How 7-Zip Extracts Payloads from ELF Files

7-Zip can open Linux Executable and Linkable Format (ELF) binaries by treating them as structured containers rather than compiled black boxes. By parsing the file's native internal tables, 7-Zip maps individual execution sections, detects embedded archives, and identifies trailing overlay data, allowing users to browse and extract internal payloads without executing the binary.

ELF Header and Structure Detection

When a file is loaded into 7-Zip, the application reads the first few bytes to match known format signatures. For ELF binaries, 7-Zip searches for the four-byte magic number: 0x7F, followed by the ASCII characters E, L, and F (\x7fELF).

Once validated, 7-Zip's dedicated ELF parser reads the initial ELF header. This header provides essential structural metadata:

  • Architecture and Bitness: Indicates whether the binary is 32-bit (Elf32_Ehdr) or 64-bit (Elf64_Ehdr).
  • Endianness: Determines whether data is read in little-endian or big-endian order.
  • Header Offsets: Locates the Section Header Table (e_shoff) and Program Header Table (e_phoff), along with the number of entries and entry sizes.

Reading the Section Header Table

7-Zip accesses the file's Section Header Table to enumerate the binary's contents. Each section entry defines a distinct part of the executable, including its name offset, file offset, and physical size.

7-Zip resolves the names of these sections (such as .text, .rodata, .data, and .bss) by reading the section header string table (.shstrtab). It then translates each identified section into a distinct virtual file within the 7-Zip interface, displaying the raw binary data contained within that segment.

Extracting Embedded Payloads and Installers

Linux installers, self-extracting scripts (like makeself), and portable formats (like AppImage) often embed compressed payloads inside or directly alongside an ELF runner. 7-Zip extracts these payloads through two primary mechanisms:

  1. Embedded Sections: If an ELF file contains a dedicated section holding an embedded archive (such as a compressed SquashFS image, CPIO archive, or Tarball), 7-Zip exposes that section. If 7-Zip recognizes the signature of a nested compression format (e.g., Gzip, XZ, or Zstandard) inside that section, it allows recursive navigation directly into the archive.
  2. Overlay/Trailing Data Detection: In many self-extracting formats, payload data is simply appended to the end of the compiled ELF executable. 7-Zip calculates the total official size of the ELF binary by checking the maximum offset and size defined by the section and program headers. Any data located past the end of the legitimate ELF boundaries is flagged as an overlay. 7-Zip scans this appended region for common archive signatures and exposes the trailing archive as extractable content.

Through direct parsing of headers and signature scanning of arbitrary binary streams, 7-Zip bypasses the execution layer entirely, isolating and unpacking raw payloads directly from the ELF container.