Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-15778 | DTBF180 | SV-16717r1_rule | ECSC-1 | Medium |
Description |
---|
Popup windows may be used to launch an attack within a new browser window with altered settings. This setting blocks popup windows created while the page is loading. |
STIG | Date |
---|---|
Mozilla FireFox | 2014-07-03 |
Check Text ( C-16623r1_chk ) |
---|
In About:Config, verify that the preference name “dom.disable_window_open_feature.status " is set to “true” and locked. Criteria: If the parameter is set incorrectly, then this is a finding. If the setting is not locked, then this is a finding. |
Fix Text (F-15995r1_fix) |
---|
Ensure the preference "dom.disable_window_open_feature.status " is set and locked to the value of “true”. |