How Unrar Handles Encrypted File Names
When handling RAR archives with encrypted file names, the
unrar utility requires authentication before it can read,
list, or extract any contents. Unlike standard encrypted archives where
only the file payloads are hidden, header-encrypted archives protect the
metadata itself, forcing unrar to halt execution
immediately and prompt for a password before it can parse the archive
structure.
Standard Encryption vs. Encrypted File Names
RAR archives support two distinct levels of password protection:
- Standard Data Encryption (
-pflag): Only the file data inside the archive is encrypted using AES. The archive headers—containing file names, directory trees, file sizes, and timestamps—remain unencrypted in plaintext. - Encrypted Headers / File Names (
-hpflag): Both the file data and the internal archive headers are encrypted. The entire file table is unreadable without the decryption key.
How unrar
Processes Encrypted Headers
When you run unrar against an archive created with the
-hp switch, the tool follows a strict sequence:
- Signature Verification: The utility reads the initial RAR file signature (magic bytes) to confirm that the file is a valid RAR archive format (RAR 4.x or RAR 5.x).
- Immediate Password Prompt: Upon detecting the
header encryption flag,
unrarimmediately halts execution and prompts the user:
This prompt occurs regardless of the operation requested, including non-extracting commands such as listing archive contents (Enter password (will not be echoed):unrar lorunrar v). - Key Derivation and Header Decryption:
unrarprocesses the supplied password through a key derivation function (PBKDF2 in RAR 5.x) to generate the AES decryption key. It then attempts to decrypt the main header block. - Validation: If the password is correct, the header
decrypts cleanly, exposing the file tables and allowing
unrarto proceed with the requested task. If the password is wrong, the decryption fails, andunrarterminates with an error such asCorrupt file or wrong passwordwithout displaying any file names.
Command-Line Usage and Automation
To handle archives with encrypted file names without an interactive
prompt, you can pass the password directly using the -p
switch:
- List contents:
unrar l -pSecretPassword archive.rar - Extract contents:
unrar x -pSecretPassword archive.rar
If no password is provided in automated scripts or non-interactive
environments (such as headless servers without stdin attached),
unrar will fail immediately, as it cannot proceed past the
encrypted header.