Let's test randomness on the generated values using the Burp Suite Sequencer:
- To use Burp Suite Sequencer, a response containing the Set-Cookie header value or other pseudorandom number value to be tested needs to be sent to it. This can be sent either from the HTTP history tab under the Proxy tab or from a response intercepted prior to being received by the browser, as shown in the following screenshot:
- Burp will automatically populate the Cookie drop-down menu with all the cookie values set in the response. Alternatively, you can use the Custom location field and then the Configure button to designate any location in the ...