For instance, if you set a cookie called 'gold' with value '10' I could edit my cookie file and give myself 1000000 gold.
The proper way to do it is to hand a unique string (such as provided by Apache::Session) to the browser as a cookie. When they return it, load their data from the backing store.
This stops users from tampering with the information.
____________________
Jeremy
I didn't believe in evil until I dated it.
In reply to Re: Re: Game.
by jepri
in thread Game.
by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |