This one is more or less straight to the point. We're going to setup a fresh raspberry pi in a headless state. It's fairly easy if you keep your wits about you.
Unfortunately you'll need either a keyboard/mouse + monitor or an ethernet connection to your device in order to get the wifi step of these instructions done.
Raspbian Lite & Wifi Connect
-
Download the image from raspberrypi
-
Burn to the SD card (straight from the ZIP) with the free Etcher.
-
In the boot partition, add an empty & extension-less file named
ssh
to enable ssh connections to the device. -
Now connect the pi to a monitor + keyboard/mouse OR connect it via ethernet and use your router's client list to find it's IP. You will be able to SSH into it if you chose the later route. (And yes, that also means you should be turning on the device in this step)
-
Setup wifi by editing the
wpa_supplicant.conf
to point your device at your wifi network.sudo nano /etc/wpa_supplicant/wpa_supplicant.conf # Add at the bottom, WITH the quotes. network={ ssid="YOUR_WIFI_NETWORK_NAME" psk="YOUR_WIFI_PASSWORD" }
-
Run
sudo raspi-config
to set things up.
Removing the Default Pi Account
Keeping the default account around is a bit of a risk. Let's make it yours.
- Make a new user:
- Enter root:
sudo -i
- Make user:
adduser [username]
- Make that user sudo:
adduser [username] sudo
- Enter root:
- Enable SSH for the user:
mkdir /home/[username]/.ssh
chown [username]:[username] /home/[username]/.ssh
- Leave root and close SSH connection
- Give local key to Raspberry Pi for SSH:
scp ~/.ssh/id_rsa.pub [username]@[Pi's IP address]:/home/[username]/.ssh/authorized_keys
- SSH in, delete the Pi account, and make a new root password:
sudo deluser pi
sudo passwd root
Some extra random steps you can take if you'd like:
-
Regenerate SSH keys stored on the Pi:
rm /etc/ssh/ssh_host_* && dpkg-reconfigure openssh-server
-
Ensure Protocol 2 is uncommented and enabled in
/etc/ssh/sshd_config
-
Setup IP Tables:
-
sudo apt install iptables
-
Open ports you want open, for example to open 22:
sudo iptables -A INPUT -p tcp --dport 22 -m state --state NEW -j ACCEPT
-
Allow pinging with:
sudo iptables -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
-
Block inbound traffic that is doesn't follow any of the rules:
sudo iptables -P INPUT DROP
-
View the rules:
sudo iptables -L
-
Save the rules:
sudo bash -c "iptables-save > /etc/iptables.rules"
-
Run the rules on startup:
# Edit this file nano /etc/network/if-pre-up.d/iptables #put these lines #!/bin/bash /sbin/iptables-restore < /etc/iptables.rules # ensure it can execute chmod +x /etc/network/if-pre-up.d/iptables
-
-
Setup Fail2Ban to push off bots.
- Sudo apt install fail2ban
- Configure inside /etc/fail2ban/jail.local
- Set some of the configuration found here
- Restart the service: /etc/init.d/fail2ban restart