Burp Sequencer is a tool for analysing the degree of
randomness in an application's session tokens or other items on
whose unpredictability the application depends for its security.
Burp Sequencer performs the same kind of statistical tests as
Stompy, with the addition of more
tests, flexible token capture, quantitative results, graphical
reporting, and arbitrary sample sizes.
Key features include:
Highly configurable facility for live capture of tokens, and
ability to manually load a previously captured sample.
Full FIPS tests for randomness, and other tests including
spectral, correlation and compression tests.
Fine-grained graphical reporting of results, with intuitive
summaries of the number of bits of effective entropy.
Character- and bit-level analysis of randomness quality.
Statistical tests are properly recalibrated for arbitrary
sample sizes from 100 to 20,000 tokens.
Burp Sequencer is part of the Burp Suite of web application hack tools. For
examples of Burp Sequencer in action, see the screenshots, or for detailed
information about the configuration and use of Burp Sequencer, see the help file.