Unrar Log Output During Password Brute-Force Attacks
Automated password-cracking scripts targeting RAR archives typically
execute the unrar utility repeatedly, testing each
candidate string against the protected file. This article examines the
exact terminal and log output generated by unrar during a
brute-force attack, detailing the standard error messages, success
responses, and return codes that scripts use to determine whether a
password guess is valid.
Standard Output on Password Failure
When a script invokes unrar with an incorrect
password—commonly using the test command
unrar t -p<guess> <archive.rar> or the extract
command
unrar x -inul -p<guess> <archive.rar>—the
utility attempts decompression and halts upon encountering a
cryptographic or integrity check mismatch.
Without suppression flags, a failed attempt produces the following standard output (stdout/stderr):
UNRAR 6.x freeware Copyright (c) 1993-2023 Alexander Roshal
Testing archive archive.rar
Testing test.txt Failed
Checksum error in the encrypted file test.txt. Corrupt file or wrong password.
Total errors: 1
Depending on the specific unrar build and RAR format
version (RAR4 vs. RAR5), the exact error string may also read:
Checksum error in test.txt (wrong password ?)
Encrypted File Headers vs. Standard Encryption
The output changes depending on whether the archive was created with
standard encryption (-p) or encrypted headers
(-hp):
- Standard Encryption (
-p):unrarcan read the archive's central directory without the password. The output lists all contained filenames, their sizes, and timestamps, followed by a failure message only when attempting to decompress the individual file streams. - Encrypted Headers (
-hp):unrarcannot parse the archive contents at all without the correct key. The log output will not list any contained files and immediately terminates:
Cannot open archive.rar
Corrupt file or wrong password.
Total errors: 1
Exit Codes Monitored by Scripts
Brute-force automation rarely parses the full text output. Instead, scripts inspect the process exit status (return code) immediately after execution.
- Exit Code 3 (Fatal error / CRC failure): Indicates that extraction failed due to a checksum mismatch, signaling an incorrect password.
- Exit Code 11 (Cannot open file): Returned if the header is encrypted and the candidate key cannot unlock the file structure.
- Exit Code 0 (Success): Returned exclusively when the correct password is provided, extraction or testing succeeds, and no CRC errors occur.
Standard Output on Success
When the script delivers the matching password, unrar
confirms extraction without errors:
Testing archive archive.rar
Testing test.txt OK
All OK
Upon registering an exit status of 0 and the "All OK"
string, the brute-force script terminates execution and outputs the
recovered key.