What parts of the Session ID are static?
What clear-text confidential information is stored in the Session ID? E.g. usernames/UID, IP addresses
What easily decoded confidential information is stored?
What information can be deduced from the structure of the Session ID?
What portions of the Session ID are static for the same log in conditions?
What obvious patterns are present in the Session ID as a whole, or individual portions?