Securely Pass Password to Unrar Without Bash History

Extracting encrypted RAR archives on the command line can inadvertently expose sensitive credentials if the password is typed directly into the terminal. This guide covers how to pass passwords to the unrar utility without saving them to your .bash_history file, mitigating the risk of credential leakage through terminal logs, shell history, and process monitoring.

1. Use the Interactive Prompt (Most Secure)

The safest and most reliable way to supply a password to unrar is to let the utility prompt you directly. This avoids placing the password into the command line entirely, preventing it from appearing in both your Bash history and the system's process table (ps aux).

Run the extraction command without specifying the password value:

unrar x -p archive.rar

Alternatively, omit the -p switch entirely:

unrar x archive.rar

unrar will detect that the archive is encrypted and prompt:

Enter password (will not be echoed) for archive.rar:

Type the password and press Enter. The input remains hidden from the terminal display, Bash history, and external process inspection.


2. Read into an Environment Variable via read -s

If you are running commands interactively and do not want the password saved in shell history, you can capture it silently into an in-memory variable using read -s.

read -s -p "Archive Password: " RAR_PASS
unrar x -p"$RAR_PASS" archive.rar
unset RAR_PASS
  • read -s suppresses terminal echo, meaning characters do not print to the screen.
  • Because the password is captured as input rather than an executed command, it never enters the .bash_history file.
  • unset RAR_PASS immediately clears the variable from memory once the extraction completes.

Note: While this method protects your Bash history, the password may briefly be visible to other local users viewing the process list (ps aux) while unrar runs.


3. Prefix the Command with a Space (HISTCONTROL)

Bash can be configured to ignore commands that begin with a leading space. By default, many Linux distributions enable this behavior via the HISTCONTROL environment variable.

Check your current configuration:

echo $HISTCONTROL

If the output contains ignorespace or ignoreboth, any command prefixed with a space will not be recorded in your history.

Execute your command with a leading space before unrar:

 unrar x -pSecretPassword archive.rar

If HISTCONTROL is not configured, enable it for your current session:

export HISTCONTROL=ignorespace

4. Temporarily Disable Bash History

If you need to run multiple commands without logging them, disable Bash history logging temporarily for the active shell session.

set +o history
unrar x -pSecretPassword archive.rar
set -o history
  • set +o history halts all history recording.
  • set -o history restores standard logging behavior after you finish executing your command.