==== X-Frame Options ==== nano /etc/apache/sites-available/default-ssl.conf ... Header always set X-Frame-Options "DENY" ...