7.4 Disable Popups Initiated by Plugins

Information

This feature controls popups that are initiated by plug-ins.

Rationale:

Disabling plug-in popups (except from white-listed sites) from being displayed, can guard against attacks that are launched using a pop-up.

Impact:

Pop-ups will not be displayed.

Solution

To establish the recommended configuration, set privacy.popups.disable_from_plugins to 2:

Type about:config in the address bar

Type privacy.popups.disable_from_plugins in the filter

Ensure the setting is set as prescribed.

OR

Open the mozilla.cfg file in the installation directory with a text editor

Add the following lines to mozilla.cfg:

lockPref('privacy.popups.disable_from_plugins', 2)

Default Value:

3

See Also

https://workbench.cisecurity.org/files/4299

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18, CSCv7|7.2

Plugin: Windows

Control ID: 36697ba0611a26edf9620732424eb46f22e2ad1b3201e5f068db1da78e227642