[iptablesfw]# iptables -I FORWARD 1 -p tcp --dport 1433 -m state --state
ESTABLISHED -m string --hex-string "'|00|" --algo bm -m string --hex-string
"-|00|-|00|" --algo bm -j LOG --log-prefix "SQL INJECTION COMMENT "
translate to mikrotik ip -> firewall -> filter
Code: Select all
;;; SQL INJECTION COMMENT
chain=forward action=log connection-state=established protocol=tcp
dst-port=1433 content=|00|,|00|-|00| connection-type="" log-prefix=""