Hello,
I'm running CentOS 8 with Directadmin with CSF/LFD. For some reason I keep receiving those emails:
The same configuration is working on CentOS 7 but not on CentOS 8 what am I missing? Adding perl to the pignore did not help.
I'm running CentOS 8 with Directadmin with CSF/LFD. For some reason I keep receiving those emails:
lfd on servername: Suspicious process running under user
Time: Fri Nov 13 10:07:33 2020 +0100
PID: 67268 (Parent PID:67248)
Account: accountname
Uptime: 23908 seconds
Executable:
/usr/bin/perl
Command Line (often faked in exploits):
spamd child
The following rules are already in the /etc/csf/csf.pignore configuration:
cmd:spamd child
exe:/usr/bin/rspamd
exe:/usr/bin/spamd
The same configuration is working on CentOS 7 but not on CentOS 8 what am I missing? Adding perl to the pignore did not help.