How Unrar Handles Encrypted File Names

When handling RAR archives with encrypted file names, the unrar utility requires authentication before it can read, list, or extract any contents. Unlike standard encrypted archives where only the file payloads are hidden, header-encrypted archives protect the metadata itself, forcing unrar to halt execution immediately and prompt for a password before it can parse the archive structure.

Standard Encryption vs. Encrypted File Names

RAR archives support two distinct levels of password protection:

  1. Standard Data Encryption (-p flag): Only the file data inside the archive is encrypted using AES. The archive headers—containing file names, directory trees, file sizes, and timestamps—remain unencrypted in plaintext.
  2. Encrypted Headers / File Names (-hp flag): Both the file data and the internal archive headers are encrypted. The entire file table is unreadable without the decryption key.

How unrar Processes Encrypted Headers

When you run unrar against an archive created with the -hp switch, the tool follows a strict sequence:

  1. Signature Verification: The utility reads the initial RAR file signature (magic bytes) to confirm that the file is a valid RAR archive format (RAR 4.x or RAR 5.x).
  2. Immediate Password Prompt: Upon detecting the header encryption flag, unrar immediately halts execution and prompts the user:
    Enter password (will not be echoed):
    This prompt occurs regardless of the operation requested, including non-extracting commands such as listing archive contents (unrar l or unrar v).
  3. Key Derivation and Header Decryption: unrar processes the supplied password through a key derivation function (PBKDF2 in RAR 5.x) to generate the AES decryption key. It then attempts to decrypt the main header block.
  4. Validation: If the password is correct, the header decrypts cleanly, exposing the file tables and allowing unrar to proceed with the requested task. If the password is wrong, the decryption fails, and unrar terminates with an error such as Corrupt file or wrong password without displaying any file names.

Command-Line Usage and Automation

To handle archives with encrypted file names without an interactive prompt, you can pass the password directly using the -p switch:

  • List contents:
    unrar l -pSecretPassword archive.rar
  • Extract contents:
    unrar x -pSecretPassword archive.rar

If no password is provided in automated scripts or non-interactive environments (such as headless servers without stdin attached), unrar will fail immediately, as it cannot proceed past the encrypted header.