4 ms·
I've had very good luck with NSIS 2.1. It's pretty far from state-of-the-art, but it's really solid if you just need to copy some files and make some start-menu
by johnhattan 10y ago
I've had very good luck with NSIS 2.1. It's pretty far from state-of-the-art, but it's really solid if you just need to copy some files and make some start-menu shortcuts.
The primary market for one of my products is elderly people, and the fact that I get almost zero setup-related tech support issues from that market tells me a lot.
And yeah, my existing installers work just fine with Windows 10, so I assume they just added some Windows 10-specific features.
- JohnTHaller 10y agoHeads up that NSIS 2.1 has a major security hole. It will use fake Windows DLLs within the same directory instead of the ones in the Windows and System directories. This wouldn't be that big of a deal except that Google Chrome is completely insecure in terms of downloads and would let any page automatically download EXE files and DLL files to the associated download directory without user interaction. The same download directory your installer would likely run from if you distribute online. Chrome has had the insecure behavior for years. Not sure if it does currently.
- slrz 10y agoIsn't this just using the Windows default library search path, though? How is NSIS supposed to know whether the library to be loaded is malicious or the result of a conscious admin decision (e.g. to circumvent some undesired installer behaviour)? The library search path is admin territory, programs shouldn't override it without a very good reason.
- user5994461 10y agoIt's the default search path for libraries which is well documented. (On the top of my head the function is LoadLibrary() on windows, see MSDN.) The thing is, there was a random guy who considered that a security issue and he started posting vulnerability reports and asking for bounties on quite literally EVERY software existing on the planet. e.g. firefox, chrome, internet explorer, nsis, inno setup, and many popular open-source applications (because of course, EVERY software is affected since the 30 years windows and all other OS doing the exact same thing have existed). It was a sort of epic scale hoax. (even though it's factually true that DLL are loaded from the current directory). That will lead to a whole generation of people who will read the reports and be mislead into thinking that this was a major security failure discovery.
- JohnTHaller 10y agoIt's an issue for the scenario I mentioned above which has been exploited in the wild for months now. You create a fake SHFOLDER.DLL or similar with your payload in it and stick it on every hacked WordPress or similar site you can. Google Chrome's stupidly insecure download setup allows any website to automatically download the vulnerable DLL right to the Downloads directory with no user interaction required. Now, every single legitimate NSIS or InnoSetup installer that hasn't been patched against this vulnerability that the end user downloads and runs will use the infected DLL instead of the legitimate one. The above works regardless of how the admin has defined the search path. It's a legitimate vulnerability. Installers specifically should be hard coded to only use Windows DLLs from the Windows directories. Realistically, Google Chrome should be fixed to not be so dumb and insecure with EXEs and DLLs as well. It may have been by now but it was definitely vulnerable when NSIS fixed this exploit and it was the primary attack vector since browsers like Firefox don't allow websites to automatically download infected DLLs to your Download directory.
- SyneRyder 10y agoAnother +1 for NSIS with older / elderly customers. I've also had success in that respect, and the NSIS support for custom DLLs let me extend NSIS to improve usability. (My products have to be installed in the plugins folder of dozens of different commercial programs, the DLL support lets me detect that automatically for my customers.) I also like InnoSetup, and its Pascal scripting is certainly more straightforward than the NSIS Assembly-like coding, but NSIS has served me very well.