# loadVariables only from my server

**URL:** <https://forum.kirupa.com/t/loadvariables-only-from-my-server/183595>\
**Category:** flash\
**Created:** [March 28, 2006, 5:36pm UTC](https://forum.kirupa.com/t/loadvariables-only-from-my-server/183595 "2006-03-28T17:36:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Balala](https://avatars.discourse-cdn.com/v4/letter/b/df705f/32.png) [@Balala](https://forum.kirupa.com/u/Balala)\
**Post date:** [March 28, 2006, 5:36pm UTC](https://forum.kirupa.com/t/loadvariables-only-from-my-server/183595/1 "2006-03-28T17:36:44Z")

</div>

Hi guys,

Im developing a game. In some parts, i need to save some info on database (like experience, money, level, …).

But i cant let people inject code on the server side script (php).

If i send the variables via post, the injector may create a form and send too =(

In php, i’ve tried to get the referer from where the data came from… without success, from flash, the referer comes null =(

If i make SESSIONs, the injector may enter on the game, after that, he goes to the form to inject the data, the session will not be erased =(

Any idea?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![forwardtrends](https://avatars.discourse-cdn.com/v4/letter/f/cab0a1/32.png) [@forwardtrends](https://forum.kirupa.com/u/forwardtrends)\
**Post date:** [March 28, 2006, 5:45pm UTC](https://forum.kirupa.com/t/loadvariables-only-from-my-server/183595/2 "2006-03-28T17:45:30Z")

</div>

If the form is never mentioned (ie the\_form.php) inside flash - how will an “injector” be able to mimic a form call? (Not to mention without knowing what the form variables are)

---

<div class="post-metadata">

**Author:** ![JoshuaJonah](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/joshuajonah/32/1775_2.png) [@JoshuaJonah](https://forum.kirupa.com/u/JoshuaJonah)\
**Post date:** [March 28, 2006, 5:51pm UTC](https://forum.kirupa.com/t/loadvariables-only-from-my-server/183595/3 "2006-03-28T17:51:56Z")

</div>

> [@forwardtrends](#):
>
> If the form is never mentioned (ie the\_form.php) inside flash - how will an “injector” be able to mimic a form call? (Not to mention without knowing what the form variables are)

As long as the PHP page is not displaying the information. If it’s just pulling into flash, your pretty secure. Unless you use a decompressor.

---

<div class="post-metadata">

**Author:** ![Balala](https://avatars.discourse-cdn.com/v4/letter/b/df705f/32.png) [@Balala](https://forum.kirupa.com/u/Balala)\
**Post date:** [March 28, 2006, 5:55pm UTC](https://forum.kirupa.com/t/loadvariables-only-from-my-server/183595/4 "2006-03-28T17:55:49Z")

</div>

Yeah… the ■■■■ decompilers =/

With these tools, the injector will know the file name
