MEDIUM · upstream
Oil and Natural Gas Corporation
2026-10-05 passive check: HTTP 200; TLS expires 2027-02-19; 1 headers absent on observed response.
ongcindia.combaseline scan 2026-04-27 · daily passive check 2026-10-05 · historical phase 2 assessment 2026-04-28
Daily passive check · 2026-10-05
score 38
Availability
HTTP 200
TLS
2027-02-19 · 137d
Headers
1 missing · 1 permissive
Email auth
SPF missing · DMARC absent
Baseline score · 2026-04-27
Watch
Historical findings · 2026-04-27
- 01SPF entirely missing — anyone can spoof @ongcindia.com
- 02DMARC absent
- 03CSP weak (upgrade-insecure-requests only)
- 04Liferay Portal stack visible (JSESSIONID/COOKIE_SUPPORT)
TLS security
pass
- Issuer
- DigiCert Inc
- Expires
- 2027-02-19(137d)
Email authentication
Hardening headers
4 / 1 / 1present/permissive/missing
- HSTSpresent
- CSPpermissive
- X-Framepresent
- X-Content-Typepresent
- Referrer-Policypresent
- Permissions-Policymissing
Lookalike domains
ongcindia.co.in→ 185.53.177.29 (Everdata/CDN, third-party owned)
Public topology · CT logs
2 total
2 subdomains in CT logs; no sensitive categories flagged.
Certificate-transparency logs are immutable and public. Sensitive subdomains advertised here cannot be retracted; the mitigation is forward-only — new internal services route through a private CA that does not submit to public CT.
Historical active assessment · 2026-04-28 · open archive
Historical phase 2 assessment · 2026-04-28
This assessment is preserved as a dated record. Its attack paths and patch deadlines are not current findings; use the daily passive check above for current TLS, headers, availability, and email authentication.
Historical question from 2026-04-28
Is unauthenticated access to Liferay workflow APIs blocked, and is the workflow component patched against CVE-2024-38002 — the highest-confidence attack path against ongcindia.com today?
Active fingerprints · per host
www.ongcindia.comEOL × 1Liferay Portal 7.x (exact version not exposed)
- ⚠ Liferay version concealed; CVE-2024-38002 applies if 7.4.x ≤ 7.4.3.111
Attack-path simulation
Mythos-class adversary analytical chain · paths ranked by exploitability × access value.
Path B: Liferay Layout SEO CSRF → RCE (CVE-2023-35030)
Path C: Ransomware staging via admin password spray
Mythos compression
Discovery-time compression: pre-AI adversary vs Mythos-class adversary, per attack path.
The compression factor is reasoned, not measured. Mythos-class capability changes the tempo of attack-path traversal; the topology of the chain is unchanged.
Historical patch list · 2026-04-28
Tier 1 · within 7 days
- critical
Liferay Workflow RCE (CVE-2024-38002) — patch to 7.4.3.112+
- Host
www.ongcindia.com- CVE
CVE-2024-38002- Fix
- Upgrade Liferay to 7.4.3.112+ or backport. If on 7.3 LTS upgrade to 7.3.10.21+. Validate workflow API requires admin permission post-patch.
- Owner
- ONGC Infrastructure / Liferay Ops
- Validation
curl /api/jsonws/workflow.workflow/get-workflows returns 401/403 without auth
- critical
Liferay Layout CSRF (CVE-2023-35030)
- Host
www.ongcindia.com- CVE
CVE-2023-35030- Fix
- Liferay 7.4.3.77+. Enable SameSite=Strict on session cookies.
- Owner
- ONGC Infrastructure
- Validation
Set-Cookie header shows SameSite=Strict
Tier 2 · within 30 days
- high
MFA on all Liferay admin accounts
- Host
www.ongcindia.com- Fix
- Liferay → Control Panel → Security → enable TOTP/hardware key for Administrator role.
- Owner
- ONGC IAM
- Validation
Admin login without MFA rejected
- high
DMARC p=reject + SPF audit (currently DMARC absent)
- Host
ongcindia.com (email)- Fix
- Publish DMARC p=reject. SPF: explicit includes for actual mail infrastructure. DKIM signing.
- Owner
- ONGC IT / Email Security
- Validation
dig _dmarc.ongcindia.com returns p=reject