Skip to content

chmod 4755: setuid: a program that runs as its owner

Runs in your browser — nothing you paste leaves this page. How we prove that

chmod calculator playground

Examples
Permission bits
Read
Write
Exec
Owner
Group
Other
Enter a value

The matrix, octal and symbolic fields all stay in sync — edit any one and the others follow.

Results update as you type — press Enter to run now.

fig. 29 — chmod-calculator · utilities 4755 · rwsr-xr-x · file
Output
Octal4755
Symbolicrwsr-xr-x
ls -l-rwsr-xr-x
Commandchmod 4755 file

`chmod 4755 file` sets `rwsr-xr-x`: a normal 755 executable plus the setuid bit, so whoever runs it gets the privileges of the file's owner for the life of the process. On a root-owned binary, that means running as root.

What chmod 4755 means

In 4755 the first digit is the special-bits digit (4 = setuid, 2 = setgid, 1 = sticky; the values add up to combine them), so 4 sets setuid. The next three digits are owner, group and others: the owner gets read, write and execute, the group gets read and execute, and others get read and execute.

ls -l shows -rwsr-xr-x. The s in the owner's execute position is setuid plus execute; a capital S means setuid is set but execute is not, which does nothing useful.

Where setuid is used

passwd is the textbook case. Changing your password means writing /etc/shadow, which only root may modify, so /usr/bin/passwd is owned by root with mode 4755 and runs with root's effective user ID while it checks who you are and only lets you change your own entry. su, mount and sudo are setuid root for the same reason, though the exact mode differs between distributions.

These programs are written with their elevated position in mind: they drop privileges early, sanitise their environment and validate every input. An ordinary program is not.

Security warning

A setuid root binary with a bug is a local privilege escalation. Never set 4755 on your own programs to get around a permission problem; use sudo rules, Linux capabilities with setcap, or a service running as the right user instead. Never put it on scripts at all. Linux ignores setuid on interpreted scripts that start with a shebang, precisely because the gap between the kernel starting the interpreter and the interpreter opening the script was a classic attack, so the bit gives a false sense of having done something.

Audit regularly with find / -perm -4000 -type f -ls 2>/dev/null, which lists every setuid file, and compare it with what your distribution ships. An unexpected entry, especially in a home or /tmp directory, is a sign of compromise. Filesystems that should never hold such programs can be mounted with the nosuid option, which makes the kernel ignore the bit.

Removing it

chmod u-s file clears setuid and keeps everything else; chmod 755 file does the same for a regular file. Note that writing to a setuid file as a non-root user makes the kernel clear the bit automatically, and chown clears it too, so re-check the mode after replacing such a binary.

FAQ

Questions, answered.

Tap a question to expand the answer.

No. Linux ignores the setuid bit on interpreted scripts, so a 4755 script runs with the caller's privileges. Use sudo with a narrow rule, or a small compiled wrapper reviewed for security, if a script genuinely needs elevated rights.

Run find / -perm -4000 -type f as root. It lists every file with the setuid bit; compare the result with your distribution's defaults and investigate anything unexpected.

More free, private DevOps tools.

The chmod Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.

42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.

Related utilities: the UUID / ULID Generator, the Case Converter and the Slugify tool — or browse the full tools directory.

Provided as-is for convenience; always double-check permission changes on production systems. OpsCanopy is free and open.