HIGH · refiner
Mangalore Refinery and Petrochemicals Ltd
2026-10-06 passive check: HTTP 503; TLS expires 2026-10-25; 6 headers absent on observed response.
mrpl.co.inbaseline scan 2026-04-27 · daily passive check 2026-10-06 · historical phase 2 assessment 2026-04-28
Daily passive check · 2026-10-06
score 42
Availability
HTTP 503
TLS
2026-10-25 · 19d
Headers
6 missing · 0 permissive
Email auth
SPF strict · DMARC quarantine
Baseline score · 2026-04-27
Critical
Historical findings · 2026-04-27
- 01TLS cert expires 2026-05-05 — 7 days remaining at this writing
- 02Missing CSP and Referrer-Policy headers
- 03Email auth strong (DMARC p=quarantine, SPF strict)
- 04Site connectivity issues at scan time
Current · time-bound actions
- 19d to expiryRenew the currently observed TLS certificate before expiry2026-10-25
TLS security
warn
- Issuer
- GlobalSign nv-sa
- Expires
- 2026-10-25(19d)
certificate expires in 19 days
Email authentication
Hardening headers
0 / 0 / 6present/permissive/missing
- HSTSmissing
- CSPmissing
- X-Framemissing
- X-Content-Typemissing
- Referrer-Policymissing
- Permissions-Policymissing
Lookalike domains
mrpl.co.com→ 169.60.151.233 (RIPE-allocated cloud, typosquat cluster)mrpl.in→ 109.71.252.143 (third-party)
Public topology · CT logs
0 total
No subdomains in CT logs — minimal external attack surface.
Certificate-transparency logs are immutable and public. Sensitive subdomains advertised here cannot be retracted; the mitigation is forward-only — new internal services route through a private CA that does not submit to public CT.
Historical active assessment · 2026-04-28 · open archive
Historical phase 2 assessment · 2026-04-28
This assessment is preserved as a dated record. Its attack paths and patch deadlines are not current findings; use the daily passive check above for current TLS, headers, availability, and email authentication.
Historical question from 2026-04-28
Can MRPL rotate the expiring certificate (7 days to expiry) and implement HPKP before the May 5–25 window opens for MITM credential harvesting at the refinery?
Active fingerprints · per host
mrpl.co.inEOL × 1Apache (Server returned 503 at scan time — load balancer or maintenance)
- ⚠ CERT EXPIRY in 7 days — Tier 1 incident; missing CSP; site connectivity issues at scan time
Attack-path simulation
Mythos-class adversary analytical chain · paths ranked by exploitability × access value.
Path B: SAP.MRPL subdomain hijack
Path C: Weak cert renewal chain → MITM persists
Path D: ERP procurement compromise
Mythos compression
Discovery-time compression: pre-AI adversary vs Mythos-class adversary, per attack path.
The compression factor is reasoned, not measured. Mythos-class capability changes the tempo of attack-path traversal; the topology of the chain is unchanged.
Historical patch list · 2026-04-28
Tier 1 · within 7 days
- critical
EMERGENCY: Rotate TLS certificate before 2026-05-05
- Host
mrpl.co.in- Fix
- Order new cert IMMEDIATELY (target 2026-04-29 install). OV cert from established CA. CSR strength: SHA-256 RSA 2048+ minimum. Install on all SANs (mrpl.co.in, *.mrpl.co.in, *.sap.mrpl.co.in).
- Owner
- MRPL TLS Admin
- Validation
openssl s_client | x509 -noout -enddate shows notAfter > 2026-05-15
- critical
Verify cert deploys to all subdomains (sap, www, etc.)
- Host
*.mrpl.co.in / *.sap.mrpl.co.in- Fix
- Deploy cert to load balancer + all reverse proxy endpoints.
- Owner
- MRPL TLS Admin / Infrastructure
- Validation
curl -sI https://sap.mrpl.co.in returns 200 with valid cert
Tier 2 · within 30 days
- high
Implement HPKP (HTTP Public Key Pinning) for backup cert key
- Host
mrpl.co.in- Fix
- Pin current cert + backup CA root. 30-day max-age. Phased rollout to avoid lockout.
- Owner
- Infrastructure
- Validation
curl -I shows Public-Key-Pins header
- high
Add CSP header (currently missing)
- Host
mrpl.co.in- Fix
- default-src 'self'; script-src 'self' 'nonce-{random}'; connect-src 'self' https://sap.mrpl.co.in; block-all-mixed-content.
- Owner
- Frontend / Security
- Validation
curl -i shows Content-Security-Policy header
- high
Upgrade DMARC p=quarantine → p=reject (after 30-day baseline)
- Host
mrpl.co.in (email)- Fix
- Monitor 30-day rua; promote to p=reject.
- Owner
- Email Security
- Validation
dig +short TXT _dmarc.mrpl.co.in returns p=reject
- high
Audit and disable unused subdomains; document SANs
- Host
*.mrpl.co.in- Fix
- nslookup *.mrpl.co.in. Decommission unused. Document each in SAN list.
- Owner
- Infrastructure
- Validation
Only active subdomains resolve
Tier 3 · within 90 days
- medium
Certificate pinning on client applications (mobile / API)
- Host
MRPL mobile apps / API clients- Fix
- Pin backup cert public key; phased SDK rollout.
- Owner
- App Development
- Validation
Client SDK logs show pin validation on TLS handshake