Securely Pass Password to Unrar Without Bash History
Extracting encrypted RAR archives on the command line can
inadvertently expose sensitive credentials if the password is typed
directly into the terminal. This guide covers how to pass passwords to
the unrar utility without saving them to your
.bash_history file, mitigating the risk of credential
leakage through terminal logs, shell history, and process
monitoring.
1. Use the Interactive Prompt (Most Secure)
The safest and most reliable way to supply a password to
unrar is to let the utility prompt you directly. This
avoids placing the password into the command line entirely, preventing
it from appearing in both your Bash history and the system's process
table (ps aux).
Run the extraction command without specifying the password value:
unrar x -p archive.rarAlternatively, omit the -p switch entirely:
unrar x archive.rarunrar will detect that the archive is encrypted and
prompt:
Enter password (will not be echoed) for archive.rar:
Type the password and press Enter. The input remains
hidden from the terminal display, Bash history, and external process
inspection.
2. Read into an
Environment Variable via read -s
If you are running commands interactively and do not want the
password saved in shell history, you can capture it silently into an
in-memory variable using read -s.
read -s -p "Archive Password: " RAR_PASS
unrar x -p"$RAR_PASS" archive.rar
unset RAR_PASSread -ssuppresses terminal echo, meaning characters do not print to the screen.- Because the password is captured as input rather than an executed
command, it never enters the
.bash_historyfile. unset RAR_PASSimmediately clears the variable from memory once the extraction completes.
Note: While this method protects your Bash history, the password
may briefly be visible to other local users viewing the process list
(ps aux) while unrar runs.
3. Prefix the
Command with a Space (HISTCONTROL)
Bash can be configured to ignore commands that begin with a leading
space. By default, many Linux distributions enable this behavior via the
HISTCONTROL environment variable.
Check your current configuration:
echo $HISTCONTROLIf the output contains ignorespace or
ignoreboth, any command prefixed with a space will not be
recorded in your history.
Execute your command with a leading space before
unrar:
unrar x -pSecretPassword archive.rarIf HISTCONTROL is not configured, enable it for your
current session:
export HISTCONTROL=ignorespace4. Temporarily Disable Bash History
If you need to run multiple commands without logging them, disable Bash history logging temporarily for the active shell session.
set +o history
unrar x -pSecretPassword archive.rar
set -o historyset +o historyhalts all history recording.set -o historyrestores standard logging behavior after you finish executing your command.