How Unrar Extracts Hidden and System Files
This article explains how the unrar utility processes
archives containing hidden and system files, detailing its attribute
preservation mechanisms, cross-platform behavior, and relevant
command-line flags. When unpacking an archive, unrar reads
the metadata attached to each entry, determining whether to restore
OS-specific flags like the Windows "Hidden" and "System" attributes or
POSIX hidden file formats. Understanding this process ensures you can
safely extract or ignore sensitive and concealed files across different
environments.
File Attribute Preservation
The RAR file format stores extended file metadata alongside the compressed data. When files are archived on a Windows system, their standard DOS/NTFS attributes—such as Read-Only, Archive, Hidden, and System—are saved into the archive header.
By default, when unrar unpacks an archive on a Windows
system, it applies these preserved attributes directly to the extracted
files. If a file was marked as both hidden and a system file in the
archive, it will retain both statuses in the destination directory,
making it invisible in standard file managers unless configured to show
protected operating system files.
Cross-Platform Handling: Windows vs. Linux/macOS
Operating systems treat "hidden" and "system" statuses differently,
and unrar adapts according to the host platform:
- On Windows:
unrarmaps the internal attribute flags directly to the Windows file system API. Files with the hidden or system bit set will immediately receive those attributes upon extraction. - On Unix-like Systems (Linux, macOS): Unix systems
do not natively use "hidden" or "system" metadata flags. Instead, files
are considered hidden if their filename begins with a dot
(
.filename). If an archive contains a file that was named with a leading dot,unrarextracts it as-is, and it becomes hidden in Unix environments. However, if a file only has the Windows "Hidden" or "System" attribute flag set without a leading dot,unrarextracts it as a visible file on Linux/macOS, though it may attempt to store these flags in extended attributes (xattr) if configured to do so.
Command-Line Switches for Attribute Control
You can control how unrar processes attributes and
system-level permissions using specific command-line switches:
-ai(Ignore file attributes): Instructsunrarnot to apply the stored file attributes (including Hidden, System, and Read-Only) to the extracted files. The extracted files inherit the default attributes of the target folder.-ow(Restore file owner and group): Restores security information, including user and group ownership on platforms that support it (requires administrative/root privileges).-os(Save and restore NTFS streams): Directsunrarto restore alternate data streams and extended file properties associated with Windows NTFS file systems.
Security and Overwrite Protections
Because hidden and system files can theoretically be used to replace
critical operating system components, unrar includes
built-in safeguards:
- Directory Traversal Protection:
unrarautomatically strips absolute paths (such asC:\Windows\or/etc/) and relative path traversal sequences (such as../) to prevent an archive from silently planting hidden system files into sensitive system directories. - Overwrite Confirmations: By default,
unrarprompts the user before overwriting existing files, preventing an incoming hidden system file from silently replacing an existing document or configuration file, unless overridden by flags such as-o+(overwrite without prompt) or-o-(do not overwrite).