🎯 Goal

Understand how Linux handles files and permissions at a fundamental level, and build safe, repeatable habits around destructive commands and log inspection.


✅ What I Did

Files & Directories

  • Created directory structures using brace expansion

  • Created multiple files at once using touch and numeric ranges

  • Practiced navigating with absolute vs relative paths

  • Used pwd intentionally before running destructive commands

Permissions & Ownership

  • Studied ownership vs permissions (user, group, others)

  • Learned how Linux evaluates permissions (owner → group → others)

  • Understood chmod in octal as bit math, not memorization

  • Created files with restricted permissions (e.g. 640, 600)

  • Explored why 777 is almost always a bad idea, and when it is (rarely) acceptable

  • Learned that a file can be executable but not readable

Safety & Destructive Commands

  • Broke down rm -rf * into its components and risks

  • Understood how shell expansion (*) works

  • Learned safer directory cleanup with:

      find . -mindepth 1 -delete
    
  • Understood why filenames starting with - break commands and how to handle them safely

Logs & Inspection

  • Explored /var/log and identified relevant log files

  • Focused on authentication and SSH-related logs

  • Used grep and grep -R to search log entries

  • Redirected grep output to files for later analysis


✅ What Worked

  • Octal permissions finally clicked once viewed as bit-level logic

  • Using absolute paths removed ambiguity and prevented mistakes

  • find -delete felt safer and more intentional than rm -rf *

  • grep proved extremely effective for log inspection

  • Redirecting output made investigations repeatable


❌ What Didn’t

  • Accidentally created files with problematic names (e.g. starting with -)

  • Initially confused file ownership with delete permissions

  • Over-trusted relative paths during early experiments


🧠 Key Takeaways

  • Linux permissions are deterministic, not mystical

  • Directories control deletion, not files

  • Ownership selects which rule set applies; permissions define the rules

  • Absolute paths remove dangerous assumptions

  • 777 removes security boundaries instead of fixing problems

  • Logs are the ground truth of system activity


❓ Questions

  • When should find -delete be preferred over rm -rf in scripts?

  • Which log files matter most first during incident response?

  • At what point do permission misconfigurations become real security vulnerabilities?