[WebUi] Scan page takes too long to load
Hello, testing last (Aug 06, 2016) nightly. After few scans run for 4 hours, some of scan pages it started to take too long to load (of course refreshing them takes a lot of time too), i'm sure that is because of gigant errors logs, which are kept in RAM. Is there an option to disable errors or to switch them logging to disk without any output of them to webUI ?
Thanks
Showing page 2 out of 2. View the first page
Comments are currently closed for this discussion. You can start a new one.
Keyboard shortcuts
Generic
| ? | Show this help |
|---|---|
| ESC | Blurs the current field |
Comment Form
| r | Focus the comment reply box |
|---|---|
| ^ + ↩ | Submit the comment |
You can use Command ⌘ instead of Control ^ on Mac
Support Staff 31 Posted by Tasos Laskos on 09 Aug, 2016 08:32 AM
How many issue did it log?
32 Posted by John on 09 Aug, 2016 08:35 AM
tried with sql inj profile - nothing, now going to try with default
Support Staff 33 Posted by Tasos Laskos on 09 Aug, 2016 08:37 AM
OK, keep an eye on the stats again and let me know how it goes.
34 Posted by John on 09 Aug, 2016 08:53 AM
16 issues, 140 r/s ata start and ~150 stable, no timeouts, no perfomance drops
Support Staff 35 Posted by Tasos Laskos on 09 Aug, 2016 09:08 AM
That's good, I must again say that I don't see a problem with Arachni.
When a site is responsive it performs well, when it's not, performance drops.
36 Posted by John on 09 Aug, 2016 09:14 AM
but why even if website is slow arachni don't stop decreasing it's speed?
Support Staff 37 Posted by Tasos Laskos on 09 Aug, 2016 09:19 AM
Arachni isn't in charge of that, it can't force a certain speed, it just consumes the responses at the speed the server sends them.
If the server gets stressed more and more over time, it'll keep getting slower.
In your case, performance was slow because the server was slow.
Then you disabled
autothrottleand increased the request concurrency from 20 to 30, which created even more stress on the server and performance dropped even lower to 2-3r/s.Nothing, from the beginning of this discussion, has pointed to an issue in Arachni.
38 Posted by John on 09 Aug, 2016 09:38 AM
this problem seem to be solvable by forcing some number of threads, as it seems to me, even if concurency at maximum,and speed drops to 2-3 r/s - so value of threads is dynamic?
Support Staff 39 Posted by Tasos Laskos on 09 Aug, 2016 09:54 AM
There are no threads in that part of the system, the HTTP client uses non-blocking sockets.
But yeah, concurrency is dynamic and is controlled by the
autothrottleplugin, if response times exceed 1s it decreases the concurrency, when response times get better it increases it up to the specified maximum.That's all to keep the server from getting too stressed.
That problem is not solvable by increasing the concurrency because too many requests at the same time can stress the server and make it slower or completely unresponsive.
40 Posted by John on 09 Aug, 2016 10:12 AM
are concurency=threads so ?
41 Posted by John on 10 Aug, 2016 05:40 PM
Hello, running 7 parralel scans, tried to restart the most fast and see what i got after restart (see atached file), before restart it was running at 40 r/s and 0.39-0.41 response. Website isn't slow, i saw it by previous arachni scan, which was running for 8 hours with stable stats (40 r/s and 0.39-0.41). Also nothing could happen to the website during 3-5 seconds while i was restarting it. Please, check arachni,
Thanks
42 Posted by John on 11 Aug, 2016 06:38 PM
problem seems to be solved by forcing concurency level, thanks for help
John closed this discussion on 11 Aug, 2016 06:40 PM.