How Unrar Verifies Passwords Before Extraction

When extracting a password-protected RAR archive, the unrar utility determines password validity either through a dedicated password verification checksum or via archive header decryption and data integrity checks. The exact verification mechanism depends entirely on the archive format version (RAR4 versus RAR5) and whether archive headers were encrypted alongside the file contents.

RAR5 Format: Dedicated Password Verification Hashes

Modern RAR archives (format version 5.0 and later) include a built-in mechanism designed specifically to validate passwords instantly without needing to decompress file contents.

  1. Key Derivation via PBKDF2: When you input a password, unrar passes it along with a stored salt (typically 16 bytes) through the PBKDF2 (Password-Based Key Derivation Function 2) algorithm using HMAC-SHA256. This process repeats over tens or hundreds of thousands of iterations to generate the 256-bit AES encryption key.
  2. Password Check Value Comparison: To verify the key, RAR5 archives store an 8-byte password verification value inside the archive headers. The derived key material is processed through an additional SHA-256 hash operation, truncated, and compared against this stored 8-byte value.
  3. Immediate Validation: If the computed check value matches the header value, unrar confirms the password is correct and proceeds to decompression. If the hashes do not match, unrar immediately aborts the operation with an incorrect password error before reading the compressed data payloads.

RAR4 Format: Header Decryption and CRC32 Checks

Legacy RAR4 archives (created by WinRAR 4.x and earlier) use AES-128 encryption and handle verification differently depending on how the archive was created.

1. Encrypted Headers (Created with the -hp flag)

When the archive headers are encrypted, the directory structure, file names, and metadata are scrambled.

  • unrar derives an AES-128 key from the password and salt using repeated SHA-1 hashing.
  • It attempts to decrypt the main archive header.
  • Each RAR header contains fixed signature bytes and a CRC32 checksum of the header data. If the decrypted block fails the CRC32 validation or lacks the expected RAR header structure, unrar immediately knows the password was wrong.

2. Unencrypted Headers (Created with the -p flag)

If only file contents are encrypted while file names remain visible, RAR4 archives lack a dedicated password verification hash.

  • unrar derives the AES-128 key and immediately begins streaming and decrypting the compressed file data.
  • As it decompresses the data, it calculates the CRC32 checksum of the uncompressed output.
  • After processing, unrar compares this calculated checksum against the original CRC32 checksum stored in the unencrypted file header.
  • A mismatch indicates either data corruption or an invalid password. In this scenario, unrar cannot fully confirm whether the password was incorrect until the decompression phase fails or produces invalid data.