
The Windows registry holds all sorts of authentication information, including
usernames and passwords.Though it is unlikely (and fairly uncommon) to locate
live, exported Windows registry files on the Web, at the time of this writing
there are nearly 100 hits on the query filetype:reg HKEY_CURRENT_USER
username, which locates Windows registry files that contain the word username
and in some cases passwords, as shown in Figure 9.3.
As any talented attacker or security person will tell you, it’s rare to get infor-
mation served to you on a silver platter. Most decent finds take a bit of persis-
tence, creativity, intelligence, and just a bit of good luck. ...