How Unrar Indicates a Password Is Required

When working with RAR archives in a command-line environment, the unrar utility communicates password requirements primarily through interactive terminal prompts, specific archive listing flags, and dedicated process exit codes. Depending on whether the entire archive structure or just the contained files are encrypted, unrar will either halt execution immediately to request credentials or display visual markers indicating that individual items require decryption keys for extraction.

Interactive Extraction Prompts

When you attempt to unpack an archive using extraction commands like unrar e archive.rar (extract to current directory) or unrar x archive.rar (extract with full paths), the tool checks the encryption flags of the target files. If encryption is detected, unrar suspends execution and outputs the following prompt:

Enter password (will not be echoed):

The tool then waits for standard input. Typed characters are hidden to prevent credential exposure on the screen. If an incorrect password is provided, extraction fails with an error message such as Corrupt file or wrong password or Checksum error in the encrypted file.

Encrypted File Headers vs. Encrypted Data

The timing of unrar's password request depends on how the RAR file was created:

  • Encrypted File Data: If only file contents are encrypted, unrar can read the archive's table of contents without authentication. It begins the extraction process and only prompts for the password once it reaches the first protected file.
  • Encrypted File Names (Encrypted Headers): If the archive was created with encrypted headers (such as using the -hp flag in WinRAR/RAR), the file names and sizes are locked. In this scenario, unrar issues the password prompt immediately, preventing any inspection or extraction until the correct key is entered.

Archive Inspection and the Asterisk Indicator

You can check if an archive requires a password before attempting extraction by using the list commands: unrar l archive.rar (standard list) or unrar v archive.rar (verbose list).

In standard list mode, unrar prints an asterisk (*) immediately preceding the file name in the output table to indicate that the item is encrypted. In verbose mode, unrar details the archive attributes, showing flags such as encrypted or displaying cipher specifications under the file details section.

Non-Interactive Signals and Exit Codes

When running scripts or automated tasks, unrar handles missing passwords by aborting execution rather than hanging indefinitely on an input prompt (particularly when standard input is closed or the -p- switch is used to disable the password prompt).

In such non-interactive cases, unrar indicates the requirement through standard error output:

Cannot open encrypted file

It then terminates with exit code 11, which represents a password error in the unrar specification. Monitoring for exit code 11 allows automation scripts to detect that an archive is password-protected without needing to parse text streams.