5.5 Permissions: r, w, x, chmod and chown
Ha topic khup important aahe, lakshat theva. "403 Forbidden" aani "Permission denied" chya bahutek problems cha mool ithe aahe – aani privilege escalation che anek raste pan.
Every file has an owner (u), a group (g) and others (o). Each can have read (r), write (w) and execute (x) permission.
| Permission | On a file | On a directory | Value |
|---|---|---|---|
| r (read) | View contents | List files (ls) |
4 |
| w (write) | Modify contents | Create/delete files inside | 2 |
| x (execute) | Run as program/script | Enter the directory (cd) |
1 |
Numeric (octal) notation — add the values for each of user, group, others:
| Octal | Symbolic | Meaning | Typical use |
|---|---|---|---|
| 777 | rwxrwxrwx |
Everyone everything | Avoid — insecure |
| 755 | rwxr-xr-x |
Owner full, others read+enter | Directories, scripts, web folders |
| 750 | rwxr-x--- |
Owner full, group read, others nothing | Private app directories |
| 700 | rwx------ |
Only owner | ~/.ssh directory |
| 644 | rw-r--r-- |
Owner write, others read | Web files (HTML, CSS), configs |
| 640 | rw-r----- |
Owner write, group read | Config with passwords (wp-config.php) |
| 600 | rw------- |
Only owner read/write | ~/.ssh/authorized_keys |
| 400 | r-------- |
Only owner read | .pem private key |
chmod 755 deploy.sh # numeric
chmod u+x deploy.sh # symbolic: add execute for user
chmod go-w file.txt # remove write from group and others
chmod -R 755 /var/www/html # recursive
chmod 400 mykey.pem # required before using an SSH key
sudo chown nginx:nginx /usr/share/nginx/html/index.html # owner:group
sudo chown -R www-data:www-data /var/www/html # Ubuntu web user
sudo chown -R apache:apache /var/www/html # AL2023/CentOS Apache user
Safe web permissions
A common, safe pattern: directories 755, files 644, owned by your login user or the web-server user. Set them in one go:
sudo find /var/www/html -type d -exec chmod 755 {} \; and sudo find /var/www/html -type f -exec chmod 644 {} \;
Special permissions – SUID, SGID and sticky bit:
| Bit | Octal | Effect | Example |
|---|---|---|---|
| SUID | 4000 | Program runs with the owner's privileges | /usr/bin/passwd (-rwsr-xr-x) |
| SGID | 2000 | Runs with group privileges; new files inherit the folder's group | Shared project folders |
| Sticky bit | 1000 | Only the owner can delete their files in a shared folder | /tmp (drwxrwxrwt) |
ls -l /usr/bin/passwd # note the 's' in rws
find / -perm -4000 -type f 2>/dev/null # list all SUID programs (a privesc check)
ls -ld /tmp # note the 't' at the end
Why this matters for security
A SUID-root program that can run a shell or write files is a classic privilege escalation path (GTFOBins lists them). World-writable files owned by root, readable private keys and 777 web folders are the other classics. Least privilege (किमान आवश्यक अधिकार) at the file level stops many attacks.
Ravindra Bagale's Tip
Error aala ki khup students laghech chmod -R 777 kartat. Kadhihi nahi! Te fakt khara problem lapavta aani security hole ughadta. Aadhi ls -l ne baghaa konta user access maagto, mag tyalach tevdhach access dya. Ekdum simple niyam.
Practice task
Convert to octal: rwxr-x---, rw-r--r--, r--------. Create a script, make it executable only for yourself, and list all SUID files on your server.