The operating system must prevent the execution of prohibited mobile code.

From Solaris 11 X86 Security Technical Implementation Guide

Part of SRG-OS-000181

Associated with: CCI-001695

SV-60841r1_rule The operating system must prevent the execution of prohibited mobile code.

Vulnerability discussion

Decisions regarding the employment of mobile code within operating systems are based on the potential for the code to cause damage to the system if used maliciously. Mobile code technologies include Java, JavaScript, ActiveX, PDF, Postscript, Shockwave movies, Flash animations, and VBScript. Usage restrictions and implementation guidance apply to both the selection and use of mobile code installed on organizational servers and mobile code downloaded and executed on individual workstations.

Check content

The Firefox browser is included with Solaris. Ensure that Java and JavaScript access by Firefox are disabled. Start Firefox. Access the Edit > Preferences menu item. Access the Content tab. If Enable JavaScript is checked, this is a finding. Access the Tools > Add ons menu item Choose the Plugins tab. If Java is enabled, this is a finding.

Fix text

Start Firefox. Access the Edit > Preferences menu item. Choose the Content tab. Disable JavaScript using the check box. Access the Tools > Add ons menu item. Choose the Plugins tab. Disable Java by clicking on the Disable button.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer