# /etc/apache2/conf-available/xss-filtering.conf Header always set X-XSS-Protection "1; mode=block"