[WebUi] Scan page takes too long to load

John's Avatar

John

06 Aug, 2016 06:27 PM

Hello, testing last (Aug 06, 2016) nightly. After few scans run for 4 hours, some of scan pages it started to take too long to load (of course refreshing them takes a lot of time too), i'm sure that is because of gigant errors logs, which are kept in RAM. Is there an option to disable errors or to switch them logging to disk without any output of them to webUI ?

Thanks

Showing page 2 out of 2. View the first page

  1. Support Staff 31 Posted by Tasos Laskos on 09 Aug, 2016 08:32 AM

    Tasos Laskos's Avatar

    How many issue did it log?

  2. 32 Posted by John on 09 Aug, 2016 08:35 AM

    John's Avatar

    tried with sql inj profile - nothing, now going to try with default

  3. Support Staff 33 Posted by Tasos Laskos on 09 Aug, 2016 08:37 AM

    Tasos Laskos's Avatar

    OK, keep an eye on the stats again and let me know how it goes.

  4. 34 Posted by John on 09 Aug, 2016 08:53 AM

    John's Avatar

    16 issues, 140 r/s ata start and ~150 stable, no timeouts, no perfomance drops

  5. Support Staff 35 Posted by Tasos Laskos on 09 Aug, 2016 09:08 AM

    Tasos Laskos's Avatar

    That's good, I must again say that I don't see a problem with Arachni.
    When a site is responsive it performs well, when it's not, performance drops.

  6. 36 Posted by John on 09 Aug, 2016 09:14 AM

    John's Avatar

    but why even if website is slow arachni don't stop decreasing it's speed?

  7. Support Staff 37 Posted by Tasos Laskos on 09 Aug, 2016 09:19 AM

    Tasos Laskos's Avatar

    Arachni isn't in charge of that, it can't force a certain speed, it just consumes the responses at the speed the server sends them.
    If the server gets stressed more and more over time, it'll keep getting slower.

    In your case, performance was slow because the server was slow.
    Then you disabled autothrottle and increased the request concurrency from 20 to 30, which created even more stress on the server and performance dropped even lower to 2-3r/s.

    Nothing, from the beginning of this discussion, has pointed to an issue in Arachni.

  8. 38 Posted by John on 09 Aug, 2016 09:38 AM

    John's Avatar

    this problem seem to be solvable by forcing some number of threads, as it seems to me, even if concurency at maximum,and speed drops to 2-3 r/s - so value of threads is dynamic?

  9. Support Staff 39 Posted by Tasos Laskos on 09 Aug, 2016 09:54 AM

    Tasos Laskos's Avatar

    There are no threads in that part of the system, the HTTP client uses non-blocking sockets.
    But yeah, concurrency is dynamic and is controlled by the autothrottle plugin, if response times exceed 1s it decreases the concurrency, when response times get better it increases it up to the specified maximum.
    That's all to keep the server from getting too stressed.

    That problem is not solvable by increasing the concurrency because too many requests at the same time can stress the server and make it slower or completely unresponsive.

  10. 40 Posted by John on 09 Aug, 2016 10:12 AM

    John's Avatar

    are concurency=threads so ?

  11. 41 Posted by John on 10 Aug, 2016 05:40 PM

    John's Avatar

    Hello, running 7 parralel scans, tried to restart the most fast and see what i got after restart (see atached file), before restart it was running at 40 r/s and 0.39-0.41 response. Website isn't slow, i saw it by previous arachni scan, which was running for 8 hours with stable stats (40 r/s and 0.39-0.41). Also nothing could happen to the website during 3-5 seconds while i was restarting it. Please, check arachni,

    Thanks

  12. 42 Posted by John on 11 Aug, 2016 06:38 PM

    John's Avatar

    problem seems to be solved by forcing concurency level, thanks for help

  13. John closed this discussion on 11 Aug, 2016 06:40 PM.

Comments are currently closed for this discussion. You can start a new one.

Keyboard shortcuts

Generic

? Show this help
ESC Blurs the current field

Comment Form

r Focus the comment reply box
^ + ↩ Submit the comment

You can use Command ⌘ instead of Control ^ on Mac