Hi!
We do not have a formal document addressing security concerns at this point. But here are a few security-related points to consider:
- Cassini was not designed to be an enterprise-strength web server. It is rather a group-, family- and a personal-level web server intended to be used primarily in intranets and home networks;
- By default UltiDev Cassini runs under powerful "Local System" account. Taking over UltiDev Cassini means taking over entire computer if service's user account left unchanged. To improve security use different, more restricted identity for the Cassini service. (Using different user account for the service will make Cassini Explorer a read-only application as it needs extra privileges to save application configuration information).
- To disable Cassini Explorer you could either modify its Default.aspx and ApplicationDetails.aspx to make them useless, or if you don't need the functionality of the GoToApplication.aspx and CassiniConfigurationService.asmx - just manually remove the Cassini Explorer entry from the CassiniMetabase.xml file altogether. The file is located in "C:\Documents and Settings\All Users\Application Data\UltiDev\Cassini\" folder. Do not disable Cassini Explorer if other Cassini-based applications can be installed on the computer.
Please let us know if there are some other specifics you'd like to know more about.
Best regards,
UltiDev Team.
Please donate at
http://www.ultidev.com/products/Donate.aspx to help us improve our products.