php - Prevent Facemash cheating through url -


i've been using facemash-like script. problem while rating people when point our cursor towards picture every image there url like:

rate.php?winner=xxx&loser=xxxx1 

so, if directly type in address bar trick works! hence there chance users hack scores. know can change methods post methods. , i've searched , nothing helped me out. links files(rate.php , index.php) included in comments of question.

i'm making own facemash-like engine , here's do.

i store 2 challengers' ids in php $_session. before displaying new pair check if $_session set , if display them instead of taking new pair database. prevents cheating refreshing page until photo. did because community i'm making facemash relatively small.

so links vote.php?v=left or right. in vote.php ids $_session['right'] , $_session['left'] , unset them. looking forward publish script day.


Comments

Popular posts from this blog

django - How can I change user group without delete record -

java - Need to add SOAP security token -

java - EclipseLink JPA Object is not a known entity type -