mailscanner suspcious process.

keat63

Well-Known Member
Nov 20, 2014
1,382
107
43
cPanel Access Level
Root Administrator
Any thoughts why mailscanner would start echoing these errors.
Only just started recently, probably since upadating to 8.0.14 late last week.

Code:
/usr/local/cpanel/3rdparty/perl/528/bin/perl


Command Line (often faked in exploits):

MailScanner: waiting for messages


Network connections by the process (if any):

udp: 213.171.xxx.xxx:36679 -> 5.9.124.53:24441


Files open by the process (if any):

/dev/null
/dev/null
/dev/null
/usr/mailscanner/usr/share/MailScanner/perl/MailScanner/CustomConfig.pm
/usr/mailscanner/usr/share/MailScanner/perl/MailScanner/ConfigDefs.pl
/usr/mailscanner/usr/share/MailScanner/perl/custom/GenericSpamScanner.pm
/var/spool/MailScanner/incoming/SpamAssassin.cache.db
I'm aware that 5.9.124.53:24441 has something to do with Pyzor, which could be related to SpamAssasin.
 

keat63

Well-Known Member
Nov 20, 2014
1,382
107
43
cPanel Access Level
Root Administrator
Still trying to figure this out.
If I look in my processes list I see 2 x processes for Mailscanner.

MailScanner: starting child
MailScanner: waiting for messages

If I stop and restart mailscanner, 2 processes start again, the PIDs change.
Then an hour later, I see the message again.
 

keat63

Well-Known Member
Nov 20, 2014
1,382
107
43
cPanel Access Level
Root Administrator
Apparently It is normal, you need to add this line to /etc/csf/csf.pignore and restart csf and lfd:

pcmd:MailScanner:.*

Odd how I never needed it before now though.