Archive: Possible Security issue w/ NSIS, ******odern UI?


Possible Security issue w/ NSIS, ******odern UI?
Hi All,

I just wanted to throw this out there.

I still have to investigate more, but basically, I downloaded the latest
NSIS and the Ultra Modern UI, all within November, and built a new
install on my Windows Server 2008 machine, so that I could capture
some screen shots and test more with the problem of the Welcome
screen appearing on top of the running Uninstall window.

I ran the Install on another, XP Pro SP3, dev machine, and as soon as the
Install phase started, I got a pop-up from ZoneAlarm saying that something was
trying to get out, on the internet, to 80.190.143.232:DNS

I've NEVER seen any NSIS Install get any pop-ups of anything wanting to get out before.

The XP machine has an up-to-date Avira, and no problems with viruses, or malware.

The server just has the stupid Windows Firewall running, which gives no
warning at all, of course.. :-\ So I installed PC Tools Firewall, and as soon as the
Install phase starts I got this pop-up:

"NSFEB is attempting to use another process Net Command with parameters (...)"

and if you click on "NSFEB" it gives: ....\Local\Temp\Nsv3ce3.tmp\Nsfeb.tmp
( the exact file name changes )

Then it gets pretty much the same pop-up at the end of the Install.

Of course that firewall puts a zillion pop-ups about every interaction
of apps, but at least it notified me that something was trying to "get out"..

Maybe this is nothing, I don't know, but I've done plenty of installs,
but not that many with the Ultra Modern UI, and I've never seen any firewall pop-ups.

Maybe I'll try to re-build NSIS from the source, but I don't know.


P.S. I might have "solved" the issue of the Welcome screen "hiding"
the running Uninstall window. After the Uninstall starts, I let it go down
into the Uninstall some, then do a:

Sleep 1500

BringToFront

And brings it back on top of the Welcome screen, for now.

Thanks


Ok, on the Server, I found out what the two "Net Command"s where,
those where okay.

At the start of the Install, I sent a command to stop my Service
and when the Install was finished I sent a command to start the new Service, so that part, on the Server machine anyway, was okay.

But the ZoneAlarm popping up that notification, on the other machine, of something
wanting to get out was totally different.

Also, I re-installed NSIS and the .zip of the Ultra Modern UI. before I
downloaded the "combined" NSIS/******odern UI and that overwrote the original
NSIS.


Looks like your security products might be tripping all over eachother.

Your ZoneAlarm alerted you to a connection to 80.190.143.232 . IP lookup tells me that IP belongs to AVIRA GMBH. So maybe you have some Avira product installed which decided to do an online lookup of.. something? For whatever reason.


Yeah, that sounds about right.

Maybe Avira decided to try to get out to do an Update.
I tried to look-up that IP and got something that seemed
weird.

Sorry about all this.

Thanks!