Obtain in reverse the .Net source code for your application
Anakrino (open source) http://www.saurik.com/net/exemplar
Salamander (comercial) http://www.remotesoft.com/salamander/index.html
Cool for looking for connection strings etc.
Mitigation by obfuscation or other techniques:
http://www.remotesoft.com/salamander/obfuscator.html (comercial) http://www.remotesoft.com/salamander/protector.html (comercial)
A similar approach is available for Java
-- Mads Rasmussen, M.Sc. Open Communications Security www.opencs.com.br +55 11 3345 2525