As you wish Martin, i found a really good resource which has collected the possible characters can be used during injection, similarly to the bad robot trap those characters and sql commands are now placed to a separated txt file.
Btw we have already released a defending wp plugin, which protect your website against
proxy exploits.