How to Change File Permissions in Linux: Complete chmod, chown & Octal Notation Guide

Change File Permissions

⚡ Quick Answer: How to Change File Permissions and Ownership in Linux?

In Linux, use chmod to modify file permissions and chown to alter file ownership:

• Change Permissions (chmod): Execute chmod [octal] [filename] (e.g., chmod 644 file.txt gives owner read/write, and group/others read-only). For directories, use chmod 755 directory/.

• Change Ownership (chown): Execute chown [user]:[group] [target] (e.g., chown -R www-data:www-data /var/www/html).

• Security Rule: Never use chmod 777 on production servers. It exposes files to arbitrary modification and execution by unauthorized users.

In Unix and Linux systems administration, file permissions form the first line of defense against unauthorized data modification, sensitive information disclosure, and remote code execution vulnerabilities. Every file and directory on a Linux filesystem carries access control metadata that dictates exactly who can read, modify, or execute its contents.

Whether you are configuring dynamic web applications on a cheap VPS or managing mission-critical enterprise databases on a cheap dedicated server hosting environment, mastering chmod and chown is mandatory for maintaining secure, high-uptime operations.

Understanding the Linux Permission Triad: User, Group, and Others (UGO)

Linux organizes file access into three distinct user classes, commonly abbreviated as UGO:

  • User / Owner (u): The specific user account that owns the file. By default, this is the user account that created the file.
  • Group (g): A collection of user accounts sharing common access rights. Useful for collaborative teams or shared system service daemons.
  • Others (o): Every other user account on the operating system who is neither the owner nor a member of the file’s assigned group.

When running ls -l in a terminal, Linux displays a 10-character string representing file type and permissions (e.g., -rwxr-xr--). The first character indicates the file type (- for regular file, d for directory), followed by three triads representing Owner, Group, and Others.

Read, Write, and Execute: Permission Bits and Octal Values

Each user triad evaluates three basic permission bits:

  • Read (r = 4): Allows opening and reading file contents, or listing directory filenames.
  • Write (w = 2): Allows modifying, appending, or deleting file contents, or adding/removing files inside a directory.
  • Execute (x = 1): Allows running the file as an executable binary/script, or changing directory into it via cd.

Octal Mode Binary Bits Symbolic Access Capability Standard Production Usage Example
755 111 101 101 rwxr-xr-x Owner: Full; Group/Others: Read & Execute Web directories (/var/www/html), executable shell scripts
644 110 100 100 rw-r–r– Owner: Read/Write; Group/Others: Read-Only Standard static web files (.html, .css, images)
600 110 000 000 rw——- Owner: Read/Write; Group/Others: No Access Sensitive credential files (SSH private keys, wp-config.php)
700 111 000 000 rwx—— Owner: Full; Group/Others: No Access Private user directories (~/.ssh, private backup archives)
777 (Dangerous) 111 111 111 rwxrwxrwx Everyone: Full Read, Write, and Execute Never use in production: High security vulnerability

Changing Permissions with chmod: Absolute Octal vs. Symbolic Syntax

The chmod (change mode) command modifies file mode bits using two distinct syntaxes according to official Linux Kernel documentation:

Octal (Numeric) Mode

Sets the entire permission mask explicitly in three numbers. Fast, unambiguous, and preferred for automated deployment scripts.

chmod 644 index.html
chmod 755 /var/www/scripts/

Symbolic Mode

Modifies specific bits using mathematical operators (+, -, =) targeting user classes (u, g, o, a) without altering other bits.

chmod u+x backup.sh
chmod g-w shared_doc.txt

Managing Ownership and Group Associations with chown and chgrp

Permissions define what actions are allowed, but the operating system must know which user identity applies. The chown command modifies user ownership and group association simultaneously:

# Change user ownership only
chown deployer app.py

# Change both user owner and group owner
chown www-data:www-data /var/www/html/index.php

# Recursively change ownership for an entire directory tree
chown -R www-data:www-data /var/www/html/

On production servers, web daemons like Nginx or Apache run under non-root system accounts (such as www-data on Ubuntu/Debian or nginx/apache on RHEL/AlmaLinux). Assigning correct user and group ownership guarantees that web daemons can read templates and write legitimate media uploads without exposing root permissions.

Hardening Web Directories: Recursive Permissions Without 777

A frequent mistake among novice administrators encountering permission errors is executing chmod -R 777 /var/www/html. This reckless action allows any process or compromised script on the server to overwrite application code and inject backdoors, violating OWASP web application security standards.

The secure industry-standard approach uses find to apply distinct permissions to directories (which require execute permissions to browse) and regular files (which do not):

# 1. Set standard ownership to web daemon
sudo chown -R www-data:www-data /var/www/html

# 2. Recursively set directories to 755 (rwxr-xr-x)
sudo find /var/www/html -type d -exec chmod 755 {} \;

# 3. Recursively set regular files to 644 (rw-r--r--)
sudo find /var/www/html -type f -exec chmod 644 {} \;

# 4. Lock down sensitive configuration files to 600 or 640
sudo chmod 600 /var/www/html/wp-config.php

Special Permissions: SUID, SGID, and Sticky Bits Explained

Beyond standard read, write, and execute permissions, Linux incorporates three specialized mode bits for advanced access management:

  • SetUID (SUID = 4000): When an executable with SUID is run, it executes with the privileges of the file’s owner rather than the user running it (e.g., /usr/bin/passwd). Represented as an s in the owner triad (-rwsr-xr-x).
  • SetGID (SGID = 2000): On directories, any newly created file inherits the group ownership of the parent directory rather than the primary group of the creating user. Essential for shared team collaboration directories. Represented as an s in the group triad (drwxrwsr-x).
  • Sticky Bit (1000): On shared directories (like /tmp), only the file’s owner or root can delete or rename files within the directory, preventing users from tampering with each other’s files. Represented as a t in the others triad (drwxrwxrwt).

Frequently Asked Questions: Linux File Permissions

Why should I never use chmod 777 on web server files?
chmod 777 grants every user and process on the server the ability to read, modify, delete, and execute files. If an attacker discovers an upload form or vulnerability, they can execute arbitrary shell scripts immediately and compromise the entire operating system.
What are the recommended file and directory permissions for WordPress?
Directories should be set to 755 (rwxr-xr-x), regular files to 644 (rw-r–r–), and sensitive configuration files like wp-config.php and .htaccess locked down to 600 or 640 to prevent unauthorized credential reading.
What is the difference between chmod and chown in Linux?
chmod (change mode) modifies what actions are permitted (read, write, execute) for the owner, group, and others. chown (change owner) modifies who owns the file and which group it belongs to.
How do I recursively change permissions for only directories or only files?
Use the find utility: run find /path -type d -exec chmod 755 {} + for directories, and find /path -type f -exec chmod 644 {} + for regular files. This prevents stripping executable bits from directories or granting executable permissions to files.
What are SUID, SGID, and Sticky Bit permissions in Linux?
These are special permission bits. SUID (4000) executes binaries with file-owner privileges. SGID (2000) forces new files to inherit parent directory group ownership. Sticky Bit (1000) prevents users from deleting files owned by others in shared directories like /tmp.

Production Best Practices: Deploying Secure File Permissions on Production Servers

Maintaining security across production workloads requires disciplined privilege delegation, regular permission auditing, and deployment on hardened server infrastructure. Whether launching web services on Linux web hosting or orchestrating enterprise databases, Onlive Server provides full root access, high-speed NVMe storage, and enterprise security.

Deploy Hardened Linux Server Infrastructure with Full Root Access

Choose secure, production-ready server hosting with full root SSH control, dedicated IP space, enterprise NVMe storage, and 24/7 technical support.

Agile Cloud Scalability

Hardened Linux Cloud VPS

Cost-efficient virtual private servers for modern web applications, microservices, staging environments, and WordPress stacks.

  • Full root SSH access & sudo configuration
  • High-speed NVMe PCIe SSD storage arrays
  • Isolated KVM hypervisor security boundaries
  • Automated snapshot backups & instant scaling

Deploy Hardened Linux VPS

Enterprise Bare Metal

Dedicated Linux Bare Metal

100% dedicated hardware for intensive databases, high-concurrency production workloads, and enterprise Kubernetes clusters.

  • Dedicated AMD EPYC / Intel Xeon multi-core silicon
  • Hardware RAID arrays with enterprise NVMe SSDs
  • Unmetered 1 Gbps to 10 Gbps network switch ports
  • Full IPMI/KVM out-of-band management control

Deploy Dedicated Server

✔ 99.9% Network & Hardware Uptime SLA
✔ Full Root & Sudo Administrative Access
✔ 24/7/365 On-Site Technical Linux Support
✔ Pure Enterprise NVMe SSD Storage