In Linux, use chmod to modify file permissions and chown to alter file ownership:
• Change Permissions (chmod): Execute chmod [octal] [filename] (e.g., chmod 644 file.txt gives owner read/write, and group/others read-only). For directories, use chmod 755 directory/.
• Change Ownership (chown): Execute chown [user]:[group] [target] (e.g., chown -R www-data:www-data /var/www/html).
• Security Rule: Never use chmod 777 on production servers. It exposes files to arbitrary modification and execution by unauthorized users.
In Unix and Linux systems administration, file permissions form the first line of defense against unauthorized data modification, sensitive information disclosure, and remote code execution vulnerabilities. Every file and directory on a Linux filesystem carries access control metadata that dictates exactly who can read, modify, or execute its contents.
Whether you are configuring dynamic web applications on a cheap VPS or managing mission-critical enterprise databases on a cheap dedicated server hosting environment, mastering chmod and chown is mandatory for maintaining secure, high-uptime operations.
Understanding the Linux Permission Triad: User, Group, and Others (UGO)
Linux organizes file access into three distinct user classes, commonly abbreviated as UGO:
- User / Owner (u): The specific user account that owns the file. By default, this is the user account that created the file.
- Group (g): A collection of user accounts sharing common access rights. Useful for collaborative teams or shared system service daemons.
- Others (o): Every other user account on the operating system who is neither the owner nor a member of the file’s assigned group.
When running ls -l in a terminal, Linux displays a 10-character string representing file type and permissions (e.g., -rwxr-xr--). The first character indicates the file type (- for regular file, d for directory), followed by three triads representing Owner, Group, and Others.
Read, Write, and Execute: Permission Bits and Octal Values
Each user triad evaluates three basic permission bits:
- Read (r = 4): Allows opening and reading file contents, or listing directory filenames.
- Write (w = 2): Allows modifying, appending, or deleting file contents, or adding/removing files inside a directory.
- Execute (x = 1): Allows running the file as an executable binary/script, or changing directory into it via
cd.
| Octal Mode | Binary Bits | Symbolic | Access Capability | Standard Production Usage Example |
|---|---|---|---|---|
| 755 | 111 101 101 | rwxr-xr-x | Owner: Full; Group/Others: Read & Execute | Web directories (/var/www/html), executable shell scripts |
| 644 | 110 100 100 | rw-r–r– | Owner: Read/Write; Group/Others: Read-Only | Standard static web files (.html, .css, images) |
| 600 | 110 000 000 | rw——- | Owner: Read/Write; Group/Others: No Access | Sensitive credential files (SSH private keys, wp-config.php) |
| 700 | 111 000 000 | rwx—— | Owner: Full; Group/Others: No Access | Private user directories (~/.ssh, private backup archives) |
| 777 (Dangerous) | 111 111 111 | rwxrwxrwx | Everyone: Full Read, Write, and Execute | Never use in production: High security vulnerability |
Changing Permissions with chmod: Absolute Octal vs. Symbolic Syntax
The chmod (change mode) command modifies file mode bits using two distinct syntaxes according to official Linux Kernel documentation:
Octal (Numeric) Mode
Sets the entire permission mask explicitly in three numbers. Fast, unambiguous, and preferred for automated deployment scripts.
chmod 644 index.html chmod 755 /var/www/scripts/
Symbolic Mode
Modifies specific bits using mathematical operators (+, -, =) targeting user classes (u, g, o, a) without altering other bits.
chmod u+x backup.sh chmod g-w shared_doc.txt
Managing Ownership and Group Associations with chown and chgrp
Permissions define what actions are allowed, but the operating system must know which user identity applies. The chown command modifies user ownership and group association simultaneously:
# Change user ownership only chown deployer app.py # Change both user owner and group owner chown www-data:www-data /var/www/html/index.php # Recursively change ownership for an entire directory tree chown -R www-data:www-data /var/www/html/
On production servers, web daemons like Nginx or Apache run under non-root system accounts (such as www-data on Ubuntu/Debian or nginx/apache on RHEL/AlmaLinux). Assigning correct user and group ownership guarantees that web daemons can read templates and write legitimate media uploads without exposing root permissions.
Hardening Web Directories: Recursive Permissions Without 777
A frequent mistake among novice administrators encountering permission errors is executing chmod -R 777 /var/www/html. This reckless action allows any process or compromised script on the server to overwrite application code and inject backdoors, violating OWASP web application security standards.
The secure industry-standard approach uses find to apply distinct permissions to directories (which require execute permissions to browse) and regular files (which do not):
# 1. Set standard ownership to web daemon
sudo chown -R www-data:www-data /var/www/html
# 2. Recursively set directories to 755 (rwxr-xr-x)
sudo find /var/www/html -type d -exec chmod 755 {} \;
# 3. Recursively set regular files to 644 (rw-r--r--)
sudo find /var/www/html -type f -exec chmod 644 {} \;
# 4. Lock down sensitive configuration files to 600 or 640
sudo chmod 600 /var/www/html/wp-config.php
Special Permissions: SUID, SGID, and Sticky Bits Explained
Beyond standard read, write, and execute permissions, Linux incorporates three specialized mode bits for advanced access management:
- SetUID (SUID = 4000): When an executable with SUID is run, it executes with the privileges of the file’s owner rather than the user running it (e.g.,
/usr/bin/passwd). Represented as ansin the owner triad (-rwsr-xr-x). - SetGID (SGID = 2000): On directories, any newly created file inherits the group ownership of the parent directory rather than the primary group of the creating user. Essential for shared team collaboration directories. Represented as an
sin the group triad (drwxrwsr-x). - Sticky Bit (1000): On shared directories (like
/tmp), only the file’s owner or root can delete or rename files within the directory, preventing users from tampering with each other’s files. Represented as atin the others triad (drwxrwxrwt).
Frequently Asked Questions: Linux File Permissions
Production Best Practices: Deploying Secure File Permissions on Production Servers
Maintaining security across production workloads requires disciplined privilege delegation, regular permission auditing, and deployment on hardened server infrastructure. Whether launching web services on Linux web hosting or orchestrating enterprise databases, Onlive Server provides full root access, high-speed NVMe storage, and enterprise security.
Deploy Hardened Linux Server Infrastructure with Full Root Access
Choose secure, production-ready server hosting with full root SSH control, dedicated IP space, enterprise NVMe storage, and 24/7 technical support.
Hardened Linux Cloud VPS
Cost-efficient virtual private servers for modern web applications, microservices, staging environments, and WordPress stacks.
- Full root SSH access & sudo configuration
- High-speed NVMe PCIe SSD storage arrays
- Isolated KVM hypervisor security boundaries
- Automated snapshot backups & instant scaling
Dedicated Linux Bare Metal
100% dedicated hardware for intensive databases, high-concurrency production workloads, and enterprise Kubernetes clusters.
- Dedicated AMD EPYC / Intel Xeon multi-core silicon
- Hardware RAID arrays with enterprise NVMe SSDs
- Unmetered 1 Gbps to 10 Gbps network switch ports
- Full IPMI/KVM out-of-band management control
