Multiple Passwords in Unrar Command Line

This article explains how the unrar utility behaves when multiple passwords are provided in the command line, detailing the internal argument parsing rules and extraction outcomes. When executing extraction commands, unrar does not test multiple passwords sequentially or attempt to match passwords to specific encrypted files. Instead, it either overwrites earlier password definitions with the latest entry or misinterprets trailing values as target file masks, depending on how the arguments are passed.

Behavior When Using Multiple -p Switches

In unrar, passwords are explicitly designated using the -p<password> switch. If you provide more than one -p switch in a single command—for example:

unrar x -ppassword1 -ppassword2 archive.rar

The utility processes flags sequentially from left to right. When the parser encounters the second -p flag, it updates the internal password variable, completely overwriting the first one.

  • The Active Password: Only the last supplied password (password2 in this example) is used.
  • The Result: If the final password is correct, the archive extracts normally. If the final password is incorrect, unrar returns a checksum or authentication error, entirely ignoring password1.

Behavior When Providing Passwords as Positional Arguments

If passwords are submitted as plain arguments without the -p prefix, the utility’s argument parsing treats them according to standard RAR command-line syntax:

unrar x archive.rar password1 password2

In this syntax pattern, any non-switch parameters provided after the archive name are interpreted as file or folder masks rather than passwords:

  1. unrar attempts to locate and extract only the files named password1 and password2 from inside archive.rar.
  2. Because no password was specified with -p, unrar will prompt the user interactively in the terminal to enter a password, unless non-interactive switches (such as -p- or -inul) are active.
  3. If an encrypted file matches the mask and an incorrect interactive password is entered, extraction fails.

Batch Password Testing

The standard unrar command-line utility does not support passing a dictionary list, an array of candidate passwords, or falling back to a secondary password natively. To test an archive against multiple potential passwords, users must use external scripting (such as a Bash for loop or PowerShell foreach block) that iterates through a list, executes unrar with one password at a time, and evaluates the process exit code (0 for success).