I've found a movement bug. As an example, check out my level and equipment and let me know if you think I could possibly get to the Lich King The portal was kinda cool too
I've noticed that you can enter any of the following URL's into the address line and move around pretty much freely and unhindered...
Code: Select all
http://www.darkgrimoire.com/move.php?dir=north
http://www.darkgrimoire.com/move.php?dir=south
http://www.darkgrimoire.com/move.php?dir=east
http://www.darkgrimoire.com/move.php?dir=west
http://www.darkgrimoire.com/move.php?dir=down
http://www.darkgrimoire.com/move.php?dir=up
What I would suggest is that when you write a players location back to the database you also write an md5 hash to it also. Then append that hash to all the movement URL's. e.g.
Code: Select all
http://www.darkgrimoire.com/move.php?dir=north&hash=D2BC25335AE3F76AFBFA0F47D52D413D
http://www.darkgrimoire.com/move.php?dir=south&hash=D2BC25335AE3F76AFBFA0F47D52D413D
http://www.darkgrimoire.com/move.php?dir=east&hash=D2BC25335AE3F76AFBFA0F47D52D413D
http://www.darkgrimoire.com/move.php?dir=west&hash=D2BC25335AE3F76AFBFA0F47D52D413D
http://www.darkgrimoire.com/move.php?dir=down&hash=D2BC25335AE3F76AFBFA0F47D52D413D
http://www.darkgrimoire.com/move.php?dir=up&hash=D2BC25335AE3F76AFBFA0F47D52D413D
Then, when the player moves and you pull their record to see where they are you can check this hash against the one in the database. If they don't match they're trying to fudge something...