• The new Python extension is now available. It allows customers to deploy and manage WSGI-based Python applications on their websites directly from Plesk.
  • Debian 11 has reached its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.81 is the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Question How to 'selectively' block Mackintosh Chrome browsers

tetrahall

Regular Pleskian
Server operating system version
CentOS Linux release 7.6.1810
Plesk version and microupdate number
Plesk Obsidian Version 18.0.81
Hi,

I need to block visitors using Mackintosh Chrome browsers - There are thousands of them on a daily basis, and almost all have unique ip addresses.

But I must allow genuine visitors who use iPhone, android or destop windows explorer, as well as search engines bots.

I have tried htaccess to no avail. Having searched the internet, the cause is running Nginx.

"The htaccess file and RewriteRule syntax belong strictly to Apache web servers. Since you are running Nginx on CentOS 7, any rules you write in an htaccess file will be completely ignored by the server."

The solution involves editing Nginx file "/etc/nginx/nginx.conf".

I am not famiilar with Nginx and I don't want to make a miss of things.

Can I do this effectively via Plesk? Or would it be better if I edited file "/etc/nginx/nginx.conf".

Please advise me.
 
What's the exact htaccess configuration you're using?

By default Plesk uses nginx as a proxy only and internally forwards request to Apache. Which means that using htaccess should work fine, unless Proxy Mode has been disabled for the domain. In that case all requests are handled by nginx.

If proxy mode has been disabled for your domain, you can use something like the nginx directive bellow. I haven't tested this, so use at your own digression. Nginx directives can be added to a domain via Domains > example.com > Hosting & DNS > Apache & nginx Settings via the Additional nginx directives field.
NGINX:
location / {
    if ($http_user_agent ~* "Macintosh.*Chrome/") {
        return 403;
    }
}
But again, htaccess should work fine if you have not disabled Proxy Mode for the domain.

However, since you're writing that you want to "allow genuine visitors", I am assuming your intention is to block traffic that you see as harmful (or unwanted). So I want to point out that it's incredibly easy for anyone to "spoof" or change their User Agent (the data send with every request to identify the users browser and OS). Blocking traffic based on the user (supposed) browser and OS is generally not considered very practical and efficient.

More effective methods usually are some sort of challenge–response test to determine whether a visitor is actually human. Like a captcha, turnstile or something similar.
 
Hi Kaspar :)

Thanks for your reply.

In Plesk's nginx settings: Proxy mode is ticked. I assume it's enabled.

The code in htaccess is:-
Code:
RewriteEngine On

# 1. Allow major search engines (Google, Bing, Yahoo, DuckDuckGo)
RewriteCond %{HTTP_USER_AGENT} !(Googlebot|bingbot|Slurp|DuckDuckBot) [NC]

# 2. Allow Android and iPhone
RewriteCond %{HTTP_USER_AGENT} !Android [NC]
RewriteCond %{HTTP_USER_AGENT} !iPhone [NC]

# 3. Block Chrome on Mac
RewriteCond %{HTTP_USER_AGENT} Intel\sMac\sOS\sX [NC]
RewriteCond %{HTTP_USER_AGENT} Chrome [NC]
RewriteCond %{HTTP_USER_AGENT} !Edge [NC]
RewriteCond %{HTTP_USER_AGENT} !OPR [NC]
RewriteRule ^ - [F,L]

# 4. Block Chrome on Linux
RewriteCond %{HTTP_USER_AGENT} Linux [NC]
RewriteCond %{HTTP_USER_AGENT} Chrome [NC]
RewriteCond %{HTTP_USER_AGENT} !Android [NC]
RewriteCond %{HTTP_USER_AGENT} !Edge [NC]
RewriteCond %{HTTP_USER_AGENT} !OPR [NC]
RewriteRule ^ - [F,L]

order allow,deny
deny from xxx.xxx.xxx.xxx
 .. several lines

You mentioned:
Code:
location / {
if ($http_user_agent ~* "Macintosh.*Chrome/") {
return 403;
}
}

I think there is more code needed to allow mobile browsers and search engines crawlers.
 
UPDATE:
I am not absolutely sure about my last statement:

"I think there is more code needed to allow mobile browsers and search engines crawlers."

But just to be on the safe side, lest the code should block everything!
 
Back
Top