Hello,
I have recently created a pokemon game,
www.pokemoncreed.net
Many of my users have hacked my game before, I realised they did this by stealing my cookie which contained my password, so I switched to PHP Sessions (MD5), which doesn't contain the password in any way.
I have stopped all SQL attacks in every area, every page in my game.
I have released the game 4 weeks ago, in this 2 weeks no'one seems to be hacking or leveling really fast.
Logs were recorded in my custom admin panel I made that someone battled and sent forms/data at a rapid rate, I have randomnised it and slowed it down, the player doesn't seem to level up so fast.
And uuhh.. about the game, its based on "Pokemon", and if you have experience or knowledge on how to abuse PHP holes, please try that in my game, but don't do it excessively or ruin my game please :p, furthermore please report these holes here.
P.S. Game or script is not for sale :).
Thanks.