Ooops... a typo in there. Also, reformatted the rule string to make it more readable. better make that: iptables -A INPUT -p tcp \! -f -m connbytes --conbytes 0:255 \ -m state ESTABLISHED -m length --length 46:375 -m u32 \ --u32 "o>>22&0x3C@ 12>>26&0x3C@ 0=0x5353482D" -j DROP