Extracting a RAR Archive Embedded in a JPEG File

Embedding a RAR archive inside a JPEG image is a common technique achieved through simple binary concatenation, allowing the resulting file to function normally as an image while secretly carrying compressed data. The unrar utility can extract these hidden archives directly because it does not depend on file extensions or assume the archive data starts at the very beginning of the file. Instead, unrar scans the binary stream for specific marker signatures to locate and unpack the RAR payload.

The Structure of a Concatenated File

Creating an embedded file usually involves appending an archive to an image using a binary copy command. In this arrangement, two distinct file formats coexist in a single byte stream:

  1. The JPEG Component: A standard JPEG begins with a Start of Image (SOI) marker (0xFF 0xD8) and concludes with an End of Image (EOI) marker (0xFF 0xD9). Most image viewers read up to the EOI marker, render the image, and ignore any data appended after it.
  2. The RAR Component: The RAR file data is appended directly after the JPEG's EOI marker.

Signature Scanning

unrar handles these embedded archives through byte scanning. Rather than requiring the RAR signature to be located at byte 0x00, the decompression engine reads through the file looking for specific magic bytes:

  • RAR 4.x Archive Header: 0x52 0x61 0x72 0x21 0x1A 0x07 0x00 (Rar!...)
  • RAR 5.x Archive Header: 0x52 0x61 0x72 0x21 0x1A 0x07 0x01 0x00

When unrar encounters this byte sequence anywhere within the file, it verifies the header integrity using checksums. This validation step ensures that random binary data within the JPEG stream is not mistaken for a valid RAR header.

Processing the Archive Stream

Once a valid signature is identified, unrar operates as follows:

  1. Offset Recalculation: The utility sets the starting byte of the detected signature as the logical offset zero for archive operations.
  2. Block Parsing: It reads subsequent block headers (file headers, metadata, encryption flags) relative to that offset.
  3. Decompression: It processes the compressed data blocks and writes the unpacked files to the destination directory as if it were processing a standard .rar file.

Extraction Command

Because unrar inspects file signatures regardless of extension, no specialized flags are required to trigger this scanning behavior. The archive can be extracted directly using the standard syntax:

unrar x embedded_image.jpg

If the tool is invoked with standard extraction flags (x to preserve paths, or e to unpack into the current directory), unrar automatically performs the search, bypasses the leading JPEG data, and unpacks the embedded files.