
t Sticky bit
SYMBOLIC MODE EXAMPLES
----------------------
chmod u+x file # Add execute for user
chmod g+w file # Add write for group
chmod o-r file # Remove read from others
chmod a+r file # Add read for all
chmod u+x,g+r file # Multiple changes
chmod u=rwx,g=rx,o=r file # Set exact permissions
chmod go= file # Remove all permissions from group/others
chmod +x file # Add execute for all (same as a+x)
chmod -x file # Remove execute from all
# Directory execute (enter)
chmod +X file # Add execute only if directory
RECURSIVE CHANGES
-----------------
chmod -R 755 directory/ # Recursive change
chmod -R u+rX directory/ # Recursive, X for directories only
# Files and directories different permissions
find dir/ -type f -exec chmod 644 {} \;
find dir/ -type d -exec chmod 755 {} \;
# Or with chmod
chmod -R a=rX,u+w directory/ # dirs: 755, files: 644
SPECIAL PERMISSIONS
-------------------
# SUID (Set User ID) - Run as owner
chmod u+s file # Symbolic
chmod 4755 file # Numeric (4xxx)
# Example: /usr/bin/passwd runs as root
# SGID (Set Group ID) - Run as group / inherit group
chmod g+s file # Symbolic
chmod 2755 directory # Numeric (2xxx)
# Files created in directory inherit group
# Sticky Bit - Only owner can delete
chmod +t directory # Symbolic
chmod 1777 directory # Numeric (1xxx)
# Example: /tmp uses sticky bit
# Combined special permissions
chmod 4755 file # SUID + rwxr-xr-x
chmod 2755 directory # SGID + rwxr-xr-x
chmod 1777 directory # Sticky + rwxrwxrwx
chmod 6755 file # SUID + SGID + rwxr-xr-x
VIEWING SPECIAL PERMISSIONS
---------------------------
-rwsr-xr-x SUID (s in user execute)
-rwxr-sr-x SGID (s in group execute)
drwxrwxrwt Sticky (t in others execute)
-rwSr--r-- SUID without execute (S = no underlying x)
CHOWN - CHANGE OWNERSHIP
------------------------
chown user file # Change owner
chown user:group file # Change owner and group
chown :group file # Change group only
chown user: file # Change owner, group to user's default
# Recursive
chown -R user:group dir/ # Recursive ownership change
# Reference file
chown --reference=ref.txt file # Copy ownership from ref.txt
# Common examples
chown root:root /etc/passwd
chown www-data:www-data /var/www
chown -R $USER:$USER ~/projects
CHGRP - CHANGE GROUP
--------------------
chgrp group file # Change group
chgrp -R group directory # Recursive
chgrp --reference=ref file # Copy group from reference
UMASK
-----
# Umask defines DEFAULT permissions for new files
# Default permissions: files=666, directories=777
# Actual = Default - Umask
umask # Show current umask
umask 022 # Set umask
# Common umask values:
# 022 = files: 644, dirs: 755 (default)
# 027 = files: 640, dirs: 750
# 077 = files: 600, dirs: 700
# Set in ~/.bashrc for permanent change
echo "umask 027" >> ~/.bashrc
ACCESS CONTROL LISTS (ACL)
--------------------------
# View ACLs
getfacl file
# Set ACLs
setfacl -m u:username:rwx file # User permission
setfacl -m g:groupname:rx file # Group permission
setfacl -m o::r file # Others permission
setfacl -m d:u:username:rwx dir/ # Default ACL for new files
# Remove ACLs
setfacl -x u:username file # Remove specific
setfacl -b file # Remove all ACLs
# Recursive
setfacl -R -m u:username:rx dir/
PRACTICAL EXAMPLES
------------------
# Web server files
chown -R www-data:www-data /var/www/html
find /var/www/html -type d -exec chmod 755 {} \;
find /var/www/html -type f -exec chmod 644 {} \;
# SSH security
chmod 700 ~/.ssh
chmod 600 ~/.ssh/id_rsa
chmod 644 ~/.ssh/id_rsa.pub
chmod 600 ~/.ssh/authorized_keys
chmod 644 ~/.ssh/config
# Script executable
chmod +x script.sh
chmod 755 /usr/local/bin/myscript
# Secure config file
chmod 600 config.ini
chown root:root /etc/sensitive.conf
# Shared directory (SGID)
mkdir /shared
chown :developers /shared
chmod 2775 /shared
# Temp-style directory (sticky)
mkdir /project/tmp
chmod 1777 /project/tmp
# Remove all permissions for others
chmod o= sensitive_file
# Make file immutable (even root can't modify)
chattr +i important_file # Set immutable
chattr -i important_file # Remove immutable
lsattr file # View attributes
SECURITY RECOMMENDATIONS
------------------------
# Home directory
chmod 700 ~ # or 750 if needed
# System files
chmod 644 /etc/passwd # World readable
chmod 640 /etc/shadow # Root and shadow group only
chmod 600 /etc/ssh/sshd_config
# Private keys
chmod 400 *.pem # Read-only for owner
chmod 600 ~/.ssh/id_* # SSH private keys
# Web application
chmod 750 /var/www/app # Owner/group access
chmod 640 /var/www/app/config.php
# Avoid
chmod 777 # Never use this!
chmod 666 # Avoid for security
QUICK REFERENCE
---------------
Permission Numeric Files Directories
--------- ------- ----- -----------
rwx 7 Full access Full access
rw- 6 Read/write List/modify
r-x 5 Read/execute List/enter
r-- 4 Read only List only
-wx 3 Write/execute Modify/enter
-w- 2 Write only Modify only
--x 1 Execute only Enter only
--- 0 No access No access
Common:
755 = rwxr-xr-x Standard directories, executables
644 = rw-r--r-- Standard files
700 = rwx------ Private directories
600 = rw------- Private files
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.