What does chmod 777 mean?
chmod 777 gives every user on the system the right to read, modify and execute a file. On a directory, anyone may create, rename and delete files inside it, including files owned by others. The three sevens stand for owner, group and everyone else, and 7 is the sum of read (4), write (2) and execute (1).
The command often shows up in forums as a quick fix for "Permission denied". It really does make the error go away, because nobody is locked out anymore. That is exactly the problem:
- Every process can write. On a server with several websites, a hacked WordPress in a neighboring subscription can drop or modify files in your directory.
- Injected code goes unnoticed. Uploads, caches and plugin directories with 777 are a popular place to hide web shells.
- Some software refuses to work. SSH ignores an
authorized_keysfile with overly open permissions, suPHP and some PHP handlers abort on world-writable files. - The real cause remains. Usually the owner is wrong, for example after an upload as root.
chownfixes that, notchmod.
Honest assessment: 777 is practically never the right answer on a web server. The only common exception is shared temp directories like /tmp, and those also have the sticky bit (1777) so that nobody can delete other users' files.
What to do instead?
- Check who owns the files and which user PHP runs as:
ls -laandps -o user= -p $(pgrep -f php-fpm | head -1). - Fix the owner:
chown user:group file. If PHP runs as the owner of the files (the default in Plesk with PHP-FPM), 644 and 755 are enough, even for uploads. - If a second account needs write access, put both into a shared group and use 664 or 775, for team directories with setgid (2775).
- For individual additional users, set ACLs selectively:
setfacl -m u:www-data:rx directory.
How the numbers work
Each digit of the octal value is the sum of 4 (read), 2 (write) and 1 (execute). From left to right, the three digits apply to owner, group and others. So 6 means read and write, 5 means read and execute.
On directories the permissions mean something different: read allows listing the contents, write allows creating, renaming and deleting files inside, and execute allows entering it (that is, cd and accessing files inside). A directory without x is therefore practically locked, even if r is set.
An optional fourth digit in front stands for the special bits: 4 setuid (program runs as its owner), 2 setgid (on directories: new files inherit the group), 1 sticky bit (on directories: only the owner of a file may delete it). In the symbolic notation they appear as s or t in place of the x, as an uppercase S or T if the x itself is missing.
Common values and what they are for
| Value | Symbolic | Use case |
|---|---|---|
| 600 | -rw------- | Private files: SSH keys, .my.cnf, wp-config.php (when PHP runs as the owner). |
| 640 | -rw-r----- | Configuration a group needs to read, such as wp-config.php with the web server group, or log files. |
| 644 | -rw-r--r-- | Default for files in web space: HTML, CSS, images, PHP files. |
| 664 | -rw-rw-r-- | Files edited by several users of the same group. |
| 700 | drwx------ | Private directories and scripts, such as ~/.ssh or a backup script. |
| 750 | drwxr-x--- | Directory only the owner and group may enter. Used by Plesk for httpdocs (group psaserv). |
| 755 | drwxr-xr-x | Default for directories and executable programs. |
| 775 | drwxrwxr-x | Shared directory for a group, where all members can write. |
| 777 | drwxrwxrwx | Everyone may do everything. Practically never right on web servers, see below. |
| 1777 | drwxrwxrwt | Shared temp directory like /tmp: everyone can create files, but only delete their own. |
| 2775 | drwxrwsr-x | Team directory: new files inherit the group of the directory. |
| 4755 | -rwsr-xr-x | Program runs with the owner's privileges, such as /usr/bin/passwd. Not for your own scripts. |
Recommendations for WordPress and Plesk
- Directories 755, files 644. That is enough for WordPress including updates and uploads, as long as PHP runs as the owner of the files.
- wp-config.php 600 or 640. 600 if PHP runs as the owner (Plesk with PHP-FPM). 640 if a web server process needs to read it through the group.
- Ownership in Plesk: files and subdirectories belong to the subscription's system user with the group
psacln. Thehttpdocsdirectory itself has the grouppsaservand permissions 750, so that nginx and Apache can enter it. Do not change this withchown -Ron the whole subscription. - No 777 for wp-content/uploads or caches. If WordPress cannot write there, the owner is almost always wrong.
Reset permissions in the WordPress directory of a Plesk subscription (adjust path and user):
find /var/www/vhosts/example.com/httpdocs -mindepth 1 -exec chown sub-user:psacln {} +
find /var/www/vhosts/example.com/httpdocs -type d -exec chmod 755 {} +
find /var/www/vhosts/example.com/httpdocs -type f -exec chmod 644 {} +
chmod 600 /var/www/vhosts/example.com/httpdocs/wp-config.phpPlesk also ships its own repair tool that resets owners and permissions of a subscription to the Plesk defaults: plesk repair fs example.com. It asks before every change.