|
This is the log of qmail-scanner:
Wed, 24 Sep 2008 12:37:25 CEST:6443: +++ starting debugging for process 6443 (ppid=5628) by uid=10003
Wed, 24 Sep 2008 12:37:25 CEST:6443: s_q: re-create the quarantine version file
Wed, 24 Sep 2008 12:37:25 CEST:6443: s_q: cleaning up files older than 2 days via /usr/bin/find /var/spool/qscan/tmp -mtime +2 -exec //bin/rm -rf {} ;
Wed, 24 Sep 2008 12:37:25 CEST:6443: s_q: cleaning up quarantined mail older than 14 days via /usr/bin/find /var/spool/qscan/quarantine -type f -mtime +14 -exec //bin/rm -rf {} ;
Wed, 24 Sep 2008 12:37:25 CEST:6443: ------ Process 6443 finished. Total of 0.427347 secs
Wed, 24 Sep 2008 12:37:47 CEST:6454: +++ starting debugging for process 6454 (ppid=6451) by uid=2020
Wed, 24 Sep 2008 12:37:47 CEST:6454: c_a_g: found URL in message - maybe phishy - better scan it
Wed, 24 Sep 2008 12:37:47 CEST:6454: w_c: Total time between DATA command and "." was 0.001907 secs
Wed, 24 Sep 2008 12:37:47 CEST:6454: g_e_h: return-path='info@test.com', recips='alessio@pippo.it'
Wed, 24 Sep 2008 12:37:47 CEST:6454: from='"Alessio" <info@test.com>', subj='test di invio 5', via SMTP from 88-149-163-77.static.ngi.it
Wed, 24 Sep 2008 12:37:47 CEST:6454: s_p_d: /var/spool/qscan/settings_per_domain.db doesn't exist falling to installed scanners
Wed, 24 Sep 2008 12:37:47 CEST:6454: clamdscan: finished scan in 0.006313 secs
Wed, 24 Sep 2008 12:37:47 CEST:6454: SA: yup, this smells like SPAM - hits=1001.6/7.0/12 - message rejected ...
Wed, 24 Sep 2008 12:37:47 CEST:6454: SA: finished scan in 0.19963 secs - hits=1001.6/7.0
Wed, 24 Sep 2008 12:37:47 CEST:6454: r_e: X-Qmail-Scanner-2.02st: We have reasons to believe this mail is SPAM (#5.7.1)
Wed, 24 Sep 2008 12:37:47 CEST:6454: ------ Process 6454 finished. Total of 0.214714 secs
An this from /var/log/messages
Sep 24 12:36:08 server xinetd[3539]: START: smtp pid=5613 from=88.149.163.77
Sep 24 12:36:09 server xinetd[3539]: EXIT: smtp status=0 pid=5613 duration=1(sec)
Sep 24 12:37:21 server clamd[3554]: /tmp/mkt_qs.5632-1222252641/eicar.com: Eicar-Test-Signature FOUND
Sep 24 12:37:46 server xinetd[3539]: START: smtp pid=6451 from=88.149.163.77
Sep 24 12:37:47 server xinetd[3539]: EXIT: smtp status=1 pid=6451 duration=1(sec)
|