5.4 Disable Moving or Resizing of Windows via Scripts

Information

This setting allows the configuration of how Firefox handles scripts from moving or resizing browser windows.

Rationale:

Arbitrary web sites can disguise an attack taking place in a minimized background window by moving or resizing browser windows.

Impact:

Scripts will not be able to move or resize browser windows.

This is the default behavior.

Solution

To establish the recommended configuration, set dom.disable_window_move_resize to false:

Type about:config in the address bar

Type dom.disable_window_move_resize in the filter

Ensure the setting is set as prescribed.

OR

Open the mozilla.cfg file in the installation directory with a text editor

Add the following lines to mozilla.cfg:

lockPref('dom.disable_window_move_resize', false);

Default Value:

False (Disabled).

See Also

https://workbench.cisecurity.org/files/4299

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-7, 800-53|CM-7(1), 800-53|SI-7, 800-53|SI-7(1)

Plugin: Windows

Control ID: 9807aec6e4e3d80ddb4f306ba0d19a3548303f32640b7431b296f1b319b9e0ff