# find वापरून files शोधा

Source: https://ravindrabagale.com/mr/cyber/part-02/ch06-linux-advanced-commands/6-2-finding-files-find.html
Language: mr (Marathi with English technical terms)

find नाव, type, size, वेळ आणि permissions वरून files शोधतो. आधी फक्त results पाहा; delete किंवा permissions बदलणारे options नंतर गरज असेल तेव्हाच वापरा.

find /var/www -name "*.html"                 # by name
find / -iname "nginx.conf" 2>/dev/null       # case-insensitive, hide permission errors
find /var/log -type f -size +100M            # files bigger than 100 MB
find /tmp -type f -mtime +7                  # modified more than 7 days ago
find /tmp -type f -mtime +7 -delete          # ...and delete them
find /var/www/html -type d -exec chmod 755 {} \;   # run a command on each result
find . -type f -name "*.log" | xargs ls -lh

Examples वाचूया

-name "*.html" नावावरून, -iname case दुर्लक्षित करून शोधतो.

-type f files; -type d directories.

-size +100M size filter; find च्या M unit/rounding semantics लक्षात घ्या.

-mtime +7 modification age 24-hour periods मध्ये तपासतो; -mmin -60 मागच्या 60 मिनिटांत बदललेल्या files.

-delete matching files delete करतो. आधी त्याशिवाय preview अनिवार्य सवय ठेवा.

-exec ... {} \; प्रत्येक result वर command चालवतो. दिलेलं chmod example प्रत्यक्ष permissions बदलतं.

-perm -o+w others-write bit असलेल्या files शोधतो. 2>/dev/null errors लपवतो, त्यामुळे access नसलेली ठिकाणं results मध्ये नसू शकतात.

Source मधला find ... | xargs ls -lh साध्या filenames साठी example आहे; spaces/newlines असलेल्या नावांसाठी सुरक्षित delimiter handling लागते. नावावरून id_rsa* शोधल्याने private key contents वाचण्याची किंवा share करण्याची गरज नसते.

find / -perm -o+w -type f 2>/dev/null | grep -v /proc     # world-writable files
find /var/www -name "*.php" -mmin -60                      # PHP files changed in last hour
find / -name "id_rsa*" 2>/dev/null                         # stray private keys

Security मध्ये उपयोग

Defenders बदललेल्या web files, चुकीच्या writable permissions आणि अनवधानाने ठेवलेल्या keys शोधतात. Incident time जवळ बदललेल्या files साठी -mmin/-mtime उपयोगी आहेत. Timestamp हा एक clue आहे; तो एकटाच अंतिम पुरावा नाही.

Practice

/etc मधल्या मागील सात दिवसांत बदललेल्या .conf files शोधा. मग system वर 50 MB पेक्षा मोठ्या files ची read-only list पाहा. या exercise ला -delete लागत नाही.

रवींद्र बागले यांची tip

find सोबत -delete किंवा -exec rm लगेच वापरू नका. आधी matching paths पाहा. योग्य folder आणि filter आहेत याची खात्री झाल्यावरच आवश्यक बदल करा.
