πŸ›‘οΈ
Security

Setting File Permissions Correctly on Linux Hosting

πŸ“… 8 October 2026 ✏️ 8 October 2026 ⏱ 5 min leestijd

Learn how to correctly set file permissions on Linux hosting with chmod and chown, so your website runs securely and error-free.

Incorrect file permissions are a common cause of 500 errors, security vulnerabilities, and non-working uploads. For most websites, a simple rule of thumb applies: folders get permission 755 and files 644, while configuration files with sensitive data often require stricter settings. In this article, you’ll learn exactly what permissions mean, which values to use where, and how to adjust them via SSH or Plesk.

What are file permissions

On Linux, every file and folder has three types of rights: read (r), write (w), and execute (x). These rights apply separately to the owner, the group, and other users. The combination is usually displayed as a three-digit number, for example 755 or 644. Each digit is the sum of read (4), write (2), and execute (1) for the owner, group, and others respectively.

For example, 755 means the owner is allowed to do everything (7 = 4+2+1), while the group and others can only read and execute (5 = 4+1). For folders, execute rights are needed to navigate into them; for files, it determines whether a script may be executed.

Folder755File644Config600

Correct values per file type

Not every file needs the same permissions. A good basic breakdown:

  • Folders: 755 (owner can do everything, others can read and open)
  • Regular files such as HTML, CSS, and images: 644
  • PHP scripts: usually 644, sometimes 755 if the script itself needs to be executable
  • Configuration files with passwords or database details: 600, so only the owner can read and write
  • Upload folders that need to be written to by CMS systems: sometimes 775, but preferably not broader than necessary

Avoid 777 on files or folders. That gives everyone on the system write access and is a major security risk, even if it seems like a quick fix for an error message.

πŸ’‘ Tip: Never use permissions as a quick fix for a 500 error without checking the cause. The problem often lies with an incorrect file owner, not the permission itself.

Adjusting permissions with chmod and chown

Via SSH, you adjust permissions with the chmod command, and the owner with chown. A few practical examples:

1

Connect via SSH

Log in to your server with SSH and navigate to your website’s folder, for example with cd httpdocs.

2

Set folders to 755

Use the command find . -type d -exec chmod 755 {} ; to recursively set all folders to 755.

3

Set files to 644

Use find . -type f -exec chmod 644 {} ; to set all files to 644.

4

Check owner and group

Use chown username:group filename to set the correct owner, so your hosting account and the web server don’t conflict with each other.

5

Use Plesk as an alternative

If you’d rather avoid SSH commands, you can right-click a file or folder in Plesk’s file manager and choose to change permissions. This can be found in the Plesk control panel, which is available by default with web hosting at Tandata.

Common mistakes and security

The most common mistake is applying 777 everywhere because a plugin or upload isn’t working. This temporarily solves the problem but makes the site vulnerable to abuse, as malicious actors can then also overwrite files. Instead, first check whether the file owner is correct.

Another common mistake is accidentally applying file permissions to folders or vice versa via an incorrect find command, causing folders to become inaccessible (missing execute bit) or scripts to no longer run.

Also pay attention when it comes to email configuration and credentials: files with passwords, API keys, or database settings should not be readable by other users on the system. This is just as important as correct DNS and SPF configuration for business email, which Tandata’s email hosting takes into account for a good security score.

If you get stuck or are unsure about the correct settings for your CMS, you can search further in the knowledge base or contact support via WhatsApp, ticket, or email, even at night.

Frequently Asked Questions

What’s the difference between chmod 644 and 755?

644 gives the owner read and write rights and others only read rights, without execute rights. 755 gives the owner full rights and others read and execute rights, which is needed to be able to open folders.

Why doesn’t my upload function work despite correct permissions?

This is often due to the owner of the folder rather than the permission itself. Check with ls -la whether the folder belongs to the correct user account, and adjust this with chown.

Is 777 ever a good solution?

No, 777 gives everyone on the system full rights and is almost never needed. Use 755 or 775 instead and check the file’s owner.

Can I also adjust permissions without SSH?

Yes, you can set permissions per file or folder via the file manager in Plesk without using the command line.

Do I need to adjust permissions after switching to a new hosting provider?

Sometimes, because file ownership can change during migration. When switching to Tandata, this is taken into account during the transfer, but it’s always wise to check this after migration.

Conclusion

Correct file permissions are essential for a secure and stable website. Keep 755 for folders, 644 for files, and stricter values such as 600 for configuration files with sensitive data. Avoid 777 and, if problems arise, first check the file’s owner before adjusting permissions.

View web hosting β†’

Was dit artikel nuttig?