What's new

Detection of iPhone Infection

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

User2896

New Around Here
Hi All,

Brand new to this forum, so forgive me if this is the wrong place to post this98. In the report I get from AIProtection Two-Way IPS feature on Asus RT-AX88U it's telling me that my iPhone with IP 192.168.1.148 has an infection. Is this necessarily correct or are there false positives?

Look at first 9 lines of the attached excerpt from this IntrusionSystemPrevention report.

Many thanks for your thoughts on this.
 

Attachments

  • IntrusionPreventionSystem Excerpt.pdf
    76.4 KB · Views: 57
There should be a column on the right that says what it thinks the specific problem is. Do you not have that column?

As far as I can see those three IP addresses are just CDN addresses. None of them have been flagged at www.abuseipdb.com
 
There should be a column on the right that says what it thinks the specific problem is. Do you not have that column?

As far as I can see those three IP addresses are just CDN addresses. None of them have been flagged at www.abuseipdb.com
Sorry, that column is on the second page of PDF. It says WEB Cross-site scripting - 36 in each of 9 rows.
 
Sorry, that column is on the second page of PDF. It says WEB Cross-site scripting - 36 in each of 9 rows.

I see similar warnings when guests' phones connect. Usually some game they downloaded, even apple is not immune to crappy apps. Sometimes just bad coding, sometimes it is actually malware.
 
Doh! :oops:


My guess is that it's a false positive. But I couldn't say 100%. Can you correlate the time to something you were doing on the phone?
Not really a good way to do that since it's looking back so far. I will keep an eye on it and see if it happens again.

Many thanks for response.
 
I did find another post here asking about the exact same error message that was also from an iPhone. There's another report here from an unspecified Android phone.
 
Last edited:
I did find another post here asking about the exact same error message that was also from an iPhone. There's another report here from an unspecified Android phone.
Thanks Colin. Looks like I am going to have to monitor this and see whether it is an ongoing problem or an isolated issue.
 
Sorry, that column is on the second page of PDF. It says WEB Cross-site scripting - 36 in each of 9 rows.
Cross site scripting dose not necessary indicate infection. It dose indicate that the host was used to do things that the site forced it to do.
 
Thanks Morris. Just trying to figure out if I should be resetting iPhone to factory settings to get rid of possible malware.

I appreciate your weighing in on this.
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top