MYTHOSAI

Linux security / PRACTICAL GUIDE

Understand Linux file permissions with a safe example

Practise owner, group and other permissions on a disposable file instead of changing system directories.

Before you start

Any ordinary Linux shell account; no sudo needed for this exercise.

Decode a permission string

The familiar rwx groups represent read, write and execute permissions for the owner, group and everyone else. The first character in ls -l identifies the file type. Directory execute permission means permission to traverse/search the directory, not execute it like a programme.

Permissions work alongside ownership, access-control lists, mount options and other security controls. A short permission string is not the entire access decision on every system.

Create a disposable exercise

bash
practice_dir=$(mktemp -d)
printf 'A harmless practice note\n' > "$practice_dir/note.txt"
ls -l "$practice_dir/note.txt"

The temporary directory avoids overwriting an existing note. Keep the variable in this shell for the remaining commands.

Restrict the file to its owner

bash
chmod 600 "$practice_dir/note.txt"
ls -l "$practice_dir/note.txt"

The numeric values come from read 4, write 2 and execute 1. Mode 600 gives the owner read and write while removing group and other access. A directory normally needs execute permission for useful traversal, so blindly applying file modes to directories can break access.

Practise a symbolic change

bash
chmod u-w "$practice_dir/note.txt"
ls -l "$practice_dir/note.txt"
chmod u+w "$practice_dir/note.txt"

This removes and restores the owner's write bit on your test file. A process with sufficient privilege can bypass ordinary access restrictions, so this is not a guarantee against an administrator or a compromised root account.

Verify understanding

Explain the before-and-after permission string in your own words. Check ownership as well as the mode. Remove the exact practice file and directory when finished:

bash
rm -- "$practice_dir/note.txt"
rmdir -- "$practice_dir"

Common mistakes

chmod 777 grants broad access and is not a standard fix for application errors. Recursive permission changes over /etc, a home directory or a shared application tree can create serious faults. If an application cannot read a file, identify the actual service user and minimum necessary access first.

Apply the lesson carefully

A private SSH key usually needs tighter access than a public web asset. A shared directory may need group-based access rather than everyone-writable permissions. Practise the model here, then follow the application's documented ownership and permission requirements for real changes.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.