A long time ago, I put an XSS payload in the HTTP Server response header on all of my self-hosted domains. Years of messing around with XSS has taught me that any public plaintext data will eventually be rendered as HTML by someone. After some time, the Server header XSS …







