HIGH · safety
Oil Industry Safety Directorate
2026-10-05 passive check: HTTP 302; TLS expires 2027-02-11; 1 headers absent on observed response.
oisd.gov.inbaseline scan 2026-04-27 · daily passive check 2026-10-05 · historical phase 2 assessment 2026-04-28
Daily passive check · 2026-10-05
score 24
Availability
HTTP 302
TLS
2027-02-11 · 129d
Headers
1 missing · 1 permissive
Email auth
SPF strict · DMARC reject
Baseline score · 2026-04-27
Critical
Historical findings · 2026-04-27
- 01Cert CN/SAN mismatch — CN=www.oisd.gov.in but apex unmatched
- 02Cert expires 2026-05-17 (19 days)
- 03Zero standard hardening headers (0/6)
- 04Broken SPF (-all rejects all senders, no DMARC recovery path)
TLS security
warn
- Issuer
- DigiCert Inc
- Expires
- 2027-02-11(129d)
TLS validation warning: UNABLE_TO_VERIFY_LEAF_SIGNATURE
Email authentication
Hardening headers
4 / 1 / 1present/permissive/missing
- HSTSpresent
- CSPpermissive
- X-Framepresent
- X-Content-Typepresent
- Referrer-Policypresent
- Permissions-Policymissing
Lookalike domains
oisd.com→ 76.223.54.146 (third-party)
Public topology · CT logs
0 total
No subdomains in CT logs — minimal external attack surface.
Certificate-transparency logs are immutable and public. Sensitive subdomains advertised here cannot be retracted; the mitigation is forward-only — new internal services route through a private CA that does not submit to public CT.
Historical active assessment · 2026-04-28 · open archive
Historical phase 2 assessment · 2026-04-28
This assessment is preserved as a dated record. Its attack paths and patch deadlines are not current findings; use the daily passive check above for current TLS, headers, availability, and email authentication.
Historical question from 2026-04-28
OISD is fragile across three dimensions — imminent cert expiry (19 days), broken email authentication, and Apache 2.2.15 EOL with 8+ years of unpatched CVEs. What is the incident response if cert renewal fails on 2026-05-17?
Active fingerprints · per host
oisd.gov.inEOL × 3Apache server; apex 404; www subdomain serves
- ⚠ IMMINENT cert expiry; CN/SAN mismatch — apex returns browser warning
- ⚠ Apex CSP permissive (unsafe-inline/eval)
- ⚠ 0/6 hardening headers on apex
connect.oisd.gov.inEOL × 1Apache 2.2.15 (Red Hat) — EOL since 2017
- ⚠ Apache 2.2.15 EOL since 2017 — 8+ years of unpatched CVEs
Attack-path simulation
Mythos-class adversary analytical chain · paths ranked by exploitability × access value.
Path B: Email spoofing via broken SPF (-all without senders) + absent DMARC
Path C: Apache 2.2.15 EOL — unpatched RCE on connect subdomain
Path D: Subdomain enumeration → potential takeover
Mythos compression
Discovery-time compression: pre-AI adversary vs Mythos-class adversary, per attack path.
The compression factor is reasoned, not measured. Mythos-class capability changes the tempo of attack-path traversal; the topology of the chain is unchanged.
Historical patch list · 2026-04-28
Tier 1 · within 7 days
- critical
EMERGENCY: Rotate TLS cert before 2026-05-17 with apex SAN coverage
- Host
oisd.gov.in- Fix
- Renew cert. Ensure SAN includes BOTH apex (oisd.gov.in) AND www. Re-issue if current cert only covers www. Validate apex serves 200 OK post-renewal.
- Owner
- OISD TLS Admin
- Validation
openssl s_client | x509 -noout -ext subjectAltName shows both apex and www
- critical
Fix broken SPF — add real includes or set neutral
- Host
oisd.gov.in (email)- Fix
- Replace 'v=spf1 -all' with 'v=spf1 include:<actual mail provider> -all'. If domain doesn't send mail, document and keep -all but pair with DMARC p=reject for clarity.
- Owner
- OISD IT / Email
- Validation
Legitimate mail from approved senders delivers; spoofed mail bounces
- critical
Publish DMARC record — start p=quarantine, escalate to p=reject
- Host
oisd.gov.in (email)- Fix
- DMARC: 'v=DMARC1; p=quarantine; rua=mailto:dmarc@oisd.gov.in; fo=1'. Monitor 2 weeks; escalate to p=reject.
- Owner
- OISD IT / Email
- Validation
dig +short TXT _dmarc.oisd.gov.in returns DMARC1
- critical
Apache 2.2.15 — upgrade to 2.4.62+ or migrate to nginx reverse proxy
- Host
connect.oisd.gov.in- CVE
Multiple unpatched (Apache 2.2.x EOL 2017)- Fix
- (a) In-place upgrade to Apache 2.4.62+ with regression testing OR (b) Deploy nginx 1.26+ in reverse-proxy mode pointing to hardened backend. Test connect endpoint thoroughly.
- Owner
- OISD Infrastructure
- Validation
curl -sI connect.oisd.gov.in | grep Server shows Apache 2.4.62+ or nginx
Tier 2 · within 30 days
- high
Harden CSP — remove unsafe-inline and unsafe-eval
- Host
oisd.gov.in- Fix
- Nonce-based CSP for inline scripts.
- Owner
- OISD Web Ops
- Validation
curl -i shows CSP without unsafe-inline/eval
- high
Add the missing 6 hardening headers on apex
- Host
oisd.gov.in- Fix
- HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy.
- Owner
- OISD Web Ops
- Validation
securityheaders.com returns A or A+
- high
Subdomain inventory + takeover prevention
- Host
*.oisd.gov.in- Fix
- For each CT-logged subdomain, verify DNS points to owned infra. Remove dangling CNAMEs. Implement CT monitoring.
- Owner
- OISD Infrastructure
- Validation
Official subdomain register; monthly CT cross-check
Tier 3 · within 90 days
- medium
Reverse proxy / WAF deployment
- Host
OISD edge- Fix
- ModSecurity OWASP CRS or Cloudflare. Block traversal, SQLi, mod_rewrite exploit patterns.
- Owner
- Security Operations
- Validation
WAF testing: CVE PoC payloads return 403
- medium
Apache deprecation roadmap for entire OISD estate
- Host
OISD-wide- Fix
- Document timeline to retire all Apache 2.2.x and migrate to supported versions.
- Owner
- OISD CISO
- Validation
Migration plan filed with target dates