Sanket security register · baseline 2026-04-27 · daily passive check 2026-06-13

19 MoPNG entities · Phase 2 active on 19

7 of 19 entities flagged HIGH.

Sanket is a public passive-reconnaissance register on the Indian Ministry of Petroleum and Natural Gas digital estate. Civic-tech transparency, refreshed daily. Click any tile below for the full per-entity assessment.

Today's spear

-39days to 2026-05-05

Rotate TLS certificate before May 5 to avoid outage

MRPL · mrpl.co.in

Security distribution

55avg score · 0 worst · 100 best
  • HIGH7
  • MEDIUM10
  • LOW1
  • PROVISIONAL1

Daily check

19entities checked

15/19 responded. 5 TLS watches, 18 header gaps, 7 email-auth risks.

Re-scan cadence · daily at 09:00 IST

Directory

19 entities · sorted worst-first

click any tile for full assessment

HIGH▸ Phase 2

OISD

oisd.gov.in
36Critical

Cert CN mismatch (CN=www, apex unmatched); cert expires 2026-05-17; 0/6 hardening headers

-29dRotate TLS certificate before May 17 + correct CN/SAN to cover apex
HIGH▸ Phase 2

EIL

engineersindia.com
38Elevated

Indexed directory listing exposes CPP-Angul-Smelter project files; Apache 2.4.29 EOL; no SPF/DMARC

3dDisable directory indexing on /wp-content/uploads/
HIGH▸ Phase 2

MRPL

mrpl.co.in
40Critical

Cert expires 2026-05-05 (8 days from scan); missing CSP and Referrer-Policy

-39dRotate TLS certificate before May 5 to avoid outage
HIGH▸ Phase 2

PPAC

ppac.gov.in
42Elevated

DMARC absent + 6/6 hardening headers missing + permissive CSP

no time-bound actions
HIGH▸ Phase 2

RGIPT

rgipt.ac.in
42Critical

Wildcard cert expires 2026-05-09 (12 days); DMARC absent

-35dRotate wildcard *.rgipt.ac.in cert before May 9
HIGH▸ Phase 2

BPCL

bharatpetroleum.in
44Elevated

Test/QA environments named in CT (adfstest, qa.convenience, qa.speed)

no time-bound actions
HIGH▸ Phase 2

HPCL

hindustanpetroleum.com
46Elevated

All 6 hardening headers missing; SPF ~all +a +mx (broad spoofing surface)

no time-bound actions
MEDIUM▸ Phase 2

ONGC

ongcindia.com
56Watch

SPF entirely missing; DMARC absent; weak CSP

no time-bound actions
MEDIUM▸ Phase 2

Petronet LNG

petronetlng.com
58Watch

0/6 hardening headers despite strong email auth; ADFS exposed in CT

no time-bound actions
MEDIUM▸ Phase 2

PCRA

pcra.org
58Watch

Missing SPF and DMARC; Cloudflare-fronted

no time-bound actions
MEDIUM▸ Phase 2

DGH

dghindia.gov.in
60Watch

CSP permits unsafe-inline + unsafe-eval; missing Referrer-Policy

no time-bound actions
MEDIUM▸ Phase 2

CPCL

cpcl.co.in
60Watch

WordPress fingerprint exposed via /wp-json/; missing CSP

no time-bound actions
MEDIUM▸ Phase 2

NRL

nrl.co.in
62Watch

45+ subdomains visible in CT including VPN, AD, document mgmt; no breach detected

no time-bound actions
MEDIUM▸ Phase 2

PNGRB

pngrb.gov.in
64Watch

edev.* dev environment exposed in CT; IIS ETag fingerprint leak

no time-bound actions
MEDIUM▸ Phase 2

IOC

iocl.com
66Watch

admin.iocl.com exposed in CT; Sucuri WAF in front

no time-bound actions
MEDIUM▸ Phase 2

MoPNG

mopng.gov.in
68Watch

SPF broken (rejects all senders despite live MX); otherwise hardened

no time-bound actions
MEDIUM▸ Phase 2

GAIL

gailonline.com
70Watch

CSP unsafe-inline + unsafe-eval (XSS surface); otherwise strong

no time-bound actions
LOW▸ Phase 2

Oil India

oil-india.com
88Normal

Cleanest in portfolio: strict SPF -all, p=reject DMARC, strong CSP

no time-bound actions
PROVISIONAL▸ Phase 2

BPRL

bharatpetroresources.com
Watch

Canonical pending verification with BPCL parent; assumed canonical bprlindia.com had no DNS

30dConfirm canonical domain via BPCL parent or MoPNG annual report reference

Portfolio-urgent

All time-bound items, soonest first

  • -39dMRPLRotate TLS certificate before May 5 to avoid outage
  • -35dRGIPTRotate wildcard *.rgipt.ac.in cert before May 9
  • -29dOISDFix SPF: include actual mail infrastructure or set neutral if no mail sent from domain
  • -27dOISDRotate TLS certificate before May 17 + correct CN/SAN to cover apex
  • -13dMRPLAdd CSP and Referrer-Policy headers
  • -13dOISDAdd HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy headers
  • -13dRGIPTAdd DMARC record (start with p=none for reporting, then tighten)
  • 3dEILDisable directory indexing on /wp-content/uploads/
  • 7dEILSubmit Google de-index request for the exposed CPP-Angul-Smelter folder
  • 30dBPRLConfirm canonical domain via BPCL parent or MoPNG annual report reference

Sibling project: Sanjaya — fuel-pricing transparency on the same Ministry portfolio. Sanjaya narrates; Sanket warns.

Methodology is reproducible by any visitor with curl, dig, and openssl.