Roll20-cheat-dice Guide
GMs can use built-in Roll20 features to verify the integrity of dice rolls and prevent common exploits:
: A showcase repository illustrating how to hijack WebSocket objects to modify client-side dice results. roll20-cheat-dice
While Roll20 uses a "Quantum Roll" system to generate random numbers server-side, vulnerabilities often stem from how these results are communicated to and from the player's client. GMs can use built-in Roll20 features to verify
: Encouraging players to use official character sheet buttons rather than custom macros makes it easier to verify that standard modifiers are being used. roll20-cheat-dice
Several community-developed projects on platforms like GitHub demonstrate these vulnerabilities for educational or illustrative purposes:
: Monitoring the chat archive for unusual patterns—such as long delays before rolls or a total lack of "average" results—can help identify users employing packet filtering software.