Arachni / arachni

Web Application Security Scanner Framework
http://www.arachni-scanner.com
Other
3.77k stars 763 forks source link

Scan fails to complete (2) #755

Closed morph2 closed 8 years ago

morph2 commented 8 years ago

The following errors popped up.

2016-08-04 16:21:48 +0100 --------------------------------------------------------------------------------
ENV:

---
CPLUS_INCLUDE_PATH: "/usr/share/arachni/bin/../system/usr/include"
XDG_VTNR: '2'
VNCDESKTOP: x11
SSH_AGENT_PID: '2528'
XDG_SESSION_ID: '46'
DISPLAYNUM: '1'
SAL_USE_VCLPLUGIN: gtk
HOSTNAME: kali
XKL_XMODMAP_DISABLE: '1'
GEM_HOME: "/usr/share/arachni/system/gems"
SHELL: "/bin/bash"
TERM: xterm-256color
XDG_MENU_PREFIX: lxde-
VTE_VERSION: '4402'
IRBRC: "/usr/share/arachni/bin/../system/usr/lib/ruby/.irbrc"
LIBRARY_PATH: "/usr/share/arachni/bin/../system/usr/lib:/usr/lib:/usr/local/lib"
QT_LINUX_ACCESSIBILITY_ALWAYS_ON: '1'
WINDOWID: '33554437'
MY_RUBY_HOME: "/usr/share/arachni/bin/../system/usr/lib/ruby"
GTK_MODULES: gail:atk-bridge
USER: root
LD_LIBRARY_PATH: "/usr/share/arachni/bin/../system/usr/lib:/usr/lib:/usr/local/lib"
LS_COLORS: 'rs=0:di=01;34:ln=01;36:mh=00:pi=40;33:so=01;35:do=01;35:bd=40;33;01:cd=40;33;01:or=40;31;01:mi=00:su=37;41:sg=30;43:ca=30;41:tw=30;42:ow=34;42:st=37;44:ex=01;32:*.tar=01;31:*.tgz=01;31:*.arc=01;31:*.arj=01;31:*.taz=01;31:*.lha=01;31:*.lz4=01;31:*.lzh=01;31:*.lzma=01;31:*.tlz=01;31:*.txz=01;31:*.tzo=01;31:*.t7z=01;31:*.zip=01;31:*.z=01;31:*.Z=01;31:*.dz=01;31:*.gz=01;31:*.lrz=01;31:*.lz=01;31:*.lzo=01;31:*.xz=01;31:*.bz2=01;31:*.bz=01;31:*.tbz=01;31:*.tbz2=01;31:*.tz=01;31:*.deb=01;31:*.rpm=01;31:*.jar=01;31:*.war=01;31:*.ear=01;31:*.sar=01;31:*.rar=01;31:*.alz=01;31:*.ace=01;31:*.zoo=01;31:*.cpio=01;31:*.7z=01;31:*.rz=01;31:*.cab=01;31:*.jpg=01;35:*.jpeg=01;35:*.gif=01;35:*.bmp=01;35:*.pbm=01;35:*.pgm=01;35:*.ppm=01;35:*.tga=01;35:*.xbm=01;35:*.xpm=01;35:*.tif=01;35:*.tiff=01;35:*.png=01;35:*.svg=01;35:*.svgz=01;35:*.mng=01;35:*.pcx=01;35:*.mov=01;35:*.mpg=01;35:*.mpeg=01;35:*.m2v=01;35:*.mkv=01;35:*.webm=01;35:*.ogm=01;35:*.mp4=01;35:*.m4v=01;35:*.mp4v=01;35:*.vob=01;35:*.qt=01;35:*.nuv=01;35:*.wmv=01;35:*.asf=01;35:*.rm=01;35:*.rmvb=01;35:*.flc=01;35:*.avi=01;35:*.fli=01;35:*.flv=01;35:*.gl=01;35:*.dl=01;35:*.xcf=01;35:*.xwd=01;35:*.yuv=01;35:*.cgm=01;35:*.emf=01;35:*.ogv=01;35:*.ogx=01;35:*.aac=00;36:*.au=00;36:*.flac=00;36:*.m4a=00;36:*.mid=00;36:*.midi=00;36:*.mka=00;36:*.mp3=00;36:*.mpc=00;36:*.ogg=00;36:*.ra=00;36:*.wav=00;36:*.oga=00;36:*.opus=00;36:*.spx=00;36:*.xspf=00;36:'
QT_ACCESSIBILITY: '1'
SSH_AUTH_SOCK: "/tmp/ssh-JBiQHeBe4amk/agent.2458"
USERNAME: root
XDG_CONFIG_DIRS: "/etc/xdg"
PATH: "/usr/share/arachni/system/gems/bin:/usr/share/arachni/bin/../system/../bin:/usr/share/arachni/bin/../system/usr/bin:/usr/share/arachni/bin/../system/gems/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
DESKTOP_SESSION: LXDE
C_INCLUDE_PATH: "/usr/share/arachni/bin/../system/usr/include"
XDG_SESSION_TYPE: x11
PWD: "/usr/share/arachni/bin"
ARACHNI_WEBUI_LOGDIR: "/usr/share/arachni/bin/../system/logs/webui"
LANG: en_GB.UTF-8
GDM_LANG: en_GB.UTF-8
ARACHNI_FRAMEWORK_LOGDIR: "/usr/share/arachni/bin/../system/logs/framework"
GDMSESSION: default
_LXSESSION_PID: '2682'
XDG_SEAT: seat0
HOME: "/usr/share/arachni/bin/../system/home/arachni"
SHLVL: '4'
XDG_CONFIG_HOME: "/root/.config"
RAILS_ENV: production
DYLD_LIBRARY_PATH: "/usr/share/arachni/bin/../system/usr/lib:/usr/lib:/usr/local/lib"
XDG_SESSION_DESKTOP: default
LOGNAME: root
GEM_PATH: "/usr/share/arachni/bin/../system/gems"
XDG_DATA_DIRS: "/usr/local/share:/usr/share:/usr/share/gdm:/var/lib/menu-xdg:/usr/local/share/:/usr/share/:/usr/share/gdm/:/var/lib/menu-xdg/"
DBUS_SESSION_BUS_ADDRESS: unix:abstract=/tmp/dbus-6qfaZa2SEs,guid=75bf0a04471db221666218b457a344d3
WINDOWPATH: '2'
XDG_RUNTIME_DIR: "/run/user/0"
DISPLAY: ":1"
XDG_CURRENT_DESKTOP: LXDE
RUBYLIB: "/usr/share/arachni/system/gems/gems/bundler-1.11.2/lib:/usr/share/arachni/bin/../system/usr/lib/ruby:/usr/share/arachni/bin/../system/usr/lib/ruby/site_ruby/2.2.0:/usr/share/arachni/bin/../system/usr/lib/ruby/2.2.0:/usr/share/arachni/bin/../system/usr/lib/ruby/2.2.0/x86_64-linux:/usr/share/arachni/bin/../system/usr/lib/ruby/site_ruby/2.2.0/x86_64-linux"
RUBY_VERSION: ruby-2.2.3
COLORTERM: truecolor
XAUTHORITY: "/root/.Xauthority"
RACK_ENV: development
BUNDLE_GEMFILE: "/usr/share/arachni/system/arachni-ui-web/Gemfile"
_ORIGINAL_GEM_PATH: "/usr/share/arachni/bin/../system/gems"
BUNDLE_BIN_PATH: "/usr/share/arachni/system/gems/gems/bundler-1.11.2/exe/bundle"
RUBYOPT: "-rbundler/setup"
MANPATH: "/usr/share/arachni/system/gems/gems/kramdown-1.4.1/man"
BUNDLE_ORIG_MANPATH: "/usr/share/arachni/system/gems/gems/kramdown-1.4.1/man"
--------------------------------------------------------------------------------
OPTIONS:

---
browser_cluster:
  local_storage: {}
  wait_for_elements: {}
  pool_size: 6
  job_timeout: 25
  worker_time_to_live: 100
  ignore_images: false
  screen_width: 1600
  screen_height: 1200
scope:
  redundant_path_patterns: {}
  dom_depth_limit: 5
  exclude_file_extensions: []
  exclude_path_patterns: []
  exclude_content_patterns: []
  include_path_patterns: []
  restrict_paths: []
  extend_paths: []
  url_rewrites: {}
session: {}
audit:
  parameter_values: true
  exclude_vector_patterns: []
  include_vector_patterns: []
  link_templates: []
  links: true
  forms: true
  cookies: true
  jsons: true
  xmls: true
  ui_forms: true
  ui_inputs: true
input:
  values:
    name: arachni_name
    user: arachni_user
    usr: arachni_user
    pass: 5543!%arachni_secret
    txt: arachni_text
    num: '132'
    amount: '100'
    mail: arachni@email.gr
    account: '12'
    id: '1'
  default_values:
    name: arachni_name
    user: arachni_user
    usr: arachni_user
    pass: 5543!%arachni_secret
    txt: arachni_text
    num: '132'
    amount: '100'
    mail: arachni@email.gr
    account: '12'
    id: '1'
  without_defaults: true
  force: false
datastore:
  token: 9ee768fee34b5377075edf72e507bf36
http:
  user_agent: Arachni/v1.4
  request_timeout: 10000
  request_redirect_limit: 5
  request_concurrency: 20
  request_queue_size: 100
  request_headers: {}
  response_max_size: 500000
  cookies: {}
checks:
- allowed_methods
- backdoors
- backup_directories
- backup_files
- captcha
- code_injection
- code_injection_php_input_wrapper
- code_injection_timing
- common_admin_interfaces
- common_directories
- common_files
- cookie_set_for_parent_domain
- credit_card
- csrf
- cvs_svn_users
- directory_listing
- emails
- file_inclusion
- form_upload
- hsts
- htaccess_limit
- html_objects
- http_only_cookies
- http_put
- insecure_client_access_policy
- insecure_cookies
- insecure_cors_policy
- insecure_cross_domain_policy_access
- insecure_cross_domain_policy_headers
- interesting_responses
- ldap_injection
- localstart_asp
- mixed_resource
- no_sql_injection
- no_sql_injection_differential
- origin_spoof_access_restriction_bypass
- os_cmd_injection
- os_cmd_injection_timing
- password_autocomplete
- path_traversal
- private_ip
- response_splitting
- rfi
- session_fixation
- source_code_disclosure
- sql_injection
- sql_injection_differential
- sql_injection_timing
- ssn
- trainer
- unencrypted_password_forms
- unvalidated_redirect
- unvalidated_redirect_dom
- webdav
- x_frame_options
- xpath_injection
- xss
- xss_dom
- xss_dom_script_context
- xss_event
- xss_path
- xss_script_context
- xss_tag
- xst
- xxe
platforms: []
plugins:
  autothrottle: {}
  discovery: {}
  healthmap: {}
  timing_attacks: {}
  uniformity: {}
no_fingerprinting: false
authorized_by: 
url: http://<REDACTED>
--------------------------------------------------------------------------------
[2016-08-04 16:21:48 +0100] [Net::OpenTimeout] execution expired
[2016-08-04 16:21:48 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/support/database/queue.rb:86:in `sleep'
[2016-08-04 16:21:48 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/support/database/queue.rb:86:in `block (2 levels) in pop'
[2016-08-04 16:21:48 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/support/database/queue.rb:82:in `loop'
[2016-08-04 16:21:48 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/support/database/queue.rb:82:in `block in pop'
[2016-08-04 16:21:48 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/support/database/queue.rb:148:in `synchronize'
[2016-08-04 16:21:48 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/support/database/queue.rb:148:in `synchronize'
[2016-08-04 16:21:48 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/support/database/queue.rb:81:in `pop'
[2016-08-04 16:21:48 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster.rb:311:in `pop'
[2016-08-04 16:21:48 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:214:in `block (2 levels) in start'
[2016-08-04 16:21:48 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `call'
[2016-08-04 16:21:48 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `exception_jail'
[2016-08-04 16:21:48 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:213:in `block in start'
[2016-08-04 16:21:48 +0100] 
[2016-08-04 16:21:48 +0100] Parent:
[2016-08-04 16:21:48 +0100] Arachni::BrowserCluster::Worker
[2016-08-04 16:21:48 +0100] 
[2016-08-04 16:21:48 +0100] Block:
[2016-08-04 16:21:48 +0100] #<Proc:0x000000029284a0@/usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:213>
[2016-08-04 16:21:48 +0100] 
[2016-08-04 16:21:48 +0100] Caller:
[2016-08-04 16:21:48 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `exception_jail'
[2016-08-04 16:21:48 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:213:in `block in start'
[2016-08-04 16:21:48 +0100] --------------------------------------------------------------------------------
[2016-08-04 17:48:10 +0100] [HTTP: 0] http://xavier.cp.local/Bria-X-P1.aspx?ItemId=30728&Options=_arachni_trainer_43417d00f9dcc79f99c625d728e4086a
[2016-08-04 17:48:10 +0100] [operation_timedout] Timeout was reached
[2016-08-04 20:03:55 +0100] [Net::OpenTimeout] execution expired
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/protocol.rb:155:in `select'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/protocol.rb:155:in `rescue in rbuf_fill'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/protocol.rb:152:in `rbuf_fill'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/protocol.rb:134:in `readuntil'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/protocol.rb:144:in `readline'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http/response.rb:39:in `read_status_line'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http/response.rb:28:in `read_new'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http.rb:1414:in `block in transport_request'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http.rb:1411:in `catch'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http.rb:1411:in `transport_request'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http.rb:1384:in `request'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http.rb:1377:in `block in request'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http.rb:853:in `start'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http.rb:1375:in `request'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/remote/http/default.rb:107:in `response_for'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/remote/http/default.rb:58:in `request'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/remote/http/common.rb:59:in `call'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/remote/bridge.rb:645:in `raw_execute'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/remote/bridge.rb:623:in `execute'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/remote/bridge.rb:592:in `find_element_by'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/common/search_context.rb:61:in `find_element'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser/element_locator.rb:70:in `locate'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:700:in `block in fire_event'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/common/wait.rb:58:in `until'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:700:in `fire_event'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:658:in `trigger_event'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/jobs/dom_exploration/event_trigger.rb:38:in `run'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/job.rb:105:in `configure_and_run'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:87:in `block (2 levels) in run_job'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `call'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `exception_jail'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:85:in `block in run_job'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:1245:in `call'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:1245:in `block in with_timeout'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:88:in `block in timeout'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:32:in `block in catch'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:32:in `catch'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:32:in `catch'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:103:in `timeout'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:1244:in `with_timeout'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:84:in `run_job'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:215:in `block (3 levels) in start'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `call'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `exception_jail'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:215:in `block (2 levels) in start'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `call'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `exception_jail'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:213:in `block in start'
[2016-08-04 20:03:55 +0100] 
[2016-08-04 20:03:55 +0100] Parent:
[2016-08-04 20:03:55 +0100] Arachni::BrowserCluster::Worker
[2016-08-04 20:03:55 +0100] 
[2016-08-04 20:03:55 +0100] Block:
[2016-08-04 20:03:55 +0100] #<Proc:0x007f70f40381f0@/usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:85>
[2016-08-04 20:03:55 +0100] 
[2016-08-04 20:03:55 +0100] Caller:
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `exception_jail'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:85:in `block in run_job'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:1245:in `call'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:1245:in `block in with_timeout'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:88:in `block in timeout'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:32:in `block in catch'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:32:in `catch'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:32:in `catch'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:103:in `timeout'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:1244:in `with_timeout'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:84:in `run_job'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:215:in `block (3 levels) in start'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `call'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `exception_jail'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:215:in `block (2 levels) in start'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `call'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `exception_jail'
[2016-08-04 20:03:55 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:213:in `block in start'
[2016-08-04 20:03:55 +0100] --------------------------------------------------------------------------------
[2016-08-04 23:24:54 +0100] [Net::OpenTimeout] execution expired
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/protocol.rb:155:in `select'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/protocol.rb:155:in `rescue in rbuf_fill'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/protocol.rb:152:in `rbuf_fill'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/protocol.rb:134:in `readuntil'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/protocol.rb:144:in `readline'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http/response.rb:39:in `read_status_line'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http/response.rb:28:in `read_new'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http.rb:1414:in `block in transport_request'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http.rb:1411:in `catch'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http.rb:1411:in `transport_request'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http.rb:1384:in `request'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http.rb:1377:in `block in request'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http.rb:853:in `start'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/net/http.rb:1375:in `request'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/remote/http/default.rb:107:in `response_for'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/remote/http/default.rb:58:in `request'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/remote/http/common.rb:59:in `call'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/remote/bridge.rb:645:in `raw_execute'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/remote/bridge.rb:623:in `execute'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/remote/bridge.rb:134:in `get'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/selenium-webdriver-2.51.0/lib/selenium/webdriver/common/navigation.rb:33:in `to'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:371:in `block in goto'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/page/dom/transition.rb:151:in `call'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/page/dom/transition.rb:151:in `start'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/page/dom/transition.rb:106:in `initialize'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:366:in `new'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:366:in `goto'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/page/dom.rb:150:in `restore'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:280:in `load'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/jobs/dom_exploration/event_trigger.rb:34:in `run'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/job.rb:105:in `configure_and_run'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:87:in `block (2 levels) in run_job'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `call'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `exception_jail'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:85:in `block in run_job'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:1245:in `call'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:1245:in `block in with_timeout'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:88:in `block in timeout'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:32:in `block in catch'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:32:in `catch'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:32:in `catch'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:103:in `timeout'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:1244:in `with_timeout'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:84:in `run_job'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:215:in `block (3 levels) in start'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `call'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `exception_jail'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:215:in `block (2 levels) in start'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `call'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `exception_jail'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:213:in `block in start'
[2016-08-04 23:24:54 +0100] 
[2016-08-04 23:24:54 +0100] Parent:
[2016-08-04 23:24:54 +0100] Arachni::BrowserCluster::Worker
[2016-08-04 23:24:54 +0100] 
[2016-08-04 23:24:54 +0100] Block:
[2016-08-04 23:24:54 +0100] #<Proc:0x00000004257bd8@/usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:85>
[2016-08-04 23:24:54 +0100] 
[2016-08-04 23:24:54 +0100] Caller:
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `exception_jail'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:85:in `block in run_job'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:1245:in `call'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:1245:in `block in with_timeout'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:88:in `block in timeout'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:32:in `block in catch'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:32:in `catch'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:32:in `catch'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/usr/lib/ruby/2.2.0/timeout.rb:103:in `timeout'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser.rb:1244:in `with_timeout'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:84:in `run_job'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:215:in `block (3 levels) in start'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `call'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `exception_jail'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:215:in `block (2 levels) in start'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `call'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/utilities.rb:425:in `exception_jail'
[2016-08-04 23:24:54 +0100] /usr/share/arachni/system/gems/gems/arachni-1.4/lib/arachni/browser_cluster/worker.rb:213:in `block in start'
[2016-08-04 23:24:54 +0100] --------------------------------------------------------------------------------
Zapotek commented 8 years ago

Can you retry with the nightlies please?

morph2 commented 8 years ago

OK, I did that. It ran for about a day and a bit, then firefox (on linux) popped up a message about a script not responding on the page. I refreshed and it just hung. I restarted Firefox, and tried to login. After the initial page I clicked on my previous run to show me the scan (still running) and it paused about a minute and said "Sorry something has gone wrong". I restarted Firefox again and there are errors on the scan page now. Attached. Also, the errors found in the scan results - quite a few seem duplicated. It's still running so I can't get a report yet - if you know how to stop the background scan without destroying the results let me know and I'll send you that report as well. The errors file is quite large (3MB). errors.zip

I notice there are about 10K files in /tmp called Arachni_Support_Database_Queue_2663

These get deleted and created, but there are about 10K of them at any one time.

The website is tiny. It's "discovered" about 100 pages and I have not provided any login creds. It seems to take an extraordinary amount of time to run and not yet finish :-(

Mike

Zapotek commented 8 years ago

I updated the nightlies with a longer time-out period so these errors should now go away. The files under /tmp/ are data that are being off-loaded to disk, probably browser jobs and page snapshots.

About the site, any chance I can have a look at it myself? You can send the details via e-mail if you prefer.

Zapotek commented 8 years ago

Btw, let's stick with the CLI instead of the WebUI while we work to resolve this issue, it will provide more feedback during the scan.

Thanks

morph2 commented 8 years ago

OK. I can do the CLI, no problem. The site is over a VPN so that won't be possible for you to access it, right now .... Once it's live though... I'd be happy to let you replicate, but am also very willing to assist in debugging now. OOI, for such a "small" site, what period should I be looking at for Arachni to complete? It's not always obvious what is taking so long and why there are so many requests being sent for so few pages (700K so far...).

I'll kill the processes, update the nightlies and run the CLI instead.

morph2 commented 8 years ago

BTW - are there any specific cmd line args you want me to use to assist? I am using right now:

arachni --output-verbose --report-save-path=pwd/xavier.afr http://[my url] >arachni.log 2>&1

Zapotek commented 8 years ago

Even a small site can generate a lot of workload via dynamic content. For example, if there's a calendar-like system the scan will take forever unless you configure the system to limit scanning redundant pages. Or, the dynamic content can be client-side, like JavaScript creating a large number of DOM states that need to be checked.

This article can help you optimize your configuration.

About CLI args, these are OK for now; let me know if you come across any errors and we'll go from there.

morph2 commented 8 years ago

OK, It's hung again with all jobs timing out. The log is huge, 61MB compressed. I also have an arachni error output log file (much smaller). I'd prefer not to post them here. How can I get them to you? I can create a dropbox link but would prefer a non-forum email to send that to as I don't know what is inside these logs...

Zapotek commented 8 years ago

You can send the error log at tasos.laskos@gmail.com

Zapotek commented 8 years ago

I think that the errors in the log you sent are fixed in the latest nightlies. Can you give them a try please?

morph2 commented 8 years ago

OK. Its been running a day and for some reason Ruby mem size exceeded 3GB, so I had to kill it and increase the memory on the VM. Should it get that large? That sorta surprised me - memory leak?

Also I added an auto-redundant flag to the parameters but I am not quite sure what would be looping. It's not clear to me why its taking so long - I have not provided any login creds for arachni so the pages it can crawl are extremely limited. The verbose output file ... can that tell me what is looping or creating such a large amount of work? There is no picture gallery or calendar available but there is a basket for adding items to purchase.

Zapotek commented 8 years ago

3GB is a lot, I don't know if it's a leak or just too much data, I'd need to run a few scans to determine that and why the scan is taking a long time.

Zapotek commented 8 years ago

Closing this since the original issue has been resolved. If anything else comes up please open a new issue.