What Does CHMOD 755 Mean?
In Unix and Linux operating systems, CHMOD 755 assigns read, write, and execute permissions to the file owner, while granting read and execute permissions to group members and all other users.
Owner (User)
Read + Write + Execute (4+2+1)The file owner has full privileges to view, modify, and run the file or list directory contents.
Group
Read + Execute (4+0+1)Members of the owning group can read and execute/traverse, but cannot modify or delete files.
Others (Public)
Read + Execute (4+0+1)Any other user on the system can view and execute the file, but cannot alter its content.
Why 755 is the Standard for Directories
On Linux web servers (such as Apache or Nginx), directories containing website files must be accessible by the web server service user (often www-data or nginx).
In Linux filesystem design:
- Read (r): Allows listing files inside the directory.
- Execute (x): Allows entering (traversing) the directory to access files within it.
- Write (w): Allows creating, renaming, or deleting files inside the directory.
Setting a directory to 755 ensures visitors and web processes can enter and read directory contents, while preventing unauthorized users from uploading or modifying files directly inside that directory.
File vs Directory Behavior for 755
| Target Type | Owner | Group & Others | Recommended Use Case |
|---|---|---|---|
| Directories | Read, Write, Traverse (rwx) | Read, Traverse (r-x) | Web roots (/var/www/html), public folders |
| Executable Files | Read, Write, Run (rwx) | Read, Run (r-x) | Shell scripts (.sh), binaries in /usr/local/bin |
| Regular Files | Not Recommended | Not Recommended | Use 644 instead for regular document/HTML/CSS files |
How to Apply CHMOD 755
Run the following terminal commands to apply 755 permissions:
chmod 755 /var/www/html/my-folder# Recursively set 755 on all directories only (best practice)find /var/www/html -type d -exec chmod 755 +Security Considerations
While 755 is widely safe for directories and executable scripts, avoid applying 755 to sensitive configuration files containing database passwords or private API keys. For regular files, use 644; for secret files, use 600 or 400.