755-rwxr-xr-x
Web Directories / Executable Scripts
Owner has full control; group & others can read and execute.
644-rw-r--r--
Web Files / HTML / CSS / Docs
Owner can read & write; group & others read-only.
700-rwx------
Private Folders & User Scripts
Owner has full control; no access for anyone else.
600-rw-------
SSH Keys / Secret Configurations
Owner can read & write; blocked for all others.
775-rwxrwxr-x
Shared Team Web Folders
Owner & group have full access; others read/execute.
664-rw-rw-r--
Shared Team Content Files
Owner & group can read/write; others read-only.
400-r--------
Read-Only Private Key Files
Owner read-only; highly restrictive key security.
500-r-x------
Read & Execute Only Scripts
Owner can read and run script, but cannot modify.
777-rwxrwxrwx
Full Access (High Security Hazard)
Everyone can read, write, and execute. Avoid on web servers!
How to Choose the Right Permission
When managing Linux servers, follow the Principle of Least Privilege: give users and processes only the minimum access necessary to perform their work.
- For website directories: Use
755 so web servers can enter and read folders. - For website regular files: Use
644 so files can be served but not modified externally. - For secret environment files: Use
600 to prevent other users from reading passwords. - For executable scripts: Use
755 (public) or 700 (private).