Skip to content
⌘ NSIS Forum Archive

Universal Extractor extract the nsi file

65 posts

thek#
No because you have to supply the key via an userinput and not hardcoded in the script...

if you put the key in the script you have lost, there is no way to "secure" it there. (only obscuring is possible)
LoRd_MuldeR#edited
Originally posted by arfgh
and how can we work with that "obscuring" in nsis ?
Be creative! Don't save you password as a simple plain string! Cut your password into several strings, add random characters to those strings and so on. Do everything that might confuse a person who is looking at the disassembly of your installer. At runtime you can calculate the correct password from the strings you have stored in your installer. And don't keep the result in memory any longer than you need it. But be aware that this will keep nobody away from reconstructing your password. It only makes things a tiny bit less trivial...


Very very simple example:

StrCpy $0 "M"
StrCpy $1 "O"
StrCpy $2 "W"
StrCpy $3 "R"
StrCpy $4 "S"
StrCpy $5 "Y"
StrCpy $6 "S"
StrCpy $7 "A"
StrCpy $8 "D"
StrCpy $9 "P"

MessageBox MB_OK "Super secret password: $0$5$9$7$6$4$2$1$3$8"

StrCpy $0 " "
StrCpy $1 " "
StrCpy $2 " "
StrCpy $3 " "
StrCpy $4 " "
StrCpy $5 " "
StrCpy $6 " "
StrCpy $7 " "
StrCpy $8 " "
StrCpy $9 " "
"Extract" that with Universal Extractor. You won't see the Password in plain text, but it's not too hard to guess the password 😁
LoRd_MuldeR#
Then why not leave NSIS behind, stop bothering the people they try to help you and use some Installer that provides better protection (in your imagination). And better hope the 7-Zip developers won't implement "support" for other Installers 😛