DTBF181 - FireFox is configured to allow JavaScript to move or resize windows.

Information

JavaScript can make changes to the browser's appearance. This activity can help disguise an attack taking place in a minimized background window. Set browser setting to prevent scripts on visited websites from moving and resizing browser windows.

Solution

Ensure the preference 'dom.disable_window_move_resize' is set and locked to the value of 'true'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MOZ_Firefox_V5R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-000381, Rule-ID|SV-223164r612236_rule, STIG-ID|DTBF181, STIG-Legacy|SV-16718, STIG-Legacy|V-15779, Vuln-ID|V-223164

Plugin: Windows

Control ID: 8c87d703a6138e53d23099cd6fc90f9878e36bc95f8b4c6e5042df175617c848