Verify UnRAR Executable Integrity

This article explains how to verify the integrity and authenticity of the unrar executable. Because the command-line unrar utility does not feature a built-in flag or internal command to test its own running binary, verifying its integrity requires external validation methods. Below, you will learn why the utility cannot verify itself directly and how to confirm that your unrar binary is authentic and untampered with using cryptographic checksums, digital signatures, and system package managers.

Why UnRAR Cannot Verify Itself

The unrar command includes an integrity testing switch (unrar t <archive.rar>), but this command is designed exclusively to test the CRC and checksums of compressed files inside a RAR archive. A running executable cannot securely validate its own binary code in memory against tampering, as a compromised binary could simply forge a successful verification response. Consequently, executable verification must always be performed independently.

Verifying via Cryptographic Hashes

The most universal method to confirm the integrity of unrar is comparing its SHA-256 hash against the official hash provided by RARLAB or your distribution source.

  1. Locate the executable on your system:

    • On Linux/macOS: which unrar
    • On Windows: where unrar.exe
  2. Generate the SHA-256 hash of the binary:

    • Linux:
      sha256sum $(which unrar)
    • macOS:
      shasum -a 256 $(which unrar)
    • Windows (PowerShell):
      Get-FileHash (Get-Command unrar.exe).Source -Algorithm SHA256
  3. Compare the output hash string against the published checksum provided on the official download page. If the hashes match, the binary has not been modified or corrupted.

Verifying via Package Managers

If you installed unrar through your operating system's package manager, the package manager maintains cryptographic records to verify file integrity.

  • Debian/Ubuntu (APT):

    debsums unrar

    This command verifies the MD5 checksums of the installed unrar files against the distribution's package database.

  • Red Hat/Fedora/CentOS (RPM):

    rpm -V unrar

    If the executable has not been altered, this command produces no output.

  • Arch Linux (Pacman):

    pacman -Qk unrar

    This checks that the files match the original package state.

Verifying Digital Signatures

On Windows systems, official binaries distributed by RARLAB are digitally signed using Authenticode. You can inspect and verify the signature using PowerShell:

Get-AuthenticodeSignature (Get-Command unrar.exe).Source

Ensure the status returns Valid and the signer certificate is issued to Alexander Roshal or win.rar GmbH. If the signature is invalid or absent, the executable should not be trusted.