• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Question Can modsecurity be used to exclude bot agents ?

sanbis

New Pleskian
Server operating system version
Windows Server 2019
Plesk version and microupdate number
Plesk Obsidian Web Host Edition
The currently used rule is Atomic Advanced
I don't know if it is possible to use a custom rule to exclude bot agents ?

SecRule REQUEST_HEADERS:User-Agent "@rx (?:AhrefsBot)" "msg:'AhrefsBot Spiderbot blocked',phase:1,log,id:7777771,t:none,block,status:403"

if ($http_user_agent ~ (MJ12bot|LieBaoFast|UCBrowser|MQQBrowser|Mb2345Browser|gumgum-bot|postmanruntime|ag_dm_spider|scrapy|chimebot|trendkite-akashic-crawler|ZoominfoBot|Sogou|ALittle|Keybot|Buck|curl|webprosbot|RestSharp|Snap|SemrushBot|AhrefsBot|DataForSeoBot)) {
return 403;
}
 
Hello Sanbis,

I believe that you may have an apache web server. and let me guide you through some steps to exclude bot agents using ModSecurityAnd I assume that you have already installed it. If you haven’t, then follow me.

In the Apache configuration setup, we already have an included directory for ModSecurity rules

Configure ModSecurity to Block bot Agents.


1654257936131.png1654258110777.png
Please go through the attached files.
 
Back
Top