7.4 Disable Popups Initiated by Plugins

Information

This feature controls popups that are initiated by plug-ins.

Rationale:

Disabling plug-in popups (except from white-listed sites) from being displayed, can guard against attacks that are launched using a pop-up.

Impact:

Pop-ups will not be displayed.

Solution

To establish the recommended configuration, set privacy.popups.disable_from_plugins to 2:

Type about:config in the address bar

Type privacy.popups.disable_from_plugins in the filter

Ensure the setting is set as prescribed.

OR

Open the mozilla.cfg file in the installation directory with a text editor

Add the following lines to mozilla.cfg:

lockPref('privacy.popups.disable_from_plugins', 2)

Default Value:

3

See Also

https://workbench.cisecurity.org/files/4299

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18, CSCv7|7.2

Plugin: Unix

Control ID: 36611937696ac1c3292e964fce85590da5d62ff30d39ef19936a3bb2e5049193