Labs · Cyber Security
Lab: Organise a Practice Folder on Your Linux Server and Set Safe Permissions – 644 for Files, 755 for Folders
Course: Cyber Security · Chapter 5: Linux Basic Commands
Chapter 5 teaches basic Linux commands; this lab uses them to set safe permissions.
Chala mitrano! In Linux, every file has a lock with three keys: one for the owner, one for the group, one for everyone else. Many websites leak passwords only because a config file was readable by everyone. Today we set the locks correctly on our own practice folder. Ekdum important aahe.
चला मित्रांनो! Linux मध्ये प्रत्येक file ला तीन किल्ल्यांचं कुलूप असतं: एक owner साठी, एक group साठी, एक बाकी सगळ्यांसाठी. बऱ्याच websites चे passwords फक्त config file सगळ्यांना वाचता येत होती म्हणून leak होतात. आज आपण आपल्या practice folder ची कुलपं बरोबर लावणार. एकदम important आहे.
चलो दोस्तों! Linux में हर file पर तीन चाबियों वाला ताला होता है: एक owner के लिए, एक group के लिए, एक बाकी सबके लिए। कई websites के passwords सिर्फ इसलिए leak होते हैं क्योंकि config file सबके लिए readable थी। आज हम अपने practice folder के ताले सही लगाएँगे। बहुत important है।
Suppose we are…
Suppose we are a junior Linux admin at Zoho. A developer copied a website to the server and set everything to 777 "so that it works". That means anyone who gets a small foothold on the server can change every file. Our job is to bring the folder back to the safe standard: 644 for normal files, 755 for folders, and 600 for files with secrets.
Goal of this lab
By the end you will have:
- A practice folder
~/shop-sitewith sub-folders and files. - The skill to read
-rw-r--r--and turn it into a number like644. - Safe permissions set with
chmod, and a secrets file only you can read.
What you need (all free)
- Any Linux you own: a free-tier EC2 server from Lab 4, WSL Ubuntu on Windows (
wsl --installin an admin PowerShell), or an Ubuntu VirtualBox VM. - 25–30 minutes.
Safety and ethics
Practise only inside your own home folder. Never run chmod -R 777 or chmod -R on /, /etc or /var "to fix an error"; it can break the system and open it to attackers.
Steps
-
Open a terminal on your Linux machine and go to your home folder:
cd ~ -
Create the practice structure in one go:
mkdir -p shop-site/css shop-site/images shop-site/config touch shop-site/index.html shop-site/css/style.css shop-site/config/db.env echo "DB_PASSWORD=practice-only-123" > shop-site/config/db.env -
Make it messy on purpose, the way the developer did:
chmod -R 777 shop-site ls -lR shop-siteWhat you should see: every line starts with
-rwxrwxrwx(files) ordrwxrwxrwx(folders). Threerwxgroups mean read, write and execute for owner, group and others. -
Learn the numbers: r = 4, w = 2, x = 1. So
rw-= 6,r--= 4,rwx= 7,r-x= 5.644means owner rw, group r, others r. -
Set all folders to 755 (others can enter and list, but not change):
find shop-site -type d -exec chmod 755 {} \; -
Set all files to 644 (others can read, only the owner can change):
find shop-site -type f -exec chmod 644 {} \; -
Lock the secrets file so only you can read it:
chmod 600 shop-site/config/db.env -
Check the result:
ls -lR shop-site stat -c '%a %n' shop-site shop-site/index.html shop-site/config/db.envWhat you should see:
755 shop-site,644 shop-site/index.htmland600 shop-site/config/db.env. Inls -l, folders showdrwxr-xr-x, files-rw-r--r--, and db.env-rw-------. -
Test it as another user. Create a test user and try to read the secret:
sudo useradd -m testuser sudo -u testuser cat /home/$USER/shop-site/config/db.env sudo -u testuser cat /home/$USER/shop-site/index.htmlWhat you should see:
Permission deniedfor db.env. For index.html you may also see Permission denied, because your home folder itself is private (700or750on many systems); that is an extra layer of safety. -
Find any file that is still writable by everyone (good habit for every server):
find shop-site -perm -o+wWhat you should see: no output, which means nothing is world-writable.
-
Remove the test user:
sudo userdel -r testuser.
Ravindra Bagale's Tip
When a website shows "Permission denied", students jump to chmod 777. Never! Ask two questions: which user runs the web server (nginx, apache), and what does it need: read only? Then 644/755 plus the right owner is enough, 99 percent of the time.
Ravindra Bagale's Tip – मराठी
Website वर "Permission denied" आलं की students लगेच chmod 777 करतात. कधीच नाही! दोन प्रश्न विचारा: web server (nginx, apache) कोणता user चालवतो, आणि त्याला काय हवंय: फक्त read? मग 644/755 आणि योग्य owner पुरेसा आहे, 99 टक्के वेळा.
Ravindra Bagale's Tip – हिंदी
Website पर "Permission denied" आते ही students तुरंत chmod 777 कर देते हैं। कभी नहीं! दो सवाल पूछो: web server (nginx, apache) कौन सा user चलाता है, और उसे क्या चाहिए: सिर्फ read? तो 644/755 और सही owner काफी है, 99 प्रतिशत बार।
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
chmod -R 644 shop-site on everything |
Folders lose x, so nobody can open them, not even you |
Use find -type d for 755 and find -type f for 644 |
chmod 777 to fix an error |
Anyone on the server can change the files | Fix the owner (chown) and use 644/755 |
| Forgetting secrets files | DB passwords readable by every user and process | chmod 600 on .env, keys and config with passwords |
| Running commands outside your home folder by mistake | System files change | Always pwd first; practise only in ~ |
Reading ls -l from right to left |
Wrong idea of who can do what | First char is type, then owner, group, others |
Self-check checklist
0 of 5 done
Try-at-home challenge
What number is -rwxr-x---, and who can do what? Then make a script shop-site/backup.sh that only you can run and edit, but your group can read.
Check your answer
-rwxr-x--- is 750: owner read/write/execute, group read/execute, others nothing. For the script: touch shop-site/backup.sh && chmod 740 shop-site/backup.sh (owner rwx = 7, group r = 4, others 0).
Samjla ka? Folders 755, files 644, secrets 600, and 777 never. Aata pudhe jaauya: Chapter 6 reads the server's logs with grep.