DTBF105 - Network shell protocol is enabled in FireFox.

Information

Although current versions of Firefox have this set to disabled by default, use of this option can be harmful. This would allow the browser to access the Windows shell. This could allow access to the
underlying system. This check verifies that the default setting has not been changed.

Solution

Procedure: Set the value of 'network.protocol-handler.external.shell' to 'false' and lock using the Mozilla.cfg file.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MOZ_Firefox_V5R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-000381, Rule-ID|SV-223157r612236_rule, STIG-ID|DTBF105, STIG-Legacy|SV-16710, STIG-Legacy|V-15771, Vuln-ID|V-223157

Plugin: Windows

Control ID: b2a6a90ecde9bfa1979818d0a253cd701a54ac82e1d6560dbfa1feb34393672b