Suppose one learned that certain developer hardcoded a bunch of usernames and passwords into application, which made it into Production. Oh-oh ..!
You know both username and password - is there a way to scan the bytecode and identify whether in fact username, password was hardcoded?