Analyzing DoS Attack Using Middlebox Amplification on CAPTCHA Server
Hyejin Lee, Woonghee Lee, Kyungrok Choi, Junbeom Hur · 2025
Denial-of-Service (DoS) attacks remain a significant threat to the Internet infrastructure, particularly when attackers leverage reflection and amplification techniques to generate largescale traffic with minimal resources. CAPTCHA servers, which are widely deployed to prevent automated access to web services, can inadvertently act as amplification vectors due to their automated and often large responses. In this paper, we investigate and analyze the potential security threat of reflected amplification DoS attacks utilizing CAPTCHA servers as middleboxes. Specifically, we focus on the structural characteristics of CAPTCHA servers that can be exploited to generate amplified traffic. Our methodology involves crafting and sending both normal and manipulated HTTP requests to an open-source CAPTCHA server, and measuring the corresponding amplification factors. The experimental results show that manipulated requests can achieve amplification factors up to 47.7x, significantly higher than those of standard interactions, thereby confirming the feasibility of abuse. For future work, we plan to extend our analysis to commercial CAPTCHA services and explore real-world attack feasibility in network environments that allow IP spoofing, as well as alternative TCP-layer bypass techniques.