MEDIUM · gas
GAIL India
2026-10-05 passive check: HTTP 200; TLS expires 2026-10-18; 4 headers absent on observed response.
gailonline.combaseline scan 2026-04-27 · daily passive check 2026-10-05 · historical phase 2 assessment 2026-04-28
Daily passive check · 2026-10-05
score 50
Availability
HTTP 200
TLS
2026-10-18 · 13d
Headers
4 missing · 0 permissive
Email auth
SPF strict · DMARC absent
Baseline score · 2026-04-27
Watch
Historical findings · 2026-04-27
- 01CSP includes unsafe-inline AND unsafe-eval in script-src — significant XSS surface
- 02Otherwise solid: HSTS, p=reject DMARC, tight SPF
- 03Apache backend, 2 subdomains only — minimal CT footprint
Current · time-bound actions
- 13d to expiryRenew the currently observed TLS certificate before expiry2026-10-18
TLS security
warn
- Issuer
- eMudhra Technologies Limited
- Expires
- 2026-10-18(13d)
certificate expires in 13 days
Email authentication
Hardening headers
2 / 0 / 4present/permissive/missing
- HSTSpresent
- CSPmissing
- X-Framepresent
- X-Content-Typemissing
- Referrer-Policymissing
- Permissions-Policymissing
Lookalike domains
gailonline.net→ 192.64.119.199 (third-party)
Public topology · CT logs
2 total
2 subdomains in CT logs; no sensitive categories flagged.
Certificate-transparency logs are immutable and public. Sensitive subdomains advertised here cannot be retracted; the mitigation is forward-only — new internal services route through a private CA that does not submit to public CT.
Historical active assessment · 2026-04-28 · open archive
Historical phase 2 assessment · 2026-04-28
This assessment is preserved as a dated record. Its attack paths and patch deadlines are not current findings; use the daily passive check above for current TLS, headers, availability, and email authentication.
Historical question from 2026-04-28
Can GAIL eliminate unsafe-inline/unsafe-eval from CSP before the next XSS injection is discovered in a public form field?
Active fingerprints · per host
gailonline.comEOL × 1Apache (no version disclosure)
- ⚠ CSP unsafe-inline + unsafe-eval (script-src) — XSS surface
Attack-path simulation
Mythos-class adversary analytical chain · paths ranked by exploitability × access value.
Path B: Spear-phishing with sector-themed lure
Path C: Refinery-contractor email phishing
Mythos compression
Discovery-time compression: pre-AI adversary vs Mythos-class adversary, per attack path.
The compression factor is reasoned, not measured. Mythos-class capability changes the tempo of attack-path traversal; the topology of the chain is unchanged.
Historical patch list · 2026-04-28
Tier 1 · within 7 days
- critical
Tighten CSP — remove unsafe-inline and unsafe-eval from script-src
- Host
gailonline.com- Fix
- Use nonce-based CSP for inline scripts. Audit templates for inline event handlers; migrate to external files.
- Owner
- Web / Frontend Engineering
- Validation
curl -i shows CSP without unsafe-inline/eval
- high
Audit form fields and AJAX endpoints for injection points; deploy WAF rule
- Host
gailonline.com- Fix
- Pen-test form inputs. Cloudflare/ModSecurity rule: block <script>, <iframe>, on*= patterns.
- Owner
- Security / WAF
- Validation
<img src=x onerror=alert(1)> payload returns 403
Tier 2 · within 30 days
- high
Subresource Integrity (SRI) on all CDN-hosted scripts
- Host
gailonline.com- Fix
- Add integrity=sha384-... attributes on external <script src> tags.
- Owner
- Frontend Engineering
- Validation
All external scripts have SRI hash attributes
- high
SIEM / EDR monitoring for suspicious document opens
- Host
GAIL endpoints- Fix
- Monitor Office macro execution and .lnk launches. Pilot 50-100 endpoints.
- Owner
- SOC / EDR
- Validation
EDR logs show exec block on suspicious file types
- high
Email attachment filtering — block .lnk, .exe, .ps1, macro Office
- Host
GAIL email infrastructure- Fix
- Mail gateway: block these extensions. Warn on external sender. Quarantine if exec content.
- Owner
- Email Security
- Validation
Test .lnk attachment quarantined
Tier 3 · within 90 days
- medium
Service-account credential rotation; reduce session TTL
- Host
gailonline.com- Fix
- Rotate all web-app service account creds. Audit token expiry; reduce to <4 h for sensitive ops.
- Owner
- App Security
- Validation
Application logs show session TTL < 4 h for sensitive ops