Roll20-cheat-dice
: A showcase repository illustrating how to hijack WebSocket objects to modify client-side dice results.
GMs can use built-in Roll20 features to verify the integrity of dice rolls and prevent common exploits: roll20-cheat-dice
: A non-technical "cheat" involves temporarily inflating ability scores or modifiers on a character sheet before rolling, then quickly reverting them before the Game Master (GM) notices. Known Tools and Scripts : A showcase repository illustrating how to hijack
: Some exploits allow players to "throw away" unfavorable rolls before they are finalized. Since the client reports the final result to the game log, a player can repeatedly roll until a desired number is generated, then only permit that specific packet to reach the server. Since the client reports the final result to
This report examines technical vulnerabilities and common exploits associated with "roll20-cheat-dice," specifically focusing on client-side manipulation of the Roll20 virtual tabletop platform. Overview of Exploits
: GMs should hover their mouse over any suspicious roll in the chat window. This reveals the formula breakdown , showing the actual raw die roll and every modifier applied.