Loading network utility...
Loading network utility...
A complete engineering guide to Linux discretionary access control, permission bits, octal calculation, and hardening file security on web servers.
Run live checks and calculations directly on LotsofNetwork.
In Unix-based operating systems, every filesystem object (regular files, directories, sockets, symbolic links, and device nodes) is governed by an ownership and access control triplet: User (owner), Group, and Others.
Each of these three roles has three discrete permission flags: Read (r), Write (w), and Execute (x). When displayed in the terminal with 'ls -l', permissions appear as a 10-character string such as '-rwxr-xr-x', where the leading character represents the file type ('-' for regular files, 'd' for directories).
The octal system represents three binary bits (2^2, 2^1, 2^0) with numeric values 4, 2, and 1. Combining these values allows any permission set to be expressed as a single digit from 0 to 7:
• Read (r) = 4 (binary 100) • Write (w) = 2 (binary 010) • Execute (x) = 1 (binary 001)
Adding these weights produces standard modes: 7 (4+2+1 = rwx), 6 (4+2 = rw-), 5 (4+1 = r-x), and 4 (4 = r--). A mode like 755 translates directly to Owner=7 (rwx), Group=5 (r-x), Others=5 (r-x).
| Octal | Binary | Symbolic | Description |
|---|---|---|---|
| 755 | 111 101 101 | -rwxr-xr-x | Standard executable/directory mode |
| 644 | 110 100 100 | -rw-r--r-- | Standard static web asset/file mode |
| 600 | 110 000 000 | -rw------- | Private credentials (SSH keys, .env) |
| 700 | 111 000 000 | -rwx------ | Private directory (~/.ssh) |
| 777 | 111 111 111 | -rwxrwxrwx | Unrestricted access (Extreme security risk) |
In addition to standard user/group/other bits, Linux supports three special execution bits represented by a 4-digit octal prefix:
1. SUID (Set User ID, 4000): When set on an executable file, the process executes with the privileges of the file owner rather than the calling user (e.g. /usr/bin/passwd).
2. SGID (Set Group ID, 2000): In directories, files created within inherit the group ownership of the directory rather than the primary group of the creating user. Critical for collaborative folders.
3. Sticky Bit (1000): Indicated by a trailing 't' in symbolic mode (e.g. 1777 on /tmp). Prevents non-root users from deleting or renaming files owned by other users within shared directories.
Running chmod -R 777 on web applications allows web server processes or attackers to overwrite executable scripts, leading directly to remote code execution (RCE). Use 755 for directories and 644 for files.
Quick answers to common questions on this topic.
High-speed, zero-cost engineering tools built for network diagnostics and developer workflows.
Beautify, minify, validate & inspect JSON tree
Encode & decode text, files, and images
Unix epoch to date & global timezone converter
UUID v4 & UUID v7 generator & timestamp decoder
Convert cURL commands to 7 languages instantly
Detect browser, OS, engine, and Client Hints telemetry