Webarchive Explained

Webarchive should not be confused with Web ARChive.

Web archive
Extension:.webarchive
Mime:application/x-webarchive
Uniform Type:com.apple.webarchive
Genre:web page file archive
Extended From:Apple Binary Property List

webarchive is a Web archive file format available on macOS and Windows for saving and reviewing complete web pages using the Safari web browser.[1] The webarchive format differs from a standalone HTML file because it also saves linked files such as images, CSS, and JavaScript.[2] The webarchive format is a concatenation of source files with filenames saved in the binary plist format using NSKeyedArchiver. Support for webarchive documents was added in Safari 4 Beta on Windows and is included in subsequent versions. Safari in iOS 13 (iPhone and iPad) has support for web archive files.[3] Previously there was a third party iOS app called Web Archive Viewer that provided this functionality.

Usage

Vulnerability

In February 2013, a vulnerability with the webarchive format was discovered and reported by Joe Vennix, a Metasploit Project developer. The exploit allows an attacker to send a crafted webarchive to a user containing code to access cookies, local files, and other data. Apple's response to the report was that it will not fix the bug, most likely because it requires action on the users' part in opening the file.[6]

Converting for other browsers

Workarounds to allow the file to be viewed in other browsers are possible, though specific webpage contents may hinder this process. This requires one of the free tools WebArchive Folderizer (for OS X 10.2 and higher)[1] or WebArchive Extractor (for OS X 10.4.3 and higher).[7]

Alternatives

MAFF is an open format (with a published specification) that enables saving of whole webpages in a single file. It is currently supported by Firefox, using an extension.[8] [9] Other web browsers use the MHTML format or do the equivalent by saving a directory of inline resources (usually images) alongside the HTML file, sometimes compressed, like the .war format used by Konqueror (tar+gzip or tar+bzip2). Safari does not support these alternative archive formats.

For archiving entire websites, the Internet Archive has developed the Web ARChive (WARC) format which was standardized by ISO.

HTMLD (HTML Directory) is a NeXT-developed format for saving web pages and their dependencies in a bundle that may also be served by a web server.[10]

Chrome offers the "webpage, complete" format which saves the page with a folder containing the required resources.

References

  1. Web site: Frakes . Dan . De-archive Web Archives . Macworld . IDG Communications . 15 June 2018.
  2. Web site: Arnott. Nick. Apple declines to fix vulnerability in Safari's Web Archive files, likely because it requires user action to exploit. iMore. 28 April 2013. Mobile Nations. 7 February 2015.
  3. Web site: iOS and IPadOS 13 Review. MacStories. 25 September 2019.
  4. Web site: iAd JS Programming Guide: Web Archives and Manifest Files. Mac Developer Library. Apple. 7 February 2015.
  5. Web site: WebArchive Class Reference. Mac Developer Library. Apple. 7 February 2015.
  6. Web site: Vennix. Joe. Abusing Safari's webarchive file format. Rapid7 Metasploit. 25 April 2013. Rapid7. 7 February 2015.
  7. https://robrohan.github.io/WebArchiveExtractor/ WebArchive Extractor
  8. Web site: Mozilla Archive Format, with MHT and Faithful Save . 8 December 2011. dead . https://web.archive.org/web/20171102005204/https://addons.mozilla.org/en-US/firefox/addon/mozilla-archive-format/ . 2 November 2017.
  9. Web site: WebScrapBook . 17 November 2019 .
  10. Web site: .htmld Discussion.