Extracting a RAR Archive Embedded in a JPEG File
Embedding a RAR archive inside a JPEG image is a common technique
achieved through simple binary concatenation, allowing the resulting
file to function normally as an image while secretly carrying compressed
data. The unrar utility can extract these hidden archives
directly because it does not depend on file extensions or assume the
archive data starts at the very beginning of the file. Instead,
unrar scans the binary stream for specific marker
signatures to locate and unpack the RAR payload.
The Structure of a Concatenated File
Creating an embedded file usually involves appending an archive to an image using a binary copy command. In this arrangement, two distinct file formats coexist in a single byte stream:
- The JPEG Component: A standard JPEG begins with a
Start of Image (SOI) marker (
0xFF 0xD8) and concludes with an End of Image (EOI) marker (0xFF 0xD9). Most image viewers read up to the EOI marker, render the image, and ignore any data appended after it. - The RAR Component: The RAR file data is appended directly after the JPEG's EOI marker.
Signature Scanning
unrar handles these embedded archives through byte
scanning. Rather than requiring the RAR signature to be located at byte
0x00, the decompression engine reads through the file
looking for specific magic bytes:
- RAR 4.x Archive Header:
0x52 0x61 0x72 0x21 0x1A 0x07 0x00(Rar!...) - RAR 5.x Archive Header:
0x52 0x61 0x72 0x21 0x1A 0x07 0x01 0x00
When unrar encounters this byte sequence anywhere within
the file, it verifies the header integrity using checksums. This
validation step ensures that random binary data within the JPEG stream
is not mistaken for a valid RAR header.
Processing the Archive Stream
Once a valid signature is identified, unrar operates as
follows:
- Offset Recalculation: The utility sets the starting byte of the detected signature as the logical offset zero for archive operations.
- Block Parsing: It reads subsequent block headers (file headers, metadata, encryption flags) relative to that offset.
- Decompression: It processes the compressed data
blocks and writes the unpacked files to the destination directory as if
it were processing a standard
.rarfile.
Extraction Command
Because unrar inspects file signatures regardless of
extension, no specialized flags are required to trigger this scanning
behavior. The archive can be extracted directly using the standard
syntax:
unrar x embedded_image.jpgIf the tool is invoked with standard extraction flags (x
to preserve paths, or e to unpack into the current
directory), unrar automatically performs the search,
bypasses the leading JPEG data, and unpacks the embedded files.