Is usr/sbin/postfix/master on 127.0.0.1:25 is the normal process?

Hello :smiley: I have the...situacuon than i install forge 1.12.2 but i don't noticed than old version minecraft have CVE-2021-44228 and today morning i return to secury backup main disk(but game's disk not x)) and i'm a little panic and i showed process /usr/sbin/postif/master on 127.0.0.1:25 on LISTEN and i have the question: why system need this process? Is this procces able to other programs comunicate among him?

And i aks because before return to save version-i sse then GE-Proton (i don't remeber how version) in /home/[my user]/.steam/... have log4j and after restore-it didn't-and i'm the little panic than i dowloand malware but i know than i dowloannd forge and fabric from official webstie(forge from files.minecraftforge.net and fabric from fabricmc.net)

And i react tha because when i run first time forge 1.12.2 i saw then connect go after 13.107.253.44 - i check and virustotal ane in this code-was many mailous files and...a connect facts and i see CVE-2021-44228 incidnet but was rapot 7 month ago etc aboit this adress) i don't connect another servwr-just run launcher x)

What you are describing is your local host only. It is unable to accept external connections.

PostFix is normal and yes, it facilitates local-only communication between normal system processes by design. This is not compromised, nor is it malicious.

CVE-2021-44228 is a vulnerability in MineCraft that was patched back in 2021. It required a direct connection to be set up by the user in a malicious chat environment - merely logging into the game was not sufficient to exploit the vulnerability.

Log4 is not malicious. It is normal - that is the software bit being exploited before the patch in 2021

Your system is safe and not compromised. Seeing a Microsoft connection is expected since it owns MineCraft.

These days, security is used as a marketable Selling Point; exploiting end user fears.
Be wary of being exploited not just by malware - but by marketing.

Yeeees...i noticed this x)- this is source why I more want aske norton AI about security than searching in internet-nothing information just feras x)

I check and this adress 13.107.253.44 is a Aa ASAS 8075 Microsoft etc so i'm shocked than on virustotal this adress have very negative signatures 0.0

Thank you so much :smiley:

I analogic situation i have with steam-i notoced when i run steam-it conect after xxxxxxx.deploy.static.acamitechnologies.net and-adress with others variants xxxxxxx on virust total is ok-but how as connections-just steam and 2 other files are ok-other files wich connecticn after this adress was malicious

But i still asking people because talking with AI this isn't the same what talking with people-i like see individual opinion from anwser not only anwser x)-individual opinion is very helpful :3 <3

I think many would agree with you on that. You can't look into AI's eyes, to see if it is telling pork pies.

2 Likes

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.