mailscanner suspcious process.

keat63

Well-Known Member
Nov 20, 2014
1,843
221
93
cPanel Access Level
Root Administrator
Any thoughts why mailscanner would start echoing these errors.
Only just started recently, probably since upadating to 8.0.14 late last week.

Code:
/usr/local/cpanel/3rdparty/perl/528/bin/perl


Command Line (often faked in exploits):

MailScanner: waiting for messages


Network connections by the process (if any):

udp: 213.171.xxx.xxx:36679 -> 5.9.124.53:24441


Files open by the process (if any):

/dev/null
/dev/null
/dev/null
/usr/mailscanner/usr/share/MailScanner/perl/MailScanner/CustomConfig.pm
/usr/mailscanner/usr/share/MailScanner/perl/MailScanner/ConfigDefs.pl
/usr/mailscanner/usr/share/MailScanner/perl/custom/GenericSpamScanner.pm
/var/spool/MailScanner/incoming/SpamAssassin.cache.db
I'm aware that 5.9.124.53:24441 has something to do with Pyzor, which could be related to SpamAssasin.
 

keat63

Well-Known Member
Nov 20, 2014
1,843
221
93
cPanel Access Level
Root Administrator
Still trying to figure this out.
If I look in my processes list I see 2 x processes for Mailscanner.

MailScanner: starting child
MailScanner: waiting for messages

If I stop and restart mailscanner, 2 processes start again, the PIDs change.
Then an hour later, I see the message again.
 

keat63

Well-Known Member
Nov 20, 2014
1,843
221
93
cPanel Access Level
Root Administrator
Apparently It is normal, you need to add this line to /etc/csf/csf.pignore and restart csf and lfd:

pcmd:MailScanner:.*

Odd how I never needed it before now though.
 

cPanelLauren

Product Owner
Staff member
Nov 14, 2017
13,297
1,251
313
Houston
@keat63

Maybe some changes to either CSF or MailScanner, but both of those are 3rd party applications and they would the best outlet for answers on their behavior or changes in it.