Ravindra BagaleCourses & study guides Track your progress

Labs · Cyber Security

Lab: Organise a Practice Folder on Your Linux Server and Set Safe Permissions – 644 for Files, 755 for Folders

Beginner30 minAny Linux: EC2, WSL Ubuntu or a VirtualBox VM · Terminal

Course: Cyber Security · Chapter 5: Linux Basic Commands

Chapter 5 teaches basic Linux commands; this lab uses them to set safe permissions.

Chala mitrano! In Linux, every file has a lock with three keys: one for the owner, one for the group, one for everyone else. Many websites leak passwords only because a config file was readable by everyone. Today we set the locks correctly on our own practice folder. Ekdum important aahe.

Suppose we are…

Suppose we are a junior Linux admin at Zoho. A developer copied a website to the server and set everything to 777 "so that it works". That means anyone who gets a small foothold on the server can change every file. Our job is to bring the folder back to the safe standard: 644 for normal files, 755 for folders, and 600 for files with secrets.

Goal of this lab

By the end you will have:

  • A practice folder ~/shop-site with sub-folders and files.
  • The skill to read -rw-r--r-- and turn it into a number like 644.
  • Safe permissions set with chmod, and a secrets file only you can read.

What you need (all free)

  • Any Linux you own: a free-tier EC2 server from Lab 4, WSL Ubuntu on Windows (wsl --install in an admin PowerShell), or an Ubuntu VirtualBox VM.
  • 25–30 minutes.

Safety and ethics

Practise only inside your own home folder. Never run chmod -R 777 or chmod -R on /, /etc or /var "to fix an error"; it can break the system and open it to attackers.

Steps

  1. Open a terminal on your Linux machine and go to your home folder:

    cd ~
    
  2. Create the practice structure in one go:

    mkdir -p shop-site/css shop-site/images shop-site/config
    touch shop-site/index.html shop-site/css/style.css shop-site/config/db.env
    echo "DB_PASSWORD=practice-only-123" > shop-site/config/db.env
    
  3. Make it messy on purpose, the way the developer did:

    chmod -R 777 shop-site
    ls -lR shop-site
    

    What you should see: every line starts with -rwxrwxrwx (files) or drwxrwxrwx (folders). Three rwx groups mean read, write and execute for owner, group and others.

  4. Learn the numbers: r = 4, w = 2, x = 1. So rw- = 6, r-- = 4, rwx = 7, r-x = 5. 644 means owner rw, group r, others r.

  5. Set all folders to 755 (others can enter and list, but not change):

    find shop-site -type d -exec chmod 755 {} \;
    
  6. Set all files to 644 (others can read, only the owner can change):

    find shop-site -type f -exec chmod 644 {} \;
    
  7. Lock the secrets file so only you can read it:

    chmod 600 shop-site/config/db.env
    
  8. Check the result:

    ls -lR shop-site
    stat -c '%a %n' shop-site shop-site/index.html shop-site/config/db.env
    

    What you should see: 755 shop-site, 644 shop-site/index.html and 600 shop-site/config/db.env. In ls -l, folders show drwxr-xr-x, files -rw-r--r--, and db.env -rw-------.

  9. Test it as another user. Create a test user and try to read the secret:

    sudo useradd -m testuser
    sudo -u testuser cat /home/$USER/shop-site/config/db.env
    sudo -u testuser cat /home/$USER/shop-site/index.html
    

    What you should see: Permission denied for db.env. For index.html you may also see Permission denied, because your home folder itself is private (700 or 750 on many systems); that is an extra layer of safety.

  10. Find any file that is still writable by everyone (good habit for every server):

    find shop-site -perm -o+w
    

    What you should see: no output, which means nothing is world-writable.

  11. Remove the test user: sudo userdel -r testuser.

Ravindra Bagale's Tip

When a website shows "Permission denied", students jump to chmod 777. Never! Ask two questions: which user runs the web server (nginx, apache), and what does it need: read only? Then 644/755 plus the right owner is enough, 99 percent of the time.

Common mistakes

Mistake What happens Fix
chmod -​R 644 shop-​site on everything Folders lose x, so nobody can open them, not even you Use find -type d for 755 and find -type f for 644
chmod 777 to fix an error Anyone on the server can change the files Fix the owner (chown) and use 644/755
Forgetting secrets files DB passwords readable by every user and process chmod 600 on .env, keys and config with passwords
Running commands outside your home folder by mistake System files change Always pwd first; practise only in ~
Reading ls -l from right to left Wrong idea of who can do what First char is type, then owner, group, others

Self-check checklist

0 of 5 done

Try-at-home challenge

What number is -rwxr-x---, and who can do what? Then make a script shop-site/backup.sh that only you can run and edit, but your group can read.

Check your answer

-rwxr-x--- is 750: owner read/write/execute, group read/execute, others nothing. For the script: touch shop-site/backup.sh && chmod 740 shop-site/backup.sh (owner rwx = 7, group r = 4, others 0).

Samjla ka? Folders 755, files 644, secrets 600, and 777 never. Aata pudhe jaauya: Chapter 6 reads the server's logs with grep.