Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

mailscanner suspcious process.

Discussion in 'E-mail Discussion' started by keat63, Jun 17, 2019.

  1. keat63

    keat63 Well-Known Member

    Joined:
    Nov 20, 2014
    Messages:
    1,291
    Likes Received:
    91
    Trophy Points:
    28
    cPanel Access Level:
    Root Administrator
    Any thoughts why mailscanner would start echoing these errors.
    Only just started recently, probably since upadating to 8.0.14 late last week.

    Code:
    /usr/local/cpanel/3rdparty/perl/528/bin/perl
    
    
    Command Line (often faked in exploits):
    
    MailScanner: waiting for messages
    
    
    Network connections by the process (if any):
    
    udp: 213.171.xxx.xxx:36679 -> 5.9.124.53:24441
    
    
    Files open by the process (if any):
    
    /dev/null
    /dev/null
    /dev/null
    /usr/mailscanner/usr/share/MailScanner/perl/MailScanner/CustomConfig.pm
    /usr/mailscanner/usr/share/MailScanner/perl/MailScanner/ConfigDefs.pl
    /usr/mailscanner/usr/share/MailScanner/perl/custom/GenericSpamScanner.pm
    /var/spool/MailScanner/incoming/SpamAssassin.cache.db
    
    I'm aware that 5.9.124.53:24441 has something to do with Pyzor, which could be related to SpamAssasin.
     
  2. keat63

    keat63 Well-Known Member

    Joined:
    Nov 20, 2014
    Messages:
    1,291
    Likes Received:
    91
    Trophy Points:
    28
    cPanel Access Level:
    Root Administrator
    Still trying to figure this out.
    If I look in my processes list I see 2 x processes for Mailscanner.

    MailScanner: starting child
    MailScanner: waiting for messages

    If I stop and restart mailscanner, 2 processes start again, the PIDs change.
    Then an hour later, I see the message again.
     
  3. keat63

    keat63 Well-Known Member

    Joined:
    Nov 20, 2014
    Messages:
    1,291
    Likes Received:
    91
    Trophy Points:
    28
    cPanel Access Level:
    Root Administrator
    Apparently It is normal, you need to add this line to /etc/csf/csf.pignore and restart csf and lfd:

    pcmd:MailScanner:.*

    Odd how I never needed it before now though.
     
  4. cPanelLauren

    cPanelLauren Forums Analyst II Staff Member

    Joined:
    Nov 14, 2017
    Messages:
    6,456
    Likes Received:
    503
    Trophy Points:
    263
    Location:
    Houston
    cPanel Access Level:
    DataCenter Provider
    @keat63

    Maybe some changes to either CSF or MailScanner, but both of those are 3rd party applications and they would the best outlet for answers on their behavior or changes in it.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
Loading...
Similar Threads - mailscanner suspcious process
  1. cPanelMichael
    Replies:
    0
    Views:
    175

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice