Mozilla has detailed its recent efforts to "harden" the Firefox browser against code injection attacks .
Its goal is to remove potentially dangerous elements in the core Firefox code.

The removal of the texts is intended to improve the protection of Firefox's 'about' protocol, better known as pages.
There are dozens of these "pages," which allow users to do things like display networking information, see how the browser , and examine installed plug-ins.
Mozilla has some concerns that hackers could use code injection to abuse a “config” page.
These pages are written in HTML and JavaScript, so they share the same security model as regular web pages, which are also vulnerable to code injection attacks. An attacker could inject code and then change the browser's configuration settings.

The two departments' response to this security risk was to rewrite all inline event handlers and move all inline JavaScript code to packaged files for all 45 or so pages. Second, Mozilla set a "strong" Content Security Policy to ensure that injected JavaScript code is not executed
“Disallowing embedded scripting on any of the pages limits the attack surface of arbitrary code execution and therefore provides a strong first line of defense against code injection attacks,” Kerschbaumer notes.
Another security enhancement measures address the eval function in JavaScript, which Mozilla describes as a “dangerous function” and warns developers to never use.
“Eval is a dangerous operation, which executes the code passed to it,” Mozilla explains in its developer support notes.
Kerschbaumer describes the operation as a “powerful but dangerous tool.”.
The purpose of this measure is to reduce the attack surface on Firefox and further discourage use of the feature.
