1. Home
  2. Security Hardening
  3. DISA STIG Mozilla Firefox Windows V6R1
  4. FFOX-00-000010 – Firefox must be configured to prevent JavaScript from moving or resizing windows.

FFOX-00-000010 – Firefox must be configured to prevent JavaScript from moving or resizing windows.

Details

JavaScript can make changes to the browser’s appearance. This activity can help disguise an attack taking place in a minimized background window. Configure the browser setting to prevent scripts on visited websites from moving and resizing browser windows.

Solution

Windows group policy:
1. Open the group policy editor tool with ‘gpedit.msc’.
2. Navigate to Policy Path: Computer ConfigurationAdministrative TemplatesMozillaFirefox
Policy Name: Preferences
Policy State: Enabled
Policy Value:
{
‘dom.disable_window_move_resize’: {
‘Value’: true,
‘Status’: ‘locked’
}
}

macOS ‘plist’ file:
Add the following:
Preferences

dom.disable_window_move_resize

Value
Status
locked

Linux ‘policies.json’ file:
Add the following in the policies section:
‘Preferences’: {
‘dom.disable_window_move_resize’: {
‘Value’: true,
‘Status’: ‘locked’
}
}

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles