Burp Suite User Forum

Create new post

Low labs performance

Vadim | Last updated: Dec 07, 2020 08:33AM UTC

I'm getting slow responses (up to 20 seconds delay) when working at least with CSRF labs (haven't tried other labs yet), examples are: Dec 07 11:20:18 MSK 2020 GET https://ac2d1f3b1f30876c80592482005e0040.web-security-academy.net/login 13454ms Dec 07 11:19:57 MSK 2020 GET https://ac2d1f3b1f30876c80592482005e0040.web-security-academy.net/ 16033ms Dec 07 11:23:44 MSK 2020 GET https://ac711f031f6087e280f92454011c00a0.web-security-academy.net/exploit 16083ms Dec 07 11:19:39 MSK 2020 GET https://ac2d1f3b1f30876c80592482005e0040.web-security-academy.net/logout 17411ms Dec 07 11:23:24 MSK 2020 POST https://ac711f031f6087e280f92454011c00a0.web-security-academy.net/ 19940ms

Hannah, PortSwigger Agent | Last updated: Dec 07, 2020 04:49PM UTC

Hi Did you experience this delay when accessing any of the other labs? Do you have any extensions loaded on your Burp installation?

Vadim | Last updated: Dec 07, 2020 05:32PM UTC

1) CSRF labs were all slow, Information disclosure ones were fast. But I've tried CSRF ones several hours earlier than the DISC ones. 2) Burp was not used. I'm using OWASP ZAP.

Hannah, PortSwigger Agent | Last updated: Dec 08, 2020 01:16PM UTC

Were you proxying the labs through ZAP at the time, or were you seeing the slow response times when connecting normally?

Vadim | Last updated: Dec 08, 2020 04:42PM UTC

I was proxying labs.

Hannah, PortSwigger Agent | Last updated: Dec 09, 2020 10:29AM UTC

Thank you for that information. We're currently investigating this issue.

Vadim | Last updated: Dec 14, 2020 09:53AM UTC

Hello, today I found another occurrence but on XSS labs. https://acb41fc11e9899618004324c00af0094.web-security-academy.net/?search=%27 took 18 sec. This was https://portswigger.net/web-security/cross-site-scripting/contexts/lab-html-context-with-most-tags-and-attributes-blocked So it is not limited on the CSRF labs only. Time of occurrence was Mon Dec 14 12:50:31 MSK 2020.

Hannah, PortSwigger Agent | Last updated: Dec 14, 2020 04:24PM UTC

Hi Thank you for that information. We're still investigating the issues with slow labs.

JS | Last updated: Feb 10, 2023 01:09PM UTC

Having similar issues, "Blind SSRF with out-of-band detection" is painfully slow, taking ages to load. Each page takes +20 seconds to load.

Hannah, PortSwigger Agent | Last updated: Feb 13, 2023 09:42AM UTC

Hi. Are you still experiencing the issue with slow labs?

Peter | Last updated: May 16, 2024 08:29AM UTC

I am experiencing the same problems. Same Lab via OWASP Zap browser and directly in chrome. Chrome: No problems, I can navigate around freely. OWASP ZAP browser; NON-AUTH requests like 'https://<MyLab>.web-security-academy.net/?search=foo' are not a problem, but everything auth related lik login and /my-account takes +20 sec.

Hannah, PortSwigger Agent | Last updated: May 16, 2024 10:56AM UTC

Hi Do you also experience this issue when proxying the lab through Burp Suite Community? Do you have any settings or extensions configured in Zap that may be slowing down the connection?

Arnd | Last updated: May 16, 2024 01:56PM UTC

I am experiencing same Problems on all Labs with Burp Chromium Browser and Chrome with Proxy, even with no extensions installed and default settings

Takahiro | Last updated: May 16, 2024 03:34PM UTC

I am using Burp Suite Pro and am experiencing a similar issue. The lab response is slow only when going through a proxy. If you do not go through a proxy, the response from the lab will be faster. However, about 3 days ago, the response from the lab was slow even when not going through Proxy.

Denis | Last updated: May 16, 2024 03:45PM UTC

Same issue, the responses from the labs are very slow. I tried 'Brute-forcing a stay-logged-in cookie' and '2FA bypass using a brute-force attack' labs. The responses were slow on Chrome, Firefox, and axios (Node.js). No proxies were used.

Takahiro | Last updated: May 16, 2024 04:02PM UTC

Sorry, there were some mistakes in my sentence, so I'd like to correct them. As of 3 days ago, the response from the lab was slow even when not going through a proxy. However, at this point, when not going through a proxy, the response speed is normal in most cases. (Sometimes it's slow.) It's still slow when going through Proxy.

Takahiro | Last updated: May 16, 2024 04:07PM UTC

However, it is not slow in all cases.

vrooo92 | Last updated: May 16, 2024 04:57PM UTC

Yes, all the labs are running so bad.

vrooo92 | Last updated: May 16, 2024 06:03PM UTC

Any update?

Aakash | Last updated: May 16, 2024 06:19PM UTC

all the labs are running very slow. What should I do?

Vuong | Last updated: May 17, 2024 02:12AM UTC

It not only lags when I do labs but also when I do certification exams. Is there any way to fix it. I can't take the test with this condition. Is there any way to fix it?

Hannah, PortSwigger Agent | Last updated: May 17, 2024 09:31AM UTC

Hi We think that we have fixed this issue. Are you still having issues with excessively slow labs?

Takahiro | Last updated: May 17, 2024 02:29PM UTC

I've been working on the lab for about 2 hours, and the problem seems to be resolved. Thank you.

Hannah, PortSwigger Agent | Last updated: May 17, 2024 03:14PM UTC

Glad to hear it! Please let us know if you continue to experience issues.

Sophy | Last updated: May 31, 2024 05:32PM UTC

I'm also running into this issue. CSRF labs load slowly (30sec+) both when I'm using Burp Suite Pro's browser and when I'm using my regular browser.

Takahiro | Last updated: May 31, 2024 05:45PM UTC

I am in the same situation. This issue is not just occurring in one type of lab, but in a variety of types of labs.

Zeeshan | Last updated: Jun 01, 2024 03:57PM UTC

Is there any issue going on with the labs recently, I am using burp pro to intercept the traffic, the responses are extremely slow, I am trying mystry labs so its probably for all labs, I want to give certification attempt soon, but the lab performance is a real hindrance

Edwin | Last updated: Jun 01, 2024 09:36PM UTC

I'm also experiencing slow performance on the labs, namely the sqli ones (haven't tried the others yet these past few days).

Ben, PortSwigger Agent | Last updated: Jun 03, 2024 09:56AM UTC

Hi, I have just loaded a random selection of labs and I am not seeing similar behaviour to that described - the pages of each of the labs appear to load instantly. Are any of you able to provide us with more details of the exact labs you see this issue and what steps you are carrying out when you do experience this?

Sophy | Last updated: Jun 03, 2024 04:42PM UTC

Steps to reproduce: 1. Open SameSite Lax bypass via cookie refresh lab with Burp Proxy on 2. For the first ~5 minutes or so of accessing the lab, pages loaded quickly 3. After ~5 minutes, go to My Account in the lab to test updating the user's email 4. Observe that the POST and GET requests from this page take 45+ seconds 5. Loading the lab info page from the same Burp browser happens instantaneously 6. Close the lab in the Burp browser 7. Open the lab again from the lab info page in a new tab 8. Open My Account and update the lab user's email; observe that the page loads quickly 9. Wait 5 minutes, try updating email again; observe that GET and POST requests are once again taking 45+ seconds It seems like a performance issue within the lab pages emerges during the middle of the day US time and when a lab has been open for more than ~5 minutes. This suggests to me that maybe the performance issue is related to a lot of people accessing Burp's labs, coupled with having a lab open for more than ~5 minutes. It's possible the window of fast performance is longer than 5 minutes depending on how much traffic PortSwigger is receiving in general. Since the degradation in performance only happens with the lab pages and not the lab info pages, perhaps there's something about these ad-hoc user-specific subdomains that are being spun up that struggle under load. Earlier today, I had labs open for 30+ minutes and never observed a performance degradation.

Sophy | Last updated: Jun 03, 2024 04:46PM UTC

One more observation - I tried opening a new session of the same lab again. This time the lab fails to even load. It times out and displays "Error: An unknown error occurred." I have to try several times before the lab loads successfully in a tab without timing out. We are past 9am Pacific US time now, which seems to suggest my hypothesis that this is a load-based performance issue in the labs, and based on previous posts probably not specific to any single lab.

Ben, PortSwigger Agent | Last updated: Jun 04, 2024 07:46AM UTC

Hi Sophy, We can continue monitoring this - the point about this happening during peak US time is interesting. At this current point in time I am simply not seeing any delays in the pages loading for the lab that you have mentioned (regardless of how long I leave the lab running for) but I realise this is outside the time frame that you have mentioned.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.