Unrar Log Output During Password Brute-Force Attacks

Automated password-cracking scripts targeting RAR archives typically execute the unrar utility repeatedly, testing each candidate string against the protected file. This article examines the exact terminal and log output generated by unrar during a brute-force attack, detailing the standard error messages, success responses, and return codes that scripts use to determine whether a password guess is valid.

Standard Output on Password Failure

When a script invokes unrar with an incorrect password—commonly using the test command unrar t -p<guess> <archive.rar> or the extract command unrar x -inul -p<guess> <archive.rar>—the utility attempts decompression and halts upon encountering a cryptographic or integrity check mismatch.

Without suppression flags, a failed attempt produces the following standard output (stdout/stderr):

UNRAR 6.x freeware      Copyright (c) 1993-2023 Alexander Roshal

Testing archive archive.rar

Testing     test.txt                                                  Failed
Checksum error in the encrypted file test.txt. Corrupt file or wrong password.
Total errors: 1

Depending on the specific unrar build and RAR format version (RAR4 vs. RAR5), the exact error string may also read:

Checksum error in test.txt (wrong password ?)

Encrypted File Headers vs. Standard Encryption

The output changes depending on whether the archive was created with standard encryption (-p) or encrypted headers (-hp):

  • Standard Encryption (-p): unrar can read the archive's central directory without the password. The output lists all contained filenames, their sizes, and timestamps, followed by a failure message only when attempting to decompress the individual file streams.
  • Encrypted Headers (-hp): unrar cannot parse the archive contents at all without the correct key. The log output will not list any contained files and immediately terminates:
Cannot open archive.rar
Corrupt file or wrong password.
Total errors: 1

Exit Codes Monitored by Scripts

Brute-force automation rarely parses the full text output. Instead, scripts inspect the process exit status (return code) immediately after execution.

  • Exit Code 3 (Fatal error / CRC failure): Indicates that extraction failed due to a checksum mismatch, signaling an incorrect password.
  • Exit Code 11 (Cannot open file): Returned if the header is encrypted and the candidate key cannot unlock the file structure.
  • Exit Code 0 (Success): Returned exclusively when the correct password is provided, extraction or testing succeeds, and no CRC errors occur.

Standard Output on Success

When the script delivers the matching password, unrar confirms extraction without errors:

Testing archive archive.rar

Testing     test.txt                                                  OK
All OK

Upon registering an exit status of 0 and the "All OK" string, the brute-force script terminates execution and outputs the recovered key.