3.6 Validate Proxy Settings

Information

Firefox can be configured to use one or more proxy servers. When a proxy server is configured for a given protocol (HTTP, FTP, Gopher, etc), Firefox will send applicable requests to that proxy server for fulfillment. It is recommended that the list of proxy servers configured in Firefox be reviewed to ensure it contains only trusted proxy servers.

Rationale:

Depending on the protocol used, the proxy server will have access to read and/or alter all information communicated between Firefox and the target server, such a web site.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Perform the following procedure:

Drop down the Firefox menu

Click on Settings

Scroll down to the Network Settings section

Click on Settings Button

Ensure that the proxy listed (if any) is the one configured and approved by the enterprise.

Default Value:

No proxy.

See Also

https://workbench.cisecurity.org/files/4299

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: cd35a0d5833f639f4c53b5804083ab86a2a8d0a6561321b027f816357897820b