I tested Stompy tool and now there is the result of running this tool. but I can't use the result. How do I deduce the session managment of the target site is vulnerable from the output? the output file is attached.
Note:
Stompy is a free tool to perform black-box assessment of algorithms used to
generate WWW session identifiers or other tokens that are meant to withstand
statistical analysis and brute-force attacks.
http://www.darknet.org.uk/2007/03/stompy-the-web-application-session-analyzer-tool/
Download Link: http://lcamtuf.coredump.cx/stompy.tgz
How can I attach file here?
log file: http://www.4shared.com/file/FuqvQ4q-/log.html


