Stompy is a free tool to perform a fairly detailed black-box assessment of WWW session identifier generation algorithms. Session IDs are commonly used to track authenticated users, and as such, whenever theyre predictable or simply vulnerable to brute-force attacks, we do have a problem.