Hi,
Last few days we put on public domain our new nopcommerce 3.3 (.net MVC) app. MSSQL DB is still locally. When we started this app, DB start to grow up dramaticly. Within 10 days it got 10GB size.
When I looked on app log, I found 4.5 Million new lines. When I research other tables in the database, I found the same number of new USER records (with status active! - even through it is set up for e-mail approval, other fields stay null) and also same number of USER Roles, but these new "users" are not seen on the admin panel.
I have stopped public site, clean-up the database, put ReCaptcha on Register page, but problem remain.
Here are the logs:
1/ IIS log from public site (still these same 2 lines, about 5 times in a seccond):
#Software: Microsoft Internet Information Services 8.0
#Version: 1.0
#Date: 2014-04-10 21:14:30
#Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken
2014-04-10 21:14:34 xxx.xxx.xxx.64 POST /momif/eai_getjobs.php sig=fccc6cf1a1181dae60acb3986f8a5f65 80 - yyy.yyy.yyy.204 uF_IGV2 - 404 0 0 3812
2014-04-10 21:14:34 xxx.xxx.xxx.64 POST /momif/eai_loginrequest.php sig=3c4bfa72052630e662ab4d277588a88c 80 - yyy.yyy.yyy.204 uF_IGV2 - 404 0 0 3812
2014-04-10 21:14:34 xxx.xxx.xxx.64 POST /momif/registerserver.php sig=65d399dda4506315a05b02f513a848e8 80 - yyy.yyy.yyy.204 uF_IGV2 - 404 0 0 26640
2014-04-10 21:14:34 xxx.xxx.xxx.64 POST /momif/eai_getjobs.php sig=fccc6cf1a1181dae60acb3986f8a5f65 80 - yyy.yyy.yyy.204 uF_IGV2 - 404 0 0 796
2014-04-10 21:14:34 xxx.xxx.xxx.64 POST /momif/eai_loginrequest.php sig=3c4bfa72052630e662ab4d277588a88c 80 - yyy.yyy.yyy.204 uF_IGV2 - 404 0 0 859
2014-04-10 21:14:35 xxx.xxx.xxx.64 POST /momif/eai_getjobs.php sig=fccc6cf1a1181dae60acb3986f8a5f65 80 - yyy.yyy.yyy.204 uF_IGV2 - 404 0 0 421
2014-04-10 21:14:35 xxx.xxx.xxx.64 POST /momif/eai_loginrequest.php sig=3c4bfa72052630e662ab4d277588a88c 80 - yyy.yyy.yyy.204 uF_IGV2 - 404 0 0 484
2014-04-10 21:14:35 xxx.xxx.xxx.64 POST /momif/eai_loginrequest.php sig=3c4bfa72052630e662ab4d277588a88c 80 - yyy.yyy.yyy.204 uF_IGV2 - 404 0 0 421
2014-04-10 21:14:35 xxx.xxx.xxx.64 POST /momif/eai_getjobs.php sig=fccc6cf1a1181dae60acb3986f8a5f65 80 - yyy.yyy.yyy.204 uF_IGV2 - 404 0 0 484
2014-04-10 21:14:35 xxx.xxx.xxx.64 POST /momif/eai_getjobs.php sig=fccc6cf1a1181dae60acb3986f8a5f65 80 - yyy.yyy.yyy.204 uF_IGV2 - 404 0 0 437
...
where xxx - ip address is from public site, yyy - ip address is IP from SQL server.
2/ NopCommerce error messages:
A:
Delete
The level of log entry.Log level: Error
The log entry message.Short message: The controller for path '/momif/eai_getjobs.php' was not found or does not implement IController.
The details for the log entry.Full message: System.Web.HttpException (0x80004005): The controller for path '/momif/eai_getjobs.php' was not found or does not implement IController. at System.Web.Mvc.DefaultControllerFactory.GetControllerInstance(RequestContext requestContext, Type controllerType) at System.Web.Mvc.DefaultControllerFactory.CreateController(RequestContext requestContext, String controllerName) at System.Web.Mvc.MvcHandler.ProcessRequestInit(HttpContextBase httpContext, IController& controller, IControllerFactory& factory) at System.Web.Mvc.MvcHandler.BeginProcessRequest(HttpContextBase httpContext, AsyncCallback callback, Object state) at System.Web.HttpApplication.CallHandlerExecutionStep.System.Web.HttpApplication.IExecutionStep.Execute() at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
IP address of the machine that caused the exception.IP address: yyy.yyy.yyy.204
Name of the customer who caused the exception.Customer: Guest
Originating page of exception.Page URL: http://<website>/ws/momif/eai_getjobs.php?sig=fccc6cf1a1181dae60acb3986f8a5f65
The referrer URL.Referrer URL:
Date/Time the log entry was created.Created on: 4/12/2014 8:02:56 AM
B:
The level of log entry.Log level: Error
The log entry message.Short message: The controller for path '/momif/eai_loginrequest.php' was not found or does not implement IController.
The details for the log entry.Full message: System.Web.HttpException (0x80004005): The controller for path '/momif/eai_loginrequest.php' was not found or does not implement IController. at System.Web.Mvc.DefaultControllerFactory.GetControllerInstance(RequestContext requestContext, Type controllerType) at System.Web.Mvc.DefaultControllerFactory.CreateController(RequestContext requestContext, String controllerName) at System.Web.Mvc.MvcHandler.ProcessRequestInit(HttpContextBase httpContext, IController& controller, IControllerFactory& factory) at System.Web.Mvc.MvcHandler.BeginProcessRequest(HttpContextBase httpContext, AsyncCallback callback, Object state) at System.Web.HttpApplication.CallHandlerExecutionStep.System.Web.HttpApplication.IExecutionStep.Execute() at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
IP address of the machine that caused the exception.IP address: yyy.yyy.yyy.204
Name of the customer who caused the exception.Customer: Guest
Originating page of exception.Page URL: http://<website>/ws/momif/eai_loginrequest.php?sig=3c4bfa72052630e662ab4d277588a88c
The referrer URL.Referrer URL:
Date/Time the log entry was created.Created on: 4/12/2014 8:02:56 AM
3/ I tryed to find directories /ws/momif/... but not found even with showing <hiden items> and <file extensions>
4/ By clicking on Guest (above) link I can administer the user account where no data, I can save it etc., but still is not visible directly in admin panel.
Can you help me?
Thanks