• Resolved sfaught

    (@sfaught)


    When I scan my websites it gets stuck on “Comparing core WordPress files against originals in repository” & “Scanning for known malware files” and hangs there indefinitely, just showing the moving black bars. Can anyone suggest what the problem might be and what I can do to fix it?

    https://wordpress.org/plugins/wordfence/

Viewing 15 replies - 1 through 15 (of 16 total)
  • Thread Starter sfaught

    (@sfaught)

    Sorry the above post should have said…

    When I scan my websites it gets stuck on “Scanning file contents for infections and vulnerabilities” & “Scanning files for URLs in Google’s Safe Browsing List” and hangs there indefinitely, just showing the moving black bars. Can anyone suggest what the problem might be and what I can do to fix it?

    WFSupport

    (@wfsupport)

    Can you enable debugging mode (near bottom of options page) and paste the last ten lines or so of the scan details here?

    tim

    Thread Starter sfaught

    (@sfaught)

    Thanks for the response, here are the last 10 or so…

    [Aug 28 15:59:39] Scanned contents of 1444 additional files at 2.62 per second
    [Aug 28 15:59:43] Scanned contents of 1445 additional files at 2.61 per second
    [Aug 28 15:59:44] Scanned contents of 1456 additional files at 2.62 per second
    [Aug 28 15:59:45] Scanned contents of 1463 additional files at 2.63 per second
    [Aug 28 15:59:46] Scanned contents of 1473 additional files at 2.64 per second
    [Aug 28 15:59:47] Scanned contents of 1483 additional files at 2.65 per second
    [Aug 28 15:59:53] Scanned contents of 1485 additional files at 2.63 per second
    [Aug 28 16:19:32] Scan kill request received.
    [Aug 28 16:31:31] Calling Wordfence API v2.17:https://noc1.wordfence.com//v2.17/?v=4.3&s=http%3A%2F%2Fvvdisposal.com&k=6e30e10d6928dbc26086504b5ed4688ddf470a7

    Thread Starter sfaught

    (@sfaught)

    It finished that time, thanks!!!

    Plugin Author WFMattR

    (@wfmattr)

    If it happens again, let us know — normally you should turn debugging mode back off after testing for problems, since it will cause a lot more information to be logged in your database, but in this case, it may just be chance that the scan was successful without any messages logged.

    Often, when the scan hangs where yours did, it is either a memory or a timeout issue — if you see a message about running out of memory, there is a setting you can adjust in your Wordfence options:
    How much memory should Wordfence request when scanning”

    Thread Starter sfaught

    (@sfaught)

    It happened again, I have since updated to pro hoping that would help but it keeps hanging. Below is the Scan Details with debugging on…
    [Sep 02 16:34:43] Scanning contents: wp-content/themes/Minamaze_Pro/lib/shortcodes/configs/font-general-settings.php (Size:5659B Mem:36.5M)
    [Sep 02 16:34:43] Scanning contents: wp-content/themes/Minamaze_Pro/lib/shortcodes/configs/slider_blog-settings.php (Size:1179B Mem:36.5M)
    [Sep 02 16:34:43] Scanning contents: wp-content/uploads/2015/06/20150608_151148-320×256.jpg (Size:38784B Mem:36.5M)
    [Sep 02 16:34:43] Scanning contents: wp-content/themes/Minamaze_Pro/admin/main/assets/img/layout/portfolio/option02.png (Size:1045B Mem:36.5M)
    [Sep 02 16:34:43] Scanning contents: wp-content/themes/Minamaze_Pro/admin/main/inc/fields/dimensions/field_dimensions.min.js (Size:600B Mem:36.5M)
    [Sep 02 16:34:43] Scanning contents: wp-content/uploads/2015/06/8×20-320×192.jpg (Size:7724B Mem:36.5M)
    [Sep 02 16:34:44] Scanning contents: wp-content/themes/Minamaze_Pro/lib/shortcodes/includes/element-five_sixth_last.php (Size:111B Mem:36.5M)
    [Sep 02 16:34:44] Scanned contents of 1135 additional files at 0.86 per second
    [Sep 02 16:34:44] Scanning contents: wp-content/themes/Minamaze_Pro/lib/shortcodes/includes/element-button3.php (Size:404B Mem:36.5M)
    [Sep 02 16:34:44] Scanning contents: wp-content/uploads/2015/06/20150608_151324_Riverside-Rd-320×107.jpg (Size:26008B Mem:36.5M)
    [Sep 02 16:34:44] Scanning contents: wp-content/updraft/backup_2015-09-01-1814_Valley_Storage_44b691af73f7-plugins.zip.tmp (Size:14.07M Mem:36.5M)

    Thread Starter sfaught

    (@sfaught)

    This is another site with the same problem…

    [Sep 02 16:40:49] Scanning contents: dev.vvdisposal.com/wp-content/plugins/updraftplus/languages/updraftplus-vi.po (Size:132479B Mem:34.2M)
    [Sep 02 16:40:53] Scanned contents of 1299 additional files at 1.66 per second
    [Sep 02 16:40:53] Scanning contents: dev/wp-content/plugins/master-slider/assets/screenshot-5.png (Size:31478B Mem:34.2M)
    [Sep 02 16:40:54] Forking during hash scan to ensure continuity.
    [Sep 02 16:40:54] Entered fork()
    [Sep 02 16:40:54] Calling startScan(true)
    [Sep 02 16:40:54] Got value from wf config maxExecutionTime: 15
    [Sep 02 16:40:54] getMaxExecutionTime() returning config value: 15
    [Sep 02 16:41:00] gzinflate(): data error (2) File: /home/sfaught/public_html/wp-includes/class-http.php Line: 2136
    [Sep 02 16:41:00] Test result of scan start URL fetch: array ( ‘headers’ => array ( ‘server’ => ‘nginx’, ‘date’ => ‘Wed, 02 Sep 2015 16:41:00 GMT’, ‘content-type’ => ‘text/html; charset=UTF-8’, ‘content-length’ => ’32’, ‘connection’ => ‘close’, ‘x-robots-tag’ => ‘noindex’, ‘x-content-type-options’ => ‘nosniff’, ‘expires’ => ‘Wed, 11 Jan 1984 05:00:00 GMT’, ‘cache-control’ => ‘no-cache, must-revalidate, max-age=0’, ‘pragma’ => ‘no-cache’, ‘x-frame-options’ => ‘SAMEORIGIN’, ‘set-cookie’ => array ( 0 => ‘wfvt_3857652086=55e7269b5e21b; expires=Wed, 02-Sep-2015 17:10:59 GMT; path=/; httponly’, 1 => ‘_asomcnc=1; Max-Age=900; Path=/’, ), ‘vary’ => ‘Accept-Encoding’, ‘content-encoding’ => ‘gzip’, ‘x-nocache’ => ‘1’, ), ‘body’ => ‘WFSCANTESTOK’, ‘response’ => array ( ‘code’ => 200, ‘message’ => ‘OK’, ), ‘cookies’ => array ( 0 => WP_Http_Cookie::__set_state(array( ‘name’ => ‘wfvt_385765208
    [Sep 02 16:41:00] Starting cron with normal ajax at URL http://vvdisposal.com/wp-admin/admin-ajax.php?action=wordfence_doScan&isFork=1&cronKey=275015b367699f1707e4840
    [Sep 02 16:41:02] Scan process ended after forking.
    [Sep 02 16:50:01] Calling Wordfence API v2.17:https://noc1.wordfence.com//v2.17/?v=4.3&s=http%3A%2F%2Fvvdisposal.com&k=8e0739e279376606e1461632bb68bdf214739379058775665b57515600d01d4c&action=send_net_404

    Plugin Author WFMattR

    (@wfmattr)

    From the scan logs, it looks like it is probably a memory or timeout issue. Usually the steps here will help:
    My scans don’t finish

    Since your site is already using only 15 seconds for each stage, you might try 12 instead, in the “Maximum execution time for each scan stage” option, on your Wordfence Options page. You might also need to ask your host to increase the max_execution_time in the file “php.ini”.

    It looks like your memory usage is fairly low, but depending on the host, it still could be an issue. Can you click the link “Test your WordPress host’s available memory” near the bottom of the Wordfence options page, and tell us what the test says?

    Thread Starter sfaught

    (@sfaught)

    Thanks for getting back with me, I am still having the problem. I first changed the “Maximum execution time for each stage to 12” that did not seem to help seems like the scan did not get as fare. I then did a host memory check and it came back as good 81.00 megabytes. I then checked the configuration page for maximum executions and it was 180 so 80% is 144. I wasn’t sure how to change this other than go back to the option page and adjust “Maximum execution page to 144” Is that the correct method? I was a little leery since I had just changed it from 15 to 12. I then ran the scan but still never finished. Below are the last few of the scan details…
    Sep 03 13:22:33] Scanning contents: wp-content/themes/Minamaze_Pro/lib/shortcodes/includes/element-one_fifth.php (Size:74B Mem:41.8M)
    [Sep 03 13:22:33] Scanning contents: wp-content/themes/Minamaze_Pro/images/slideshow/placeholder_image.png (Size:42509B Mem:41.8M)
    [Sep 03 13:22:40] Scanned contents of 79 additional files at 1.24 per second
    [Sep 03 13:22:40] Forking during hash scan to ensure continuity.
    [Sep 03 13:22:40] Entered fork()
    [Sep 03 13:22:40] Calling startScan(true)
    [Sep 03 13:22:40] Got value from wf config maxExecutionTime: 144
    [Sep 03 13:22:40] getMaxExecutionTime() returning config value: 144
    [Sep 03 13:22:59] Test result of scan start URL fetch: array ( ‘headers’ => array ( ‘server’ => ‘nginx’, ‘date’ => ‘Thu, 03 Sep 2015 13:22:57 GMT’, ‘content-type’ => ‘text/html’, ‘content-length’ => ‘166’, ‘connection’ => ‘close’, ), ‘body’ => ‘ 502 Bad Gateway 502 Bad Gateway nginx ‘, ‘response’ => array ( ‘code’ => 502, ‘message’ => ‘Bad Gateway’, ), ‘cookies’ => array ( ), ‘filename’ => NULL, )
    [Sep 03 13:22:59] Starting cron via proxy at URL http://noc1.wordfence.com/scanp/valleystorageonline.com/wp-admin/admin-ajax.php?action=wordfence_doScan&isFork=1&cronKey=5b4a28ee1a2422732c7ada86
    [Sep 03 13:23:02] Scan process ended after forking.

    Plugin Author WFMattR

    (@wfmattr)

    It looks like your last two posts are from two different sites on the same server, is that correct? On the second one, I think you should turn off the Wordfence option “Start all scans remotely,” because that may be causing a different problem. (Usually this is used to fix a site that can’t start a scan otherwise, but yours appear to be starting, and running at least for a while.)

    The memory looks ok so far, but I think you will need to contact your host about the timeout. It might be that they have a lower max_execution_time set in php.ini — I see that the two sites show different values, so I can’t tell what the actual limit is. If you tell them the time that the scan failed, too, they may be able to see something in the site’s access log at the same time (it would be a hit on wp-admin/admin-ajax.php).

    Normally, using 144 seconds, as you mentioned, should work in your case, but I think there is something else getting in the way. (When scans fail like this, lowering the value often helps, even if a higher value might work. A high value may work when the server isn’t busy, but when there is a lot of traffic, it could cause the scan to stop wherever it happens to be.)

    I see also that your server is running nginx, but I’m not sure if it is being used as a front end proxy, or if it is actually running the PHP processes directly. Either way should work, but there may be other settings that the host would need to change, to let processes run longer.

    Thread Starter sfaught

    (@sfaught)

    Yes Wordfence is running on two different sites but on the same server and yes I am having the same problem on both. I have contacted my host, I am waiting to see what they come up with. I will let you know, thanks!!!

    Thread Starter sfaught

    (@sfaught)

    I heard back from my host and they set the max execution to 144. I ran the scan again to see if that fixed the problem, but it still stops I have attached some of the log in hopes you can see why, thanks!!!

    Plugin Author WFMattR

    (@wfmattr)

    Sorry, I think there was some misunderstanding — using 144 within Wordfence should have worked in your case because the time limit set by the host was 180, so Wordfence would try to stop before it hit their limit. But now, they have decreased their limit to 144!

    I didn’t see any logs in your reply above — if they were long, the forum moderators may have removed them. You can paste them on a site like pastebin.com and just post a link here, if so, but make sure there is no sensitive information in anything you post.

    Even so, 180 (or even 144) should normally work, especially since you tried a much lower time limit in Wordfence’s settings — I think the host is limiting time somewhere else, whether it’s in the web server’s connection timeout, or some other restrictions.

    From your other post (about the lockout issue), I saw that nginx was being used as a reverse proxy — it could be that nginx drops the connection too soon, or apache does (on the server where your php code runs).

    Thread Starter sfaught

    (@sfaught)

    Sorry not sure why that did not post please see it below…

    [Sep 16 19:50:44] Scanning contents: wp-content/plugins/thinkup-panels/inc/plugins/animate.css/source/lightspeed/lightSpeedOut.css (Size:248B Mem:38.0M)
    [Sep 16 19:50:44] Scanning contents: wp-content/themes/VVDR/index.php (Size:2180B Mem:38.0M)
    [Sep 16 19:50:44] Scanning contents: wp-content/themes/Minamaze_Pro/lib/shortcodes/includes/widget-thinkup_builder_thinkupslider.php (Size:10898B Mem:38.0M)
    [Sep 16 19:50:44] Scanning contents: wp-content/plugins/limit-login-attempts_old/limit-login-attempts-ru_RU.po (Size:8910B Mem:38.0M)
    [Sep 16 19:50:44] Scanning contents: wp-content/uploads/2015/05/Mesquite-Service-Equipment-Rental-Package.pdf (Size:1.75M Mem:38.0M)
    [Sep 16 19:50:49] Scan process ended after forking.
    [Sep 16 19:52:46] Calling Wordfence API v2.17:https://noc1.wordfence.com//v2.17/?v=4.3.1&s=http%3A%2F%2Fvvdisposal.com&k=8e0739e279376606e1461632bb68bdf214739379058775665b57515600d01d4c&action=ping_api_key
    [Sep 16 19:52:47] Calling Wordfence API v2.17:https://noc1.wordfence.com//v2.17/?v=4.3.1&s=http%3A%2F%2Fvvdisposal.com&k=8e0739e279376606e1461632bb68bdf214739379058775665b57515600d01d4c&action=get_known_vuln_patter

    Do you think I should have them change that time then?

    Plugin Author WFMattR

    (@wfmattr)

    Right now, I’m not sure if it will make a difference, but a higher limit couldn’t hurt.

    I tried connecting to the server and waiting for it, and found that it waits 60 seconds, which is good, so the 12 or 15 second limit (that you tried setting within Wordfence) should definitely have made it under the limit. Normally the only other thing I would expect on a normal host is Apache’s time limit, but that is usually 60 seconds or higher too, if the hosting company didn’t set it extremely low.

    I don’t know if there is anything else we can check at this point — you will probably need the hosting company to help determine why the process is ending too soon. (I would set the time limit within Wordfence back to 15 or 12, while having them test their settings. If you get it working, you could then try gradually increasing the time in Wordfence’s Options page.)

Viewing 15 replies - 1 through 15 (of 16 total)

The topic ‘Scan doe not finish, hangs’ is closed to new replies.