Showing posts with label raspberry pi. Show all posts
Showing posts with label raspberry pi. Show all posts

Tuesday, February 3, 2015

Secure your Raspberry Pi


Recently I examined my Raspberry Pi's logfiles because of all the cyber warfare going on and as I went trough the auth.log (/var/log/auth.log) looking for failed login attempts I saw a list of about 100 attempts from IPs trying to login as root or bin user.

$ cat /var/log/auth.log | grep 'sshd.*Failed'

This got my attention and my awareness, of having an unprotected SSH server running open to the worldwide net. I decided to pay a little bit more attention to the security of my Raspberry Pi and here I'll show you a few easy steps to make your Pi more secure:

Changing the pi standard user

First you have to kill all processes running under your current user. Therefore it would be best for you to log in via SSH as root and then you have to find out the id of your pi user:

$ sudo su
$ killall -u pi
$ id pi

uid=1000(pi) gid=1000(pi) groups=1000(pi), ...

next you have to change the login user, group and the home directory to the new user called newuser and copy the contents of the pi user's home to the home of the newuser, then delete the old directory

$ usermod -l newuser pi 
$ groupmod -n newuser pi 
$ usermod -d /home/newuser -m newuser 
$ usermod -c REALNAME newuser
$ cp -r /home/pi /home/newuser 
$ rm -r /home/pi

Now you should be able to log in as 'newuser', but to still be able to use sudo, you need to change the user in /etc/sudoers from pi to newuser. This is only possible with the tool "visudo":

$ visudo

newuser ALL=(ALL) NOPASSWD: ALL


Set a hard password

Most important and most easiest thing to do, is to choose a strong password. You can change your current password by typing

$ passwd

and then set your new, strong password. Strong passwords usually contain
  • upper and lower case characters
  • numbers
  • special characters
  • more then 8 characters in length
  • and so on and so forth
Here you have a nice command that will give you a random password directly on your Pi:

$ </dev/urandom tr -dc '12345!@#$%qwertQWERTasdfgASDFGzxcvbZXCVB' | head -c12; echo ""


Changing the SSH port

One important action to avoid crawler which randomly test for open ports, is to change the standard SSH port from 22 to something else. This can easily be done either
  • directly via your routers port forwarding rule    or
  • by changing the SSH daemon's listening port

Directly via the router

Depending on your routers configuration you have to change the port forwarding from port 22 on your router to a random port (say 1337), which is not used by another service. By using this alternative, you don't need to change your sshd config on the Pi, you just have to change add the port-number when ssh-ing to the pi. Your router redirects port 1337 to port 22 on your Pi, and everything works as usual

$ ssh pi@my.duckdns.org -p 1337

Here a short overview over various services and their standard ports.

Changing the daemon

If you want to change the listening-port of the daemon directly, you have to alter the sshd config.

$ sudo vi /etc/ssh/sshd_config

replace Port 22 with Port 1337

Keep in mind that you also need to change the port-forwarding on your router to the port you selected.
If you want to open a connection you have to specify the port:

$ ssh pi@my.duckdns.org -p 1337

For your convenience you can create a $HOME/.ssh/config file and add the following:

Host rpi
HostName my.duckdns.org
User newuser
Port 1337

This enables you to connect easily from this computer:

$ ssh rpi

Adapt the SSH config

There are a few more things you can do with the sshd_config to improve the security of your Raspberry. As we are curious, we want to increase the logging level of our SSH daemon by changing following parameter from

$ sudo vim /etc/ssh/sshd_config
[...]
LogLevel INFO


to

LogLevel VERBOSE

After this change, ALL details of the login attempts will be saved to the auth.log file.

Allow and deny specific users

One great feature is to only allow specific users to login via SSH. Therefore you just have to add or change following lines in the config:

$ sudo vim /etc/ssh/sshd_config
[...]
AllowUsers Peter Jango

This line tells the server to allow only Peter and Jango to sign in via SSH. The next line does exactly the opposite:

$ sudo vim /etc/ssh/sshd_config
[...]
DenyUsers Peter Jango

Peter and Jango are not allowed to sign in via SSH, everyone else is allowed.

If you want to personalize your SSH login, then you can take a look at this tutorial, showing you how to customize the SSH login.

Restrict root access

Another important option, is to disable root access via SSH. It is still possible to login as normal user and switch to root or to work with sudo only. Just change the option "PermitRootLogin" to no

$ sudo vim /etc/ssh/sshd_config
[...]
PermitRootLogin no

$ sudo /etc/init.d/ssh reload


Limit number of connections

If an IP address tries to open more than X connections in XX seconds, we can tell the server to drop this connections. This can be handled by the MaxStartups option and can significantly alleviate DDOS attacks.

MaxStartups 10:30:60 (start:rate:full)

10 is the number of unauthenticated connections before we start dropping connections by a chance of rate/100 (30 %). Once there are 60 unauthenticated connections, we drop every connection. Because the Pi is on the lower end of the performance scale and isn't used as server for many users, I suggest to insert smaller values for start and full.

$ sudo vim /etc/ssh/sshd_config
[...]
MaxStartups 2:50:10

It also makes sense to reduce the LoginGraceTime, this is the time the server keeps the connection alive while waiting for authorization.

$ sudo vim /etc/ssh/sshd_config
[...]
LoginGraceTime 20


Disable password authentification - SSH keys only

A weak password is the biggest problem on SSH servers, so best thing would be to use SSH keys instead of passwords, because this keys are complex enough to withstand an average attack and together with the other configuration described above should provide a certain amount of protection. But the use of SSH-keys also comes with disadvantages: You can not log in from a device without pre-approving. Keep that in mind! To disable password authentication set

$ sudo vim /etc/ssh/sshd_config
[...]
PasswordAuthentication no

You can find a short tutorial about ssh-key authentication here.

Fail2ban

Fail2ban is a python based intrusion prevention tool, which scans logfiles like the auth.log and bans IPs that cause too many login errors by updating firewall rules (iptables) or TCP Wrappers (/etc/hosts.deny). It is very flexible, easy to use and has a lot of filters for various services like SSH, lighttpd, apache, vsftpd and so on.

You can download fail2ban on the fail2ban download page or simply install it on your raspbian by typing:

$ sudo apt-get install fail2ban

After installation is finished, we have to configure fail2ban, therefore go to the directory containing the config files (usually /etc/fail2ban/) and make a copy of the jail.conf with the name jail.local. Only change the parameters in the jail.local file, because changing the .conf file directly can cause errors on program updates and the parameters in the jail.conf get overwritten by the ones in the .local file. Here I will just talk about the basic options for SSH.

Look for the options regarding the SSH service and see if the filters are enabled and the logpath is set to the right place, usually /var/log/auth.log. I would recommend to set the maxretry parameter to 3 and the increase the time the IP is banned to e.g. 1800 (30 min). If you want to ban the IP forever you have to set a negative value for the bantime e.g. -1

$ sudo vi /etc/fail2ban/jail.local [...]
bantime = 1800
[...]

[ssh]
enabled  = true
port     = ssh
filter   = sshd
logpath  = /var/log/auth.log
maxretry = 3


You can find the filter rules in /etc/fail2ban/filter.d/ and you can create new ones for every service you like.
Find more information on www.fail2ban.org/wiki

I hope you found this useful and it will help you to stay secure!

Thursday, January 8, 2015

Customize SSH login

After you have set up a secure  SSH server maybe you would like to customize your login, to look a bit more personal. e.g. like the penrose triangle

     ____  ____  ____  ____                      ______________________
    /\   \/\   \/\   \/\   \                    /\                     \
   /  \___\ \___\ \___\ \___\                  /  \    _________________\
   \  / __/_/   / /   / /   /                  \   \   \                /
    \/_/\   \__/\/___/\/___/                    \   \   \__________    /
      /  \___\    /  \___\                       \   \   \    /   /   /
      \  / __/_  _\  /   /                        \   \   \  /   /   /
       \/_/\   \/\ \/___/                          \   \   \/   /   /
         /  \__/  \___\                             \   \  /   /   /
         \  / _\  /   /                              \   \/   /   /
          \/_/\ \/___/                                \      /   /
            /  \___\                                   \    /   /
            \  /   /                                    \  /   /
             \/___/                                      \/___/

 (source: wikipedia)


You can also create an ASCII Art from any picture. There are some sites where you can upload your picture and create an ASCII pic out of it, look here. Once you connect via SSH e.g.  > ssh user@myraspberry.pi you see the welcome text or logo, which is defined in your sshd config. First you have to create the file containing the hello message, e.g.  

 $ sudo vim /etc/ssh/welcome.msg  
     ____  ____  ____  ____                   |
    /\   \/\   \/\   \/\   \                  |
   /  \___\ \___\ \___\ \___\                 |
   \  / __/_/   / /   / /   /                 |
    \/_/\   \__/\/___/\/___/                  |
      /  \___\    /  \___\                    |
      \  / __/_  _\  /   /                    |
       \/_/\   \/\ \/___/                     |
         /  \__/  \___\                       |
         \  / _\  /   /                       |
          \/_/\ \/___/                        |
            /  \___\                          |
            \  /   /                          |
             \/___/                           |
WELCOME TO MY RASPBERRY PI!
PLEASE AUTHENTICATE!


In the next step, we have to tell our ssh daemon where to find this welcome message, therefore we have to change the 'Banner' entry in the sshd config to the location of our welcome message:

$ sudo vim /etc/ssh/sshd_config 
[...]
Banner /etc/ssh/welcome.msg


After that, we have to restart sshd:

$ sudo service sshd restart

We can also add another welcome message for the users, which are already authenticated by editing the MOTD file:  

$ sudo vim /etc/motd 

Once finished, we again have to restart the ssh daemon on the raspberry and then we can try this thing out. On connecting to our pi we should now see the pi ASCII logo and after entering the password, we should be informed about the news in our motd file.

Wednesday, February 27, 2013

Tomboy's new sync-server Rainy running on the Raspberry Pi!


As Ubuntu One is shutting down their note-sync service based on the Snowy server, I needed to come up with a solution for this problem. My main thought was: Why should I trust anyone on this again, if it is so easy to build your own "cloud" for syncing notes?
Rainy is still in early development, but already does an awesome job on syncing notes between Tomboy and Tomdoid. Special thanks to Timo Dรถrr for this! Further, the Raspberry Pi (a credit-card sized computer) is the ideal platform for this purpose as it only "eats" 2 Watts per hour and can be easily run 24/7.

How do I build my own note-sync-server?

To create a minimal Debian system on a SD Card for the Raspberry Pi, just follow the steps here: 
http://blog.kmp.or.at/2012/05/build-your-own-raspberry-pi-image/

In summary you need to:
1. Install these dependencies on your computer: 
apt-get install binfmt-support qemu qemu-user-static debootstrap kpartx lvm2 dosfstools
2. Adopt the script (Optional! Just search for the lines and put your things in there!):
x) Change the debian mirror url: deb_mirror="http://http.debian.my/debian"
x) Add the network interface wlan0 for wifi access and use a static IP address of your choice:
echo "auto lo
iface lo inet loopback

#auto eth0
#iface eth0 inet static
# address 192.168.0.4
# netmask 255.255.255.0
# gateway 192.168.0.1

auto wlan0
iface wlan0 inet static
address 192.168.0.4
netmask 255.255.255.0
gateway 192.168.0.1
wpa-ssid MYSSID
wpa-psk MYWIRELESSKEY
" > etc/network/interfaces

    x) Change the password: echo \"root:MYPASSWORD\" | chpasswd
    x) Add packages to pre-install for wifi (you might need other firmware packages!): 
apt-get -y install locales console-common ntp openssh-server less vim wireless-tools firmware-atheros firmware-realtek wpasupplicant
3. Run script: sudo ./build_rpi_sd_card.sh /dev/sdX
4. Put the SD Card into your Raspberry Pi and plug it in. It should automatically connect to your wifi (or lan)!

After you logged in (either directly or over ssh root@192.168.0.4), you will see a typical Linux shell. At first we will have to install the dependencies and necessary packages for our mono based Rainy server:
apt-get -y install libmono-system-runtime2.0-cil libmono-microsoft-csharp4.0-cil libmono-system-componentmodel-dataannotations4.0-cil libmono-system-web2.0-cil libmono-system-web-services4.0-cil libmono-system-data-linq2.0-cil libmono-system-data-linq4.0-cil libmono-system-web-abstractions4.0-cil mono-runtime unzip screen
Then we have to download the pre-compiled Rainy binary, unzip it and change into the directory:
wget http://rainy.notesync.org/release/rainy-0.1.3.zip
unzip rainy-0.1.3.zip
cd rainy-0.1.3
With a text editor of you choice you can edit the settings.conf file to change the user names, passwords, etc. Then start Rainy:
mono Rainy.exe -c settings.conf
If you want to run the server as a background job, I suggest to use screen. A very short explanation on how it works can be found here: http://jjjjango.blogspot.co.at/2013/01/linux-start-long-running-jobs-with-ssh.html

Now open your Tomboy, or Tomdroid and add the new sync server URL:
http://192.168.0.4:8080/<username>/<password>/
If you want to sync from outside your home, you have to redirect the 8080 port of your router to the IP address of the Pi. Further, you have to use the public IP of your router in the sync URL. In case you get a dynamic public IP, you will have to use http://www.noip.com/ or a similar service.

I hope, you know what to do! If not, please don't hesitate and ask your questions in the comments!

Saturday, June 2, 2012

Most perfectly fitting Raspberry Pi Paper Case

Previously I downloaded the famous Punnet paper case (http://www.raspberrypi.org/archives/1310), but unfortunately it was not really fitting. The base area was too broad and the holes for audio out, HDMI and micro USB not properly placed.

Therefore I measured the whole Raspberry Pi in detail and quickly drew a case based on the Punnet, but without the annoying bugs.



You can choose which file to DOWNLOAD:

I think you are smart enough to figure out where to cut, fold and glue ;-)
The case has to be folded in a way that the lines are inside!
Keep in mind that you uncheck "Fit to printable area", and that you do not use scaling for printing.

Further, if you glue paper edges above the HDMI and the micro-USB plug, the board is even more stable in the case! There is no wobbling or squeezing (See photos for details).

Here some photos of the resulting paper case:




This case, as well as the all blog-entries, images,... are published under the Creative Commons License: http://creativecommons.org/licenses/by-nc/3.0/

So, if you still find a bug, just download the *.svg and fix it (or comment here)!