├── README.md
├── rules_for_radicals.txt
├── chess.txt
├── quotes_gq.fortune
├── moscow_rules_full2.html
├── downclimb.txt
├── murphys_laws_of_war.md
├── moscow_rules_full.html
├── fortune.txt
└── murphys_laws_of_combat.md
/README.md:
--------------------------------------------------------------------------------
1 | # quotes
2 | quotes i like.
3 |
--------------------------------------------------------------------------------
/rules_for_radicals.txt:
--------------------------------------------------------------------------------
1 | Rules for radicals
2 |
3 | 1. "Power is not only what you have but what the enemy thinks you have."
4 | 2. "Never go outside the expertise of your people."
5 | 3. "Whenever possible go outside the expertise of the enemy."
6 | 4. "Make the enemy live up to its own book of rules."
7 | 5. "Ridicule is man's most potent weapon."
8 | 6. "A good tactic is one your people enjoy."
9 | 7. "A tactic that drags on too long becomes a drag."
10 | 8. "Keep the pressure on."
11 | 9. "The threat is usually more terrifying than the thing itself."
12 | 10. "The major premise for tactics is the development of operations that will maintain a constant pressure upon the opposition."
13 | 11. "If you push a negative hard and deep enough it will break through into its counterside."
14 | 12. "The price of a successful attack is a constructive alternative."
15 | 13. "Pick the target, freeze it, personalize it, and polarize it."
16 |
--------------------------------------------------------------------------------
/chess.txt:
--------------------------------------------------------------------------------
1 | %
2 | Chess is the struggle against the error.” – Johannes Zukertort
3 | %
4 | “I don’t believe in psychology. I believe in good moves.” – Bobby Fischer
5 | %
6 | I used to attack because it was the only thing I knew. Now I attack because I know it works best.” – Garry Kasparov
7 | %
8 | When you see a good move, look for a better one.” – Emanuel Lasker
9 | %
10 | Chess is rarely a game of ideal moves. Almost always, a player faces a series of difficult consequences whichever move he makes.” – David Shenk
11 | %
12 | Half the variations which are calculated in a tournament game turn out to be completely superfluous. Unfortunately, no one knows in advance which half.” – Jan Timman
13 | %
14 | Even a poor plan is better than no plan at all.” – Mikhail Chigorin
15 | %
16 | Tactics is knowing what to do when there is something to do; strategy is knowing what to do when there is nothing to do.” – Savielly Tartakower
17 | %
18 | In life, as in chess, forethought wins.” – Charles Buxton
19 | %
20 | Nobody ever won a chess game by resigning.” – Savielly Tartakower
21 | %
22 | “The blunders are all there on the board, waiting to be made.” – Savielly Tartakower
23 | %
24 | “One doesn’t have to play well, it’s enough to play better than your opponent.” – Siegbert Tarrasch
25 | %
26 | “If your opponent offers you a draw, try to work out why he thinks he’s worse off.” – Nigel Short
27 | %
28 | Chess is a battle between your aversion to thinking and your aversion to losing.
29 | %
30 | A reporter once asked Spasky if he preferred chess or sex more. He replied "It very much depends on the position"
31 | %
32 | You must take your opponent into a deep dark forest where 2+2=5, and the path leading out is only wide enough for one'' - Mikhail Tal
33 | %
34 | In the game of chess, you must never let your adversary see your pieces" — Zapp Brannigan
35 | %
36 | If we hit that bullseye, the rest of the dominoes should fall like a house of cards. Checkmate. — Zapp Brannigan
37 | %
38 | You from the school of hard knocks? I'm from the college of kicking doors down!
39 | %
40 | The winner of the game is the player who makes the next-to-last mistake. - Tartakower
41 | %
42 | Chess is a struggle against one's own errors. - Tartakower
43 | %
44 | "If you can't win, make sure you don't lose" - Johan Cruijff
45 | %
46 |
--------------------------------------------------------------------------------
/quotes_gq.fortune:
--------------------------------------------------------------------------------
1 | Give a man an 0day and he'll have access for a day, teach a man to phish and he'll have access for life.
2 | %
3 | You can't fight a meme with an exploit.
4 | %
5 | Cyber warfare isn't chess, it's calvinball.
6 | %
7 | An APT is not a toolchain. You can't download your way to parity with Ft Meade.
8 | %
9 | OPSEC is a process, not a tool set
10 | %
11 | Finding the right level of paranoia is an operational challenge
12 | %
13 | 0days are offensive security by obscurity.
14 |
15 | Just as fragile for attackers as “security by obscurity” is for defenders.
16 | %
17 | “If you want to conceal something, don’t swear people to silence, tell as many alternative stories as possible.” -- SOE rule
18 | %
19 | I think the American way of cyberwar is: “it is statistically impossible to make mistakes 100% of the time, plus law of large numbers, so…”
20 |
21 | %
22 |
23 | grugq’s law is: don’t attribute to exploits what can adequately be explained by password theft.
24 |
25 | %
26 |
27 | The P in APT doesn’t stand for “Pathetic”
28 |
29 | %
30 |
31 | Relying on attacker incompetence is no way to go through life
32 |
33 | %
34 |
35 | Offensive cyber’s real strategic (ie. continuing) advantage is a "true positive" success signal. Defenders must deal with this
36 |
37 | %
38 |
39 | Only break one law at a time.
40 |
41 | %
42 |
43 | Never lie by accident.
44 |
45 | %
46 |
47 | ProTip: you’re not worth an 0day.
48 |
49 | %
50 |
51 | Fear of 0day is like being terrified of ninjas instead of cardiovascular disease.
52 |
53 | %
54 |
55 | I’m not going to advise you on how to break the law other than to suggest that you shouldn’t.
56 |
57 | %
58 |
59 | Cyber is really only effective as an offensive capability. Defence has mitigation, detection, resilience, etc...but at the end of the day, cyber is a domain that favours the offensive (of course, once on someone else's network, you're on the defensive)
60 |
61 | %
62 |
63 | Make compromises: cost more; yield less; harder to use; easier to find. Analyze them, & stay awake
64 |
65 | %
66 |
67 | Fetishising 0day means that people think once a vulnerability is public there's some sort of automagic immunity.
68 | %
69 |
70 | It's surprising how critical good phishing technique is with these APT attacks. Effective phishing is more important than 0day.
71 |
72 | %
73 |
74 | I think I understand the US strategy against Chinese APT. It’s to flood the APT with so much data they won’t have analysts to review it all.
75 |
76 | %
77 |
78 | The APT that can be named is not the real APT. The way of APT is vast and unknowable. The APT is everywhere & nowhere
79 |
80 | %
81 |
82 | APT: repeatable success, interchangeable operators of low to mediocre skill. Easy to train techniques. Consistent results.
83 |
84 | Like infantry.
85 |
86 | %
87 |
88 | Metcalfe’s Law is a bitch.
89 |
90 | %
91 |
92 | Limit the number of people involved to the bare minimum.
93 |
94 | %
95 |
96 | “The less written down, the better” or, “never say or email anything you don’t want read out in a court of law”
97 |
98 | %
99 |
100 | Never write if you can speak;
101 | Never speak if you can nod;
102 | Never nod if you can wink.
103 |
104 | -- OPSEC maxim
105 | (Martin Lomasney)
106 |
107 | %
108 |
109 | If you think, don't speak.
110 | If you speak, don't write.
111 | If you write, don't sign.
112 | If you sign, don't be surprised.
113 |
114 | -- Russian joke.
115 |
116 | %
117 |
118 | A ruse is the subtlest means of attaining one's ends
119 | - the subtle ruse, arab philosophy
120 |
121 | %
122 |
123 | winning wars without battles.
124 | - T.E. Lawrence
125 |
126 | %
127 |
128 |
--------------------------------------------------------------------------------
/moscow_rules_full2.html:
--------------------------------------------------------------------------------
1 |
The Moscow Rules
2 | 1. Assume nothing.
3 | 2. Technology will always let you down.
4 | 3. Murphy is right.
5 | 4. Never go against your gut.
6 | 5. Always listen to your gut; it is your operational antennae.
7 | 6. Everyone is potentially under opposition control.
8 | 7. Don’t look back; you are never completely alone. Use your gut.
9 | 8. Go with the flow; use the terrain.
10 | 9. Take the natural break of traffic.
11 | 10. Maintain a natural pace.
12 | 11. Establish a distinctive and dynamic profile and pattern.
13 | 12. Stay consistent over time.
14 | 13. Vary your pattern and stay within your profile.
15 | 14. Be non threatening: keep them relaxed; mesmerize!
16 | 
17 | 15. Lull them into a sense of complacency.
18 | 16. Know the opposition and their terrain intimately.
19 | 17. Build in opportunity but use it sparingly.
20 | 18. Don’t harass the opposition.
21 | 19. Make sure they can anticipate your destination.
22 | 20. Pick the time and place for action.
23 | 21. Any operation can be aborted; if it feels wrong, then it is wrong.
24 | 22. Keep your options open.
25 | 23. If your gut says to act, overwhelm their senses.
26 | 24. Use misdirection, illusion and deception.
27 | 25. Hide small operative motions in larger non threatening motions.
28 | 26. Float like a butterfly; sting like bee.
29 | 27. When free, In Obscura, immediately change direction and leave the area.
30 | 28. Break your trail and blend into the local scene.
31 | 29. Execute a surveillance detection run designed to draw them out over time.
32 | 
33 | 30. Once is an accident; twice is a coincidence; three times is an enemy action.
34 | 31. Avoid static lookouts; stay away from chokepoints where they can reacquire you.
35 | 32. Select a meeting site so you can overlook the scene.
36 | 33. Keep any asset separated from you by time and distance until it is time.
37 | 34. If the asset has surveillance, then the operation has gone bad.
38 | 35. Only approach the site when you are sure it is clean.
39 | 36. After the meeting or act is done, “close the loop” at a logical cover destination.
40 | 37. Be aware of surveillance’s time tolerance so they aren’t forced to raise an alert.
41 | 38. If an alert is issued, they must pay a price and so must you.
42 | 39. Let them believe they lost you; act innocent.
43 | 40. There is no limit to a human being’s ability to rationalize the truth.
--------------------------------------------------------------------------------
/downclimb.txt:
--------------------------------------------------------------------------------
1 | Give a man an 0day and he'll have access for a day, teach a man to phish and he'll have access for life.
2 | https://twitter.com/thegrugq/status/563964286783877121
3 | --
4 |
5 | You can get 25% off a Mandiant incident response with the code: ITWASCHINA. 100% off if you just use that code as the report.
6 | https://twitter.com/thegrugq/status/600345075562909696
7 | --
8 |
9 | Fear of 0day is like being terrified of ninjas instead of cardiovascular disease.
10 | https://twitter.com/thegrugq/status/851001030019907588
11 | --
12 |
13 | Ransomware is not about encrypting data. It is the _current_ implementation of a methodology that coerces the victim to act as an agent for the criminal (typically to acquire BTC.) Encrypting data just an implementation detail; it’s the “coerced agent” part that matters. There are infinite ways to coerce someone once you have access to their data. People will pay more to keep their secrets from their friends than to regain access to their data.
14 | https://twitter.com/thegrugq/status/933540391055273984
15 | --
16 |
17 | APT28 still going through about 2 0days a month, they don't stockpile, they burn.
18 | https://twitter.com/thegrugq/status/864274606130995201
19 | --
20 |
21 | W/ the MySpace hack, people will understand that passwords are like condoms. You aren't supposed to use them at more than one place.
22 | https://twitter.com/thegrugq/status/736492040335155200
23 | --
24 |
25 | Trust relationships are the foundations of compromise.
26 | https://twitter.com/thegrugq/status/705088675915239424
27 | --
28 |
29 | That marketing cycles around major conferences dictate when research is released tells you everything you need to know about infosec.
30 | https://twitter.com/thegrugq/status/702765131562749952
31 | --
32 |
33 | People that need their software to work in order to make money invest more into engineering than those who don't. Think about that next time you buy enterprise security software. Unless you pay only after it has stopped attacks ;)
34 | https://twitter.com/thegrugq/status/770849174589804545) on malware authors A/B testing, localizing and testing their work before deployment
35 | --
36 |
37 | An important lesson to learn is not to deploy tools before they are ready. The risk is revealing capability before you can exploit it
38 | https://twitter.com/thegrugq/status/707273816058109955
39 | --
40 |
41 | That’s pretty amazing discipline from the attackers. They discard 5 9's of infections to focus on a tiny subset. No chance that’s criminals
42 | https://twitter.com/thegrugq/status/912960298998366208) on the CCleaner hackers
43 | --
44 |
45 |
46 | when your attribution is based exclusively on forensic artifacts, you're using only adversarial controlled data
47 | https://twitter.com/thegrugq/status/548490283046797312
48 | --
49 |
50 | Drop 0day, not bombs.
51 | https://twitter.com/thegrugq/status/643844416537526272
52 | --
53 |
54 | Are there any #pwn2own winners that aren’t sponsored by massive Chinese Internet companies? It’s the equivalent of a Google team winning. No doubt the teams are skilled, but this is just marketing for the Chinese audience. 'Tencent wins hacking competition!' 'Baidu wins...' Is it time to accept that #Pwn2Own has outlived its usefulness to the community? Companies paying each other for marketing... *yawn*
55 | https://twitter.com/thegrugq/status/578467834054852609
56 | --
57 |
58 | AirCnC: It’s like AirBnB for botnets. Have a compromised host you don’t use all the time? Need a host but can’t afford the maintenance?
59 | https://twitter.com/thegrugq/status/657508423332814849
60 | --
61 |
62 | Long uptime for security. No one ever tests their exploits against browsers with a week of uptime. Heap feng shui? More like heap makeover
63 | https://twitter.com/thegrugq/status/584356859777159168
64 | --
65 |
66 | You are going to be phished long before you are going to be hit with CIA 0days. Enable 2FA and get a password manager.
67 | https://twitter.com/thegrugq/status/839471981120495616
68 | --
69 |
70 | a key signing party is basically "bring your children over to get infected with chicken pox", but for grownup's laptops
71 | https://twitter.com/thegrugq/status/831363157176184832
72 | --
73 |
74 | There are people with Tor browser 0day. This is a perennial truth. Learn to be secure even if the adversary has exploits. Because they do.
75 | https://twitter.com/thegrugq/status/720334344036818944
76 | --
77 |
78 | A great way to mitigate TAO is to not be the elected leader of a nation state, #protip
79 | https://twitter.com/thegrugq/status/692793830945337344
80 | --
81 |
82 | Journos assume we know to say 'off the record' and we assume they know not to click on 'Secret Doc.PDF.exe'
83 | https://twitter.com/thegrugq/status/654293293879070720
84 | --
85 |
86 | In none of the targeted attacks me and @CDA observed against Iranian civil society we found a 0day used. Mostly no "exploit" at all in fact. Besides the usual .scr, we see a variety of Office tricks, and embedding of PowerShell in a variety of file formats (e.g. LNK) as well as repackaging of legitimate software. [...] Surely, there's a lot of human mistakes involved, but as long as we enable e.g. executing embedded EXEs through PowerPoint animations the human mistakes seem more tolerable, and development and employment of exploits way less "profitable". Most of the tricks I observe used for infection also have the "advantage" of requiring way less situational awareness from the attacker which significantly reduces costs and improve success rate for attackers [...] In some sadistic way, I wish we'd be in a place where exploits were really required, at least it would sensibly increase costs for attacks.
87 | https://twitter.com/thegrugq/timelines/764512283099697152
88 | --
89 |
90 | less Twitter more committer! Keep coding
91 | https://twitter.com/thegrugq/status/533620917469855749
92 | --
93 |
94 | Software is eating the world. Software rots. This is a very scary thing to think about.
95 | https://twitter.com/thegrugq/status/633306726142337025
96 | --
97 |
98 | Everybody that's been breached or has security patches to release? Today is _the_ day to bury infosec news!
99 | https://twitter.com/thegrugq/status/618028615054159873) on the day of the Hacking Team hack.
100 | --
101 |
102 | New rule: if you are hacked via OWASP Top 10, you’re not allowed to call it 'advanced' or 'sophisticated.'
103 | https://twitter.com/thegrugq/status/658991205816995840
104 | --
105 |
106 | Don’t make me sudo. You wouldn’t like me when I’m root.
107 | https://twitter.com/thegrugq/status/614305448540311552
--------------------------------------------------------------------------------
/murphys_laws_of_war.md:
--------------------------------------------------------------------------------
1 | 1. Friendly fire - isn't.
2 | 1. Recoilless rifles - aren't.
3 | 1. Suppressive fires - won't.
4 | 1. You are not Superman; Marines and fighter pilots take note.
5 | 1. A sucking chest wound is Nature's way of telling you to slow down.
6 | 1. If it's stupid but it works, it isn't stupid.
7 | 1. Try to look unimportant; the enemy may be low on ammo and not want to waste a bullet on you.
8 | 1. If at first you don't succeed, call in an airstrike.
9 | 1. If you are forward of your position, your artillery will fall short.
10 | 1. Never share a foxhole with anyone braver than yourself.
11 | 1. Never go to bed with anyone crazier than yourself.
12 | 1. Never forget that your weapon was made by the lowest bidder.
13 | 1. If your attack is going really well, it's an ambush.
14 | 1. The enemy diversion you're ignoring is their main attack.
15 | 1. The enemy invariably attacks on two occasions: When they're ready or when you're not.
16 | 1. No PLAN ever survives initial contact.
17 | 1. There is no such thing as a perfect plan.
18 | 1. Five second fuzes always burn three seconds.
19 | 1. There is no such thing as an atheist in a foxhole.
20 | 1. A retreating enemy is probably just falling back and regrouping.
21 | 1. The important things are always simple; the simple are always hard.
22 | 1. The easy way is always mined.
23 | 1. Teamwork is essential; it gives the enemy other people to shoot at.
24 | 1. Don't look conspicuous; it draws fire. (For this reason, it is not at all uncommon for aircraft carriers to be known as bomb magnets.)
25 | 1. Never draw fire; it irritates everyone around you.
26 | 1. If you are short of everything but the enemy, you are in the combat zone.
27 | 1. When you have secured the area, make sure the enemy knows it too.
28 | 1. Incoming fire has the right of way.
29 | 1. No combat ready unit has ever passed inspection.
30 | 1. No inspection ready unit has ever passed combat.
31 | 1. If the enemy is within range, so are you.
32 | 1. The only thing more accurate than incoming enemy fire is incoming friendly fire.
33 | 1. Things which must be shipped together as a set, aren't.
34 | 1. Things that must work together, can't be carried to the field that way.
35 | 1. Radios will fail as soon as you need fire support. Corollary: Radar tends to fail at night and in bad weather, and especially during both.
36 | 1. Anything you do can get you killed, including nothing.
37 | 1. Make it too tough for the enemy to get in, and you won't be able to get out.
38 | 1. Tracers work both ways.
39 | 1. If you take more than your fair share of objectives, you will get more than your fair share of objectives to take.
40 | 1. When both sides are convinced they're about to lose, they're both right.
41 | 1. Professional soldiers are predictable; the world is full of dangerous amateurs.
42 | 1. Military Intelligence is a contradiction.
43 | 1. Fortify your front; you'll get your rear shot up.
44 | 1. Weather ain't neutral.
45 | 1. If you can't remember, the Claymore is pointed towards you.
46 | 1. Air defense motto: shoot 'em down; sort 'em out on the ground.
47 | 1. 'Flies high, it dies; low and slow, it'll go.
48 | 1. The Cavalry doesn't always come to the rescue.
49 | 1. Napalm is an area support weapon.
50 | 1. Mines are equal opportunity weapons.
51 | 1. B-52s are the ultimate close support weapon.
52 | 1. Sniper's motto: reach out and touch someone.
53 | 1. Killing for peace is like screwing for virginity.
54 | 1. The one item you need is always in short supply.
55 | 1. Interchangeable parts aren't.
56 | 1. It's not the one with your name on it; it's the one addressed "to whom it may concern" you've got to think about.
57 | 1. When in doubt, empty your magazine.
58 | 1. The side with the simplest uniforms wins.
59 | 1. Combat will occur on the ground between two adjoining maps.
60 | 1. If the Platoon Sergeant can see you, so can the enemy.
61 | 1. Never stand when you can sit, never sit when you can lie down, never stay awake when you can sleep.
62 | 1. The most dangerous thing in the world is a Second Lieutenant with a map and a compass.
63 | 1. Exceptions prove the rule, and destroy the battle plan.
64 | 1. Everything always works in your HQ, everything always fails in the Colonel's HQ.
65 | 1. The enemy never watches until you make a mistake.
66 | 1. One enemy soldier is never enough, but two is entirely too many.
67 | 1. A clean (and dry) set of BDU's is a magnet for mud and rain.
68 | 1. The worse the weather, the more you are required to be out in it.
69 | 1. Whenever you have plenty of ammo, you never miss. Whenever you are low on ammo, you can't hit the broad side of a barn.
70 | 1. The more a weapon costs, the farther you will have to send it away to be repaired.
71 | 1. The complexity of a weapon is inversely proportional to the IQ of the weapon's operator.
72 | 1. Field experience is something you don't get until just after you need it.
73 | 1. No matter which way you have to march, it's always uphill.
74 | 1. If enough data is collected, a board of inquiry can prove anything.
75 | 1. For every action, there is an equal and opposite criticism. (in boot camp)
76 | 1. Airstrikes always overshoot the target, artillery always falls short.
77 | 1. When reviewing the radio frequencies that you just wrote down, the most important ones are always illegible.
78 | 1. Those who hesitate under fire usually do not end up KIA or WIA.
79 | 1. The tough part about being an officer is that the troops don't know what they want, but they know for certain what they don't want.
80 | 1. To steal information from a person is called plagiarism. To steal information from the enemy is called gathering intelligence.
81 | 1. The weapon that usually jams when you need it the most is the M60.
82 | 1. The perfect officer for the job will transfer in the day after that billet is filled by someone else.
83 | 1. When you have sufficient supplies & ammo, the enemy takes 2 weeks to attack.When you are low on supplies & ammo the enemy decides to attack that night.
84 | 1. The newest and least experienced soldier will usually win the Medal of Honor.
85 | 1. A Purple Heart just proves that were you smart enough to think of a plan, stupid enough to try it, and lucky enough to survive.
86 | 1. Murphy was a grunt.
87 | 1. Beer Math -> 2 beers times 37 men equals 49 cases.
88 | 1. Body count Math -> 3 guerrillas plus 1 probable plus 2 pigs equals 37 enemies killed in action.
89 | 1. The bursting radius of a hand grenade is always one foot greater than your jumping range.
90 | 1. All-weather close air support doesn't work in bad weather.
91 | 1. The combat worth of a unit is inversely proportional to the smartness of its outfit and appearance.
92 | 1. The crucial round is a dud.
93 | 1. Every command which can be misunderstood, will be.
94 | 1. There is no such place as a convenient foxhole.
95 | 1. Don't ever be the first, don't ever be the last and don't ever volunteer to do anything.
96 | 1. If your positions are firmly set and you are prepared to take the enemy assault on, he will bypass you.
97 | 1. If your ambush is properly set, the enemy won't walk into it.
98 | 1. If your flank march is going well, the enemy expects you to outflank him.
99 | 1. Density of fire increases proportionally to the curiousness of the target.
100 | 1. Odd objects attract fire - never lurk behind one.
101 | 1. The more stupid the leader is, the more important missions he is ordered to carry out.
102 | 1. The self-importance of a superior is inversely proportional to his position in the hierarchy (as is his deviousness and mischievousness).
103 | 1. There is always a way, and it usually doesn't work.
104 | 1. Success occurs when no one is looking, failure occurs when the General is watching.
105 | 1. The enemy never monitors your radio frequency until you broadcast on an unsecured channel.
106 | 1. Whenever you drop your equipment in a fire-fight, your ammo and grenades always fall the farthest away, and your canteen always lands at your feet.
107 | 1. As soon as you are served hot chow in the field, it rains.
108 | 1. Never tell the Platoon Sergeant you have nothing to do.
109 | 1. The seriousness of a wound (in a fire-fight) is inversely proportional to the distance to any form of cover.
110 | 1. Walking point = sniper bait.
111 | 1. Your bivouac for the night is the spot where you got tired of marching that day.
112 | 1. If only one solution can be found for a field problem, then it is usually a stupid solution.
113 | 1. All or any of the above combined.
114 |
--------------------------------------------------------------------------------
/moscow_rules_full.html:
--------------------------------------------------------------------------------
1 | - Assume nothing. Commentary
2 | - Technology will always let you down. Commentary
3 | - Murphy is right. Commentary
4 | - Never go against your gut. Commentary
5 | - Always listen to your gut; it is your operational antennae. Commentary
6 | - Everyone is potentially under opposition control. Commentary
7 | - Don’t look back; you are never completely alone. Use your gut. Commentary
8 | - Go with the flow; use the terrain. Commentary
9 | - Take the natural break of traffic. Commentary
10 | - Maintain a natural pace. Commentary
11 | - Establish a distinctive and dynamic profile and pattern. Commentary
12 | - Stay consistent over time. Commentary
13 | - Vary your pattern and stay within your profile. Commentary
14 | - Be non threatening: keep them relaxed; mesmerize! Commentary
15 | - Lull them into a sense of complacency. Commentary
16 | - Know the opposition and their terrain intimately. Commentary
17 | - Build in opportunity but use it sparingly. Commentary
18 | - Don’t harass the opposition. Commentary
19 | - Make sure they can anticipate your destination. Commentary
20 | - Pick the time and place for action. Commentary
21 | - Any operation can be aborted; if it feels wrong, then it is wrong. Commentary
22 | - Keep your options open. Commentary
23 | - If your gut says to act, overwhelm their senses. Commentary
24 | - Use misdirection, illusion, and deception. Commentary
25 | - Hide small operative motions in larger non threatening motions. Commentary
26 | - Float like a butterfly; sting like bee. Commentary
27 | - When free, In Obscura, immediately change direction and leave the area. Commentary
28 | - Break your trail and blend into the local scene. Commentary
29 | - Execute a surveillance detection run designed to draw them out over time. Commentary
30 | - Once is an accident; twice is a coincidence; three times is an enemy action. Commentary
31 | - Avoid static lookouts; stay away from chokepoints where they can reacquire you. Commentary
32 | - Select a meeting site so you can overlook the scene. Commentary
33 | - Keep any asset separated from you by time and distance until it is time. Commentary
34 | - If the asset has surveillance, then the operation has gone bad. Commentary
35 | - Only approach the site when you are sure it is clean. Commentary
36 | - After the meeting or act is done, “close the loop” at a logical cover destination. Commentary
37 | - Be aware of surveillance’s time tolerance so they aren’t forced to raise an alert. Commentary
38 | - If an alert is issued, they must pay a price and so must you. Commentary
39 | - Let them believe they lost you; act innocent. Commentary
40 | - There is no limit to a human being’s ability to rationalize the truth.Commentary
41 | References[edit]
42 |
--------------------------------------------------------------------------------
/fortune.txt:
--------------------------------------------------------------------------------
1 | %
2 |
3 | Give a man an 0day and he'll have access for a day, teach a man to phish and he'll have access for life.
4 |
5 | https://twitter.com/thegrugq/status/563964286783877121
6 |
7 | %
8 |
9 | You can't fight a meme with an exploit.
10 |
11 | %
12 |
13 | Cyber warfare isn't chess, it's calvinball.
14 |
15 | %
16 |
17 | An APT is not a toolchain. You can't download your way to parity with Ft Meade.
18 | https://twitter.com/thegrugq/status/786339349847609344
19 |
20 | %
21 |
22 | Think of it like this:
23 |
24 | 0days are offensive security by obscurity.
25 |
26 | Just as fragile for attackers as “security by obscurity” is for defenders.
27 |
28 | %
29 |
30 | “If you want to conceal something, don’t swear people to silence, tell as many alternative stories as possible.” -- SOE rule
31 | https://twitter.com/thegrugq/status/1037577891150585856
32 |
33 | %
34 |
35 | I think the American way of cyberwar is: “it is statistically impossible to make mistakes 100% of the time, plus law of large numbers, so…”
36 | https://twitter.com/thegrugq/status/811330599424135169
37 |
38 | %
39 |
40 | grugq’s law is: don’t attribute to exploits what can adequately be explained by password theft.
41 |
42 | %
43 |
44 | The P in APT doesn’t stand for “Pathetic”
45 |
46 | %
47 |
48 | relying on attacker incompetence is no way to go through life
49 |
50 | %
51 |
52 | offensive cyber’s real strategic (ie. continuing) advantage is a "true positive" success signal. Defenders must deal with this
53 |
54 | %
55 |
56 | Only break one law at a time.
57 |
58 | %
59 |
60 | Never lie by accident.
61 |
62 | %
63 |
64 | ProTip: you’re not worth an 0day.
65 |
66 | %
67 |
68 | Fear of 0day is like being terrified of ninjas instead of cardiovascular disease.
69 |
70 | %
71 |
72 | I’m not going to advise you on how to break the law other than to suggest that you shouldn’t.
73 |
74 | %
75 |
76 | Cyber is really only effective as an offensive capability. Defence has mitigation, detection, resilience, etc...but at the end of the day, cyber is a domain that favours the offensive (of course, once on someone else's network, you're on the defensive)
77 |
78 | %
79 |
80 | make compromises: cost more; yield less; harder to use; easier to find. Analyze them, & stay awake
81 |
82 | %
83 |
84 | Fetishising 0day means that people think once a vulnerability is public there's some sort of automagic immunity.
85 | %
86 |
87 | It's surprising how critical good phishing technique is with these APT attacks. Effective phishing is more important than 0day.
88 |
89 | %
90 |
91 | I think I understand the US strategy against Chinese APT. It’s to flood the APT with so much data they won’t have analysts to review it all.
92 |
93 | %
94 |
95 | the APT that can be named is not the real APT. The way of APT is vast and unknowable. The APT is everywhere & nowhere
96 |
97 | %
98 |
99 | APT: repeatable success, interchangeable operators of low to mediocre skill. Easy to train techniques. Consistent results.
100 |
101 | Like infantry.
102 |
103 | %
104 |
105 | Metcalfe’s Law is a bitch.
106 |
107 | %
108 |
109 | Limit the number of people involved to the bare minimum.
110 | 11:09 PM - 4 Aug 2015
111 | https://twitter.com/thegrugq/status/628598651951054848
112 |
113 | %
114 |
115 | “The less written down, the better” or, “never say or email anything you don’t want read out in a court of law”
116 | 2:58 AM - 11 Jul 2016
117 | https://twitter.com/thegrugq/status/752230475029057536
118 |
119 | %
120 |
121 | Never write if you can speak;
122 | Never speak if you can nod;
123 | Never nod if you can wink.
124 |
125 | % OPSEC maxim
126 | (Martin Lomasney)
127 | 11:11 PM - 4 Aug 2015
128 | https://twitter.com/thegrugq/status/628599130160431105
129 |
130 | %
131 |
132 |
133 | Encryption is a law enforcement problem, not an intelligence one.
134 | 1:56 AM - 22 Jan 2016
135 | https://twitter.com/thegrugq/status/690246691232944128
136 |
137 | %
138 |
139 | OH: International law is colonialism by other means.
140 | 12:45 PM - 22 Jan 2018
141 | https://twitter.com/thegrugq/status/955315437914353664
142 |
143 | %
144 |
145 | "Only break one law at a time."
146 |
147 | "Never lie by accident."
148 |
149 | Conducting influence campaigns isn’t that hard. It doesn’t require state-spectrum investment or capabilities. All you need is a plan, an audience, time, and an achievable goal. Keep good records, never lie by accident, iterate fast, use themes for guidance.
150 | Yes. Accidental lies can totally blow your operation. Only lie when you know what and why. It must be purposeful
151 | More of a “one law at a time” thing. You want to be in control of your messaging. Lies can confuses things or completely sink the ship.
152 | A) A riot in Boston D.C. killed 7
153 | B) A riot in DC killed 7
154 |
155 | It’s clear to the target audience “A” fishy, but “B” is not self evidently wrong
156 | Similarly to one lie at a time is one operation at a time. If your hijacking TV to inject fake data don’t also try to add satirical commentary to the news caster. The two ops would get jumbled and risk exposing each other. Everything must be deliberate
157 |
158 | %
159 |
160 | Laws make criminals. Repeal more laws, you get fewer criminals, they can use the law courts to settle contractual disputes rather than violence.
161 |
162 | %
163 |
164 | snowden argues the same techy bullshit argument other geeks have: that tech can defeat law, so ignore policy
165 | it's complete bullshit. It makes geeks feel powerful while not actually doing anything useful.
166 |
167 | %
168 |
169 | They violate the primary rule of maintaining security against a nation state - don’t break the law.
170 |
171 | %
172 |
173 | until geeks realize that people execute law code and not automatons, it’s kinda messy.
174 |
175 | %
176 |
177 | “An APT is more than just a tool chain, you can’t download your way to parity with Fort Meade”
178 | https://twitter.com/thegrugq/status/1063239079284760576
179 |
180 | %
181 |
182 | Not everything is APT and not every APT is sophisticated. Focus on practicing basic IT governance — asset management, patching, network segmentation, least privilege, 2FA, logging... drop in some @ThinkstCanary. Make them work to earn their pay
183 |
184 | %
185 |
186 | Real APT: we need to read their emails and steal their spreadsheets.
187 | Fantasy APT: we need to hack their baseband…because reasons!
188 |
189 | %
190 |
191 | Hey aspirational B team APT. You guys really need to learn that mission success is about the escape and evation, not the execution.
192 |
193 | %
194 |
195 | Yeah, I’m just being stupid about bureaucracy and organizations these days. Wondering if there’s units that work to enable the dev teams (hack for certs, hack for source, hack for infrastructure) and so on. Just like an army isn’t all infantry, what elements make up an APT group?
196 |
197 | %
198 |
199 | 17 Malware Analysis Techniques That Work For Any APT Campaign.
200 | #infoseccosmo
201 |
202 | %
203 |
204 | cyber pathogen profilaxis is a common complication from APT infections.
205 |
206 | %
207 |
208 | The phrase for today is: collection bias. We see only the ops that get caught in the sector that is being monitored. The view port on APT activity is limited and skewed. Our data sets suck.
209 |
210 | %
211 |
212 | Wonder how much the style of attacks has to do with provenance. That is, pen testers mimic old school hackers, APT is repeatable success.
213 | j
214 | %
215 |
216 | Criminals and other APT groups will happily use anything that works, even if it is known.
217 |
218 | %
219 |
220 | Which APT Campaigns Are Hot This Summer!
221 |
222 | #infoseccosmo
223 |
224 | %
225 |
226 | Interestingly the North Koreans are probably the only APT that views cyberwar in the same terms as the US, but they aren’t constrained
227 |
228 | %
229 |
230 | TBF, there’s not much a civilian group can do to protect against an APT.
231 |
232 | %
233 |
234 | Does anyone except Russian crooks & pen testers still do “Step 1: hack the server“ style pen tests? The world has standardized on APT right?
235 |
236 |
237 |
238 |
239 | This is like the APT starter pack: Flash, win33k, old Java *and* old office, everything a gov contracting house runs on every workstation!
240 |
241 | %
242 |
243 | If I’m understanding this correctly, “cyber” is something you catch from a Chinese if you have unprotected APT?
244 |
245 | %
246 |
247 | in peace, prepare for apt
248 |
249 | %
250 |
251 | WTF is wrong with people? The opposition will use the cheapest most reliable tool every time they can. Yes, the GRU uses phishing (and 0day)
252 |
253 | %
254 |
255 | Russia can afford to kill the opposition’s 0day, regardless of how good, because they don’t care much about stealth or preserving exploits.
256 |
257 | %
258 |
259 | APTs use what works. But it’s kinda embarrassing if you don’t make them at least burn 0day...
260 |
261 | %
262 |
263 | Fetishising 0day leads to bizarre situations where ppl think that making more vulnerabilities known to more people reduces risk.
264 |
265 | %
266 |
267 | Yes. 0day are for hardened HVT. Like spices, you don’t want to over use them, just enough
268 |
269 | %
270 |
271 | I’ll concede it isn’t perfect or feasible in every case, but I think “decruitment” is a totally viable offensive technique in a variety of situations. It is a variant of “countering violent extremism” in a way. Provide an off ramp, throw in incentives (if possible)
272 |
273 | %
274 |
275 | actually not a stupid question.
276 |
277 |
278 |
279 | Any competent offensive cyber team is going to need to detect whether they’ve popped a compromised box. They need a simple operational tool that works and doesn’t leak intelligence about what they know regarding other teams’ tooling —because it is run on a compromised host.
280 |
281 | %
282 |
283 | Reminder to everyone: [bug bounties use] market forces to secure things by raising the cost of offensive ops, not the cost of defence.
284 |
285 | %
286 |
287 | Create infrastructure that requires only a new $5 VPS and a “rake deploy” to replicate to a new system. Offensive DevOps
288 |
289 | %
290 |
291 | APT groups operational characteristics are the result of organizational make up which is the result of politics & history.
292 |
293 | %
294 |
295 | Defender's strategic advantage is visibility at vantage points & scale unavailable & unknown to attackers. Denial of certainty of stealth. -- @dinodaizovi
296 |
297 | In addition to attacker vulnerabilities,
298 |
299 | %
300 |
301 | Modern day alchemy: turn a nothing burger wiki dump into an information operation.
302 |
303 | %
304 |
305 | Phrack, uniformed, etc are the alchemical grimoires of cyber security. Practitioners scribbling down what they knew from experiments and presenting the knowledge to their peers. They’re presented authoritatively, rich w/ arcane detail, on the path to professional discipline
306 | As an industry we still don’t know how to produce “hacker enlightenment” other than walking the old paths. Some of the Services have developed private colleges for professionalized training, but even they aren’t reliable at creating “master” hackers.
307 | Hacking is beyond the “alchemy” phase, but it’s not yet “chemistry.” Is it just gonna take more time? What would we need to bridge that gap?
308 |
309 | %
310 |
311 | cyber is calvinball. The only rule is that it’s never played the same way twice.
312 |
313 | %
314 |
315 | We're only at the Alchemy stage of security - it's not a real science yet.
316 |
317 | %
318 |
319 | If a nation state is after you, you’re going to have a bad time.
320 |
321 | %
322 |
323 | The Internet is the Wild West. We thought we were the cowboys but it turns out we're the indians. Fuck.
324 |
325 | %
326 |
327 | Learning good OPSEC requires internalizing the behavioural changes required to continually maintain a strong security posture.
328 |
329 | %
330 |
331 | Attackers are resource constrained too. -- @dinodaizovi
332 |
333 | %
334 |
335 | Attackers have bosses and budgets too. -- Phil Venables (@philvenables)
336 |
337 | %
338 |
339 | Your perimeter is not the boundary of your network but the boundary of your telemetry.
340 |
341 | %
342 |
343 | The future of CNO is the Morris Worm from 1988.
344 |
345 | %
346 |
347 | Core offensive methodologies exploit human factors. Decades of success prove they aren't going away.
348 |
349 | %
350 |
351 | [a cyber offence framework] does not cost an aircraft carrier as Aitel says, it costs a submarine.
352 |
353 | %
354 |
355 | A key signing party is basically "bring your children over to get infected with chicken pox," but for grownup's laptops.
356 |
357 | %
358 |
359 | "Happy birthday @miaubiz!" -- the birthday attack.
360 |
361 | %
362 |
363 | No one's going to jail for you.
364 |
365 | %
366 |
367 | The ultimate goal of strategem is to make the enemy quite certain, very decisive, and wrong. -- Bart Whaley
368 |
369 | %
370 |
371 | Give a man an 0day and he'll have access for a day, teach a man to phish and he'll have access for life.
372 | https://twitter.com/thegrugq/status/563964286783877121
373 |
374 | %
375 |
376 | You can get 25% off a Mandiant incident response with the code: ITWASCHINA. 100% off if you just use that code as the report.
377 | https://twitter.com/thegrugq/status/600345075562909696
378 |
379 | %
380 |
381 | Fear of 0day is like being terrified of ninjas instead of cardiovascular disease.
382 | https://twitter.com/thegrugq/status/851001030019907588
383 |
384 | %
385 |
386 | Ransomware is not about encrypting data. It is the _current_ implementation of a methodology that coerces the victim to act as an agent for the criminal (typically to acquire BTC.) Encrypting data just an implementation detail; it’s the “coerced agent” part that matters. There are infinite ways to coerce someone once you have access to their data. People will pay more to keep their secrets from their friends than to regain access to their data.
387 | https://twitter.com/thegrugq/status/933540391055273984
388 |
389 | %
390 |
391 | APT28 still going through about 2 0days a month, they don't stockpile, they burn.
392 | https://twitter.com/thegrugq/status/864274606130995201
393 |
394 | %
395 |
396 | W/ the MySpace hack, people will understand that passwords are like condoms. You aren't supposed to use them at more than one place.
397 | https://twitter.com/thegrugq/status/736492040335155200
398 |
399 | %
400 |
401 | Trust relationships are the foundations of compromise.
402 | https://twitter.com/thegrugq/status/705088675915239424
403 |
404 | %
405 |
406 | That marketing cycles around major conferences dictate when research is released tells you everything you need to know about infosec.
407 | https://twitter.com/thegrugq/status/702765131562749952
408 |
409 | %
410 |
411 | People that need their software to work in order to make money invest more into engineering than those who don't. Think about that next time you buy enterprise security software. Unless you pay only after it has stopped attacks ;)
412 | https://twitter.com/thegrugq/status/770849174589804545) on malware authors A/B testing, localizing and testing their work before deployment
413 |
414 | %
415 |
416 | An important lesson to learn is not to deploy tools before they are ready. The risk is revealing capability before you can exploit it
417 | https://twitter.com/thegrugq/status/707273816058109955
418 |
419 | %
420 |
421 | That’s pretty amazing discipline from the attackers. They discard 5 9's of infections to focus on a tiny subset. No chance that’s criminals
422 | https://twitter.com/thegrugq/status/912960298998366208) on the CCleaner hackers
423 |
424 | %
425 |
426 |
427 | when your attribution is based exclusively on forensic artifacts, you're using only adversarial controlled data
428 | https://twitter.com/thegrugq/status/548490283046797312
429 |
430 | %
431 |
432 | Drop 0day, not bombs.
433 | https://twitter.com/thegrugq/status/643844416537526272
434 |
435 | %
436 |
437 | Are there any #pwn2own winners that aren’t sponsored by massive Chinese Internet companies? It’s the equivalent of a Google team winning. No doubt the teams are skilled, but this is just marketing for the Chinese audience. 'Tencent wins hacking competition!' 'Baidu wins...' Is it time to accept that #Pwn2Own has outlived its usefulness to the community? Companies paying each other for marketing... *yawn*
438 | https://twitter.com/thegrugq/status/578467834054852609
439 |
440 | %
441 |
442 | AirCnC: It’s like AirBnB for botnets. Have a compromised host you don’t use all the time? Need a host but can’t afford the maintenance?
443 | https://twitter.com/thegrugq/status/657508423332814849
444 | %
445 |
446 | Long uptime for security. No one ever tests their exploits against browsers with a week of uptime. Heap feng shui? More like heap makeover
447 | https://twitter.com/thegrugq/status/584356859777159168
448 |
449 | %
450 |
451 | You are going to be phished long before you are going to be hit with CIA 0days. Enable 2FA and get a password manager.
452 | https://twitter.com/thegrugq/status/839471981120495616
453 |
454 | %
455 |
456 | a key signing party is basically "bring your children over to get infected with chicken pox", but for grownup's laptops
457 | https://twitter.com/thegrugq/status/831363157176184832
458 |
459 | %
460 |
461 | There are people with Tor browser 0day. This is a perennial truth. Learn to be secure even if the adversary has exploits. Because they do.
462 | https://twitter.com/thegrugq/status/720334344036818944
463 |
464 | %
465 |
466 | A great way to mitigate TAO is to not be the elected leader of a nation state, #protip
467 | https://twitter.com/thegrugq/status/692793830945337344
468 |
469 | %
470 |
471 | Journos assume we know to say 'off the record' and we assume they know not to click on 'Secret Doc.PDF.exe'
472 | https://twitter.com/thegrugq/status/654293293879070720
473 |
474 | %
475 |
476 | In none of the targeted attacks me and @CDA observed against Iranian civil society we found a 0day used. Mostly no "exploit" at all in fact. Besides the usual .scr, we see a variety of Office tricks, and embedding of PowerShell in a variety of file formats (e.g. LNK) as well as repackaging of legitimate software. [...] Surely, there's a lot of human mistakes involved, but as long as we enable e.g. executing embedded EXEs through PowerPoint animations the human mistakes seem more tolerable, and development and employment of exploits way less "profitable". Most of the tricks I observe used for infection also have the "advantage" of requiring way less situational awareness from the attacker which significantly reduces costs and improve success rate for attackers [...] In some sadistic way, I wish we'd be in a place where exploits were really required, at least it would sensibly increase costs for attacks.
477 | https://twitter.com/thegrugq/timelines/764512283099697152
478 |
479 | %
480 |
481 | less Twitter more committer! Keep coding
482 | https://twitter.com/thegrugq/status/533620917469855749
483 |
484 | %
485 |
486 | Software is eating the world. Software rots. This is a very scary thing to think about.
487 | https://twitter.com/thegrugq/status/633306726142337025
488 |
489 | %
490 |
491 | Everybody that's been breached or has security patches to release? Today is _the_ day to bury infosec news!
492 | https://twitter.com/thegrugq/status/618028615054159873) on the day of the Hacking Team hack.
493 |
494 | %
495 |
496 | New rule: if you are hacked via OWASP Top 10, you’re not allowed to call it 'advanced' or 'sophisticated.'
497 | https://twitter.com/thegrugq/status/658991205816995840
498 |
499 | %
500 |
501 | Don’t make me sudo. You wouldn’t like me when I’m root.
502 | https://twitter.com/thegrugq/status/614305448540311552
503 |
504 | %
505 |
506 | The Russians are playing chess and the Americans are playing “how far does this crayon go up my nose?”
507 | https://twitter.com/thegrugq/status/766337166406393856
508 |
509 | %
510 |
511 | “The more security, the more bizarre the method of escape must be.”
512 | -- Forrest Tucker, bank robber, stickup man, prison escape artist
513 |
514 | %
515 |
--------------------------------------------------------------------------------
/murphys_laws_of_combat.md:
--------------------------------------------------------------------------------
1 |
2 | - Friendly fire - isn't.
3 | - Recoilless rifles - aren't.
4 | - Suppressive fires - won't.
5 | - You are not Superman; Marines and fighter pilots take note.
6 | - A sucking chest wound is Nature's way of telling you to slow down.
7 | - If it's stupid but it works, it isn't stupid.
8 | - Try to look unimportant; the enemy may be low on ammo and not want to waste a bullet on you.
9 | - If at first you don't succeed, call in an air strike.
10 | - If you are forward of your position, your artillery will fall short.
11 | - Never share a foxhole with anyone braver than yourself.
12 | - Never go to bed with anyone crazier than yourself.
13 | - Never forget that your weapon was made by the lowest bidder.
14 | - If your attack is going really well, it's an ambush.
15 | - The enemy diversion you're ignoring is their main attack.
16 | - The enemy invariably attacks on two occasions:
17 | when they're ready.
18 | when you're not.
19 | - No OPLAN ever survives initial contact.
20 | - There is no such thing as a perfect plan.
21 | - Five second fuses always burn three seconds.
22 | - There is no such thing as an atheist in a foxhole.
23 | - A retreating enemy is probably just falling back and regrouping.
24 | The Ol' Ranger's addendum:
25 | Or else they're trying to suck you into a serious ambush!
26 | - The important things are always simple; the simple are always hard.
27 | - The easy way is always mined.
28 | - Teamwork is essential; it gives the enemy other people to shoot at.
29 | - Don't look conspicuous; it draws fire. For this reason, it is not at all uncommon for aircraft carriers to be known as bomb magnets.
30 | - Never draw fire; it irritates everyone around you.
31 | - If you are short of everything but the enemy, you are in the combat zone.
32 | - When you have secured the area, make sure the enemy knows it too.
33 | - Incoming fire has the right of way.
34 | - No combat ready unit has ever passed inspection.
35 | - No inspection ready unit has ever passed combat.
36 | - If the enemy is within range, so are you.
37 | - The only thing more accurate than incoming enemy fire is incoming friendly fire.
38 | - Things which must be shipped together as a set, aren't.
39 | - Things that must work together, can't be carried to the field that way.
40 | - Radios will fail as soon as you need fire support.
41 | - Radar tends to fail at night and in bad weather, and especially during both.)
42 | - Anything you do can get you killed, including nothing.
43 | - Make it too tough for the enemy to get in, and you won't be able to get out.
44 | - Tracers work both ways.
45 | - If you take more than your fair share of objectives, you will get more than your fair share of objectives to take.
46 | - When both sides are convinced they're about to lose, they're both right.
47 | - Professional soldiers are predictable; the world is full of dangerous amateurs.
48 | - Military Intelligence is a contradiction.
49 | - Fortify your front; you'll get your rear shot up.
50 | - Weather ain't neutral.
51 | - If you can't remember, the Claymore is pointed toward you.
52 | - Air defense motto: shoot 'em down; sort 'em out on the ground.
53 | - 'Flies high, it dies; low and slow, it'll go.
54 | - The Cavalry doesn't always come to the rescue.
55 | - Napalm is an area support weapon.
56 | - Mines are equal opportunity weapons.
57 | - B-52s are the ultimate close support weapon.
58 | - Sniper's motto: reach out and touch someone.
59 | - Killing for peace is like screwing for virginity.
60 | - The one item you need is always in short supply.
61 | - Interchangeable parts aren't.
62 | - It's not the one with your name on it; it's the one addressed "to whom it may concern" you've got to think about.
63 | - When in doubt, empty your magazine.
64 | - The side with the simplest uniforms wins.
65 | - Combat will occur on the ground between two adjoining maps.
66 | - If the Platoon Sergeant can see you, so can the enemy.
67 | - Never stand when you can sit, never sit when you can lie down, never stay awake when you can sleep.
68 | - The most dangerous thing in the world is a Second Lieutenant with a map and a compass.
69 | - Exceptions prove the rule, and destroy the battle plan.
70 | - Everything always works in your HQ, everything always fails in the Colonel's HQ.
71 | - The enemy never watches until you make a mistake.
72 | - One enemy soldier is never enough, but two is entirely too many.
73 | - A clean (and dry) set of BDU's is a magnet for mud and rain.
74 | - The worse the weather, the more you are required to be out in it.
75 | - Whenever you have plenty of ammo, you never miss. Whenever you are low on ammo, you can't hit the broad side of a barn.
76 | - The more a weapon costs, the farther you will have to send it away to be repaired.
77 | - The complexity of a weapon is inversely proportional to the IQ of the weapon's operator.
78 | - Field experience is something you don't get until just after you need it.
79 | - No matter which way you have to march, its always uphill.
80 | - If enough data is collected, a board of inquiry can prove anything.
81 | - For every action, there is an equal and opposite criticism. (in boot camp)
82 | - Air strikes always overshoot the target, artillery always falls short.
83 | - When reviewing the radio frequencies that you just wrote down, the most important ones are always illegible.
84 | - Those who hesitate under fire usually do not end up KIA or WIA.
85 | - The tough part about being an officer is that the troops don't know what they want, but they know for certain what they don't want.
86 | - To steal information from a person is called plagiarism. To steal information from the enemy is called gathering intelligence.
87 | - The weapon that usually jams when you need it the most is the M60.
88 | - The perfect officer for the job will transfer in the day after that billet is filled by someone else.
89 | - When you have sufficient supplies & ammo, the enemy takes 2 weeks to attack. When you are low on supplies & ammo the enemy decides to attack that night.
90 | - The newest and least experienced soldier will usually win the Medal of Honor.
91 | - A Purple Heart just proves that were you smart enough to think of a plan, stupid enough to try it, and lucky enough to survive.
92 | - Murphy was a grunt.
93 | - Beer Math: 2 beers times 37 men equals 49 cases.
94 | - Body count Math: 3 guerrillas plus 1 probable plus 2 pigs equals 37 enemies killed in action.
95 | - The bursting radius of a hand grenade is always one foot greater than your jumping range.
96 | - All-weather close air support doesn't work in bad weather.
97 | - The combat worth of a unit is inversely proportional to the smartness of its outfit and appearance.
98 | - The crucial round is a dud.
99 | - Every command which can be misunderstood, will be.
100 | - There is no such place as a convenient foxhole.
101 | - Don't ever be the first, don't ever be the last and don't ever volunteer to do anything.
102 | - If your positions are firmly set and you are prepared to take the enemy assault on, he will bypass you.
103 | - If your ambush is properly set, the enemy won't walk into it.
104 | - If your flank march is going well, the enemy expects you to outflank him.
105 | - Density of fire increases proportionally to the curiousness of the target.
106 | - Odd objects attract fire - never lurk behind one.
107 | - The more stupid the leader is, the more important missions he is ordered to carry out.
108 | - The self-importance of a superior is inversely proportional to his position in the hierarchy (as is his deviousness and mischievousness).
109 | - There is always a way, and it usually doesn't work.
110 | - Success occurs when no one is looking, failure occurs when the General is watching.
111 | - The enemy never monitors your radio frequency until you broadcast on an unsecured channel.
112 | - Whenever you drop your equipment in a fire-fight, your ammo and grenades always fall the farthest away, and your canteen always lands at your feet.
113 | - As soon as you are served hot chow in the field, it rains.
114 | - Never tell the Platoon Sergeant you have nothing to do.
115 | - The seriousness of a wound (in a fire-fight) is inversely proportional to the distance to any form of cover.
116 | - Walking point = sniper bait.
117 | - Your bivouac for the night is the spot where you got tired of marching that day.
118 | - If only one solution can be found for a field problem, then it is usually a stupid solution.
119 | - No battle plan ever survives contact with the enemy.
120 | - The most dangerous thing in the combat zone is an officer with a map.
121 | - The problem with taking the easy way out is that the enemy has already mined it.
122 | - The buddy system is essential to your survival; it gives the enemy somebody else to shoot at.
123 | - If your advance is going well, you are walking into an ambush.
124 | - The quartermaster has only two sizes, too large and too small.
125 | - If you really need an officer in a hurry, take a nap.
126 | - The only time suppressive fire works is when it is used on abandoned positions.
127 | - There is nothing more satisfying that having someone take a shot at you, and miss.
128 | - Don't be conspicuous. In the combat zone, it draws fire. Out of the combat zone, it draws sergeants.
129 | - If see you, so can the enemy.
130 | - All or any of the above combined.
131 | - Avoid loud noises, there are few silent killers in a combat zone.
132 | - Never screw over a buddy; you'll never know when he could save your life.
133 | - Never expect any rations; the only rations that will be on time and won't be short is the ration ofshit.
134 | - Respect all religions in a combat zone, take no chances on where you may go if killed.
135 | - A half filled canteens a beacon for a full loaded enemy weapon.
136 | - When in a fire fight, kill as many as you can, the one you miss may not miss tomorrow.
137 | The last six laws were sent by Hank Samples. A Viet Nam combat veteran (70-72) 11th ACR-101st Abn.
138 | - It is a physical impossibility to carry too much ammo.
139 | Sent by - Baseka@aol.com
140 | - If you survive an ambush, something's wrong.
141 | Sent by - CPL Nagel
142 | - Some General last words (as his aides tried to get him to get his head down):
143 | "What! what! men, dodging this way for single bullets! What will you do when they open fire along the whole line? I am ashamed of you. They couldn't hit an elephant at this dist..."
144 | Sent by Yael Dragwyla
145 | The General was General John Sedgwick, said on May 9, 1864 at the Battle of Spotsylvania.
146 | Sent by Mike Gottert
147 | - If you can see the flashes from the enemies' guns in battle, he can see yours too.
148 | - Flashlights, lighters and matches don't just illuminate the surrounding area; they illuminate you too.
149 | - Just because you have nearly impenetrable body armor and a hard-ass Kevlar helmet, doesn't mean you don't have exposed areas.
150 | - There are few times when the enemy can't hear you: When he's dead, you're dead, or both.
151 | Addendum: When he's not there, when you're not there, or both.
152 | - Never cover a dead body with your own in hopes of looking like you're one of the casualties.
153 | Even using his cadaver is a stretch to avoid being shot "just in case."
154 | - You're only better than your enemy if you kill him first.
155 | The last seven laws were sent by Charlie.
156 | - Complain about the rations all you want, but just remember; they could very well be your last meal.
157 | - Never underestimate the ability of the brass to foul things up.
158 | - You have two mortal enemies in combat; the opposing side and your own rear services.
159 | - You think the enemy has better artillery support and the enemy
160 | thinks yours is better; you're both right.
161 | - Three things you will never see in combat; hot chow, hot showers, and an uninterrupted night's sleep.
162 | - "Live" and "Hero" are mutually exclusive terms.
163 | The last six laws were sent by Donald J. Cheek, CPT, US Army (Ret) - Gulf War vet.
164 | - Don't be a hero
165 | Sent by Bo Zhang
166 | - Once you are in the fight it is way too late to wonder if this is a good idea.
167 | - NEVER get into a fight without more ammunition that the other guy.
168 | - Cover your Buddy, so he can be around to cover for you.
169 | - Decisions made by someone over your head will seldom be in your best interest.
170 | - Sometimes, being good and lucky still is not enough.
171 | - If the rear echelon troops are really happy, the front line troops probably do not have what they need.
172 | - If you are wearing body armor they will probably miss that part.
173 | - Happiness is a belt fed weapon.
174 | - Having all your body parts intact and functioning at the end of the day beats the alternative...
175 | - If you are allergic to lead it is best to avoid a war zone.
176 | - Hot garrison chow is better than hot C-rations which, in turn, are better than cold C-rations, which are better than no food at all. All of these, however, are preferable to cold rice balls even if they do have little pieces of fish in them.
177 | - A free fire zone has nothing to do with economics.
178 | - Medals are OK, but having your body and all your friends in one piece at the end of the day is better.
179 | - Being shot hurts.
180 | - Thousands of Veterans earned medals for bravery every day. A few were even awarded.
181 | - There is only one rule in war: When you win, you get to make up the rules.
182 | - C-4 can make a dull day fun.
183 | - There is no such thing as a fair fight -- only ones where you win or lose.
184 | - If you win the battle you are entitled to the spoils. If you lose you don't care.
185 | - Nobody cares what you did yesterday or what you are going to do tomorrow. What is important is what you are doing -- NOW -- to solve our problem.
186 | - Always make sure someone has a can opener.
187 | - Prayer may not help . . . but it can't hurt.
188 | - Flying is better than walking. Walking is better than running. Running is better than crawling. All of these, however, are better than extraction by a Med-Evac even if it is, technically, a form of flying.
189 | - If everyone does not come home none of the rest of us can ever fully come home either.
190 | - Carrying any weapon that you weren't issued (e.g, an AK) in combat is Not A Good Idea!
191 | A combat vet will know the sound of an unfamiliar weapon in an instant and will point and shoot.
192 | Not only that, AKs use green tracers which mean "shoot 'em all and let God sort them out".
193 | As has been noted, "Friendly fire isn't!"
194 | The last 25 laws were sent by Jim
195 | - When the going gets tough, the tough go cyclic.
196 | Sent by SPC Chris
197 | - Military Intelligence is not a contradiction in terms, "Light Infantry" is!
198 | Sent by CPT Sean M. Murphy, FA, USA
199 | - Proximity factor: The need for relief is directly related to the distance of the relief station.
200 | Sent by Joe Garcia
201 | - Always keep one bullet in the chamber when changing your magazine.
202 | Sent by J.E.S.
203 | - In peacetime people say, "War is Hell". In combat, under fire from artillery, airplanes, or whatever, a soldier thinks, "War is really really really LOUD as Hell!!!".
204 | - f you can think clearly, know exactly what's happening, and have total control of a situation in combat, then you're not in combat.
205 | - When you get the coveted 1,000 yard stare, don't forget about the enemy who is 30 yards away and about to pop your ass.
206 | - Stay away from officers in combat, they're clever decoys for noncoms.
207 | - If you think you don't need something for your combat load for an OP PLAN, you'll probably wish you had it after the shit hits the fan in combat.
208 | - Hope for the best, but prepare for the worst.
209 | The last six laws were sent by Michael Desai
210 | - Failure of plan A will directly affect your ability to carry out plan B.
211 | Sent by Lenny Quites
212 | - If you drop a soldier in the middle of a desert with a rock, a hammer, and an anvil, tell him not to touch any of it, and come back two hours later, the anvil will be broken. "Because soldiers gotta fuck with shit". (quoted from an Officer during an interview in which the Officer was asked why barrels were thickened on the M-16A2).
213 | Sent by Darrell A. Pierce
214 | - War does not determine who is right, war determines who is left.
215 | Sent by Quenya. Aus. (didn't know there were Elves in Australia, didn't know that elves were interested in war).
216 | - Lackland's Laws:
217 |
218 | - Never be first.
219 | - Never be last.
220 | - Never volunteer for anythin
221 |
222 |
223 | - An escaping soldier can be used again.
224 | Sent by Asier Zabarte
225 | - If you think you'll die, don't worry you won't.
226 | - Near death, but still a live? There is nothing wrong with physics. God doesn't like you.
227 | - It is better to be lucky than good in the battlefield.
228 | Sent by Rob
229 | - If it's worth fighting for...it's worth fighting dirty for.
230 | Sent by former Lt. C. Harper (Vietnam '65)
231 | - if god wanted boots to be comfortable he would have designed them like running shoes.
232 | Sent by Pv1 Goetze
233 | - If you survive the extraordinary things, it will often be the little things that will kill you.
234 | - Give an order, then change the order, will get you disorder.
235 | Sent by Samuel
236 | - You never have fire support in heavy firefight but you always have it on a silent recon mission
237 | Sent by Roswell
238 | - Revision to Marine Corp. Motto "If it makes sense, we won't do it".
239 | Sent by Larry Wotring
240 | - The only thing more dangerous to you than the enemy, is your allies
241 | Sent by Marc Underwood
242 | - Night vision - isn't
243 | Sent by truga
244 | - When you need CAS, they'll be on last weeks radio fill and you won't be able to reach them
245 | - When you need Apache's, they'll be busy escorting the generals bird around
246 | Last two laws were sent by Warpig, saying they are "A couple of additions to the law I picked up in Afghanistan".
247 | - Supply & Demand law
248 | Whatever you have, you won't need; whatever you need, you won't have.
249 | - Leadership law
250 | If it was risky, it worked and no one got hurt: you were brilliant
251 | If it was risky, it worked and someone got hurt; you were courageous
252 | If it was risky, it didn't work and no one got hurt; you were lucky
253 | If it was risky, it didn't work and someone got hurt; you were stupid (and probably dead)
254 | Last two laws were sent by Sylvia Steward
255 | - The best sniper position is always the hardest to reach
256 | - Snakes aren't neutral
257 | - When you need to use the bathroom - the enemy is watching your position
258 | Last three laws were sent by Mitchell Jones, Law Enforcement Precision Marksman, Arkansas
259 | - Never trust a private that says "don't worry I learned this is in basic".
260 | - When your warrant starts to laugh and says "watch this" LEAVE.
261 | - Bring extra rations when you hear the lieutenant is leading the recce patrol.
262 | - Everything you packed for the field is everything you don't need, and everything you need is at your FOB.
263 | - Be prepared to go defensive when your vehicle breaks down until support arrives.
264 | - Your vehicle is a civilian car painted tan, with less security features.
265 | Last 7 laws were sent by Dane Prosper
266 |
267 | Laws of War for Helicopters
268 |
269 | - Helicopter tail rotors are naturally drawn toward trees, stumps, rocks, etc.
270 | While it may be possible to ward off this event some of the time, it cannot, despite the best efforts of the crew, always be prevented.
271 | It's just what they do.
272 | - The engine RPM and the rotor RPM must BOTH be kept in the GREEN.
273 | Failure to heed this commandment can adversely affect the morale of the crew.
274 | - The terms Protective Armor and Helicopter are mutually exclusive.
275 | - "Chicken Plates" are not something you order in a restaurant.
276 | - The BSR (Bang Stare Red) Law:
277 | The louder the sudden bang in the helicopter, the quicker your eyes will be drawn to the gauges.
278 | Corollary: The longer you stare at the gauges the less time it takes them to move from green to red.
279 | - Loud, sudden noises in a helicopter WILL get your undivided attention.
280 | - The further you fly into the mountains, the louder the strange engine noises become.
281 | - It is a bad thing to run out of airspeed, altitude and ideas all at the same time.
282 | - "Pucker Factor" is the formal name of the equation that states the more hairy the situation is, the more of the seat cushion will be sucked up your butt.
283 | It can be expressed in its mathematical formula of:
284 | S (suction) + H (height above ground) + I (interest in staying alive) + T (# of tracers coming your way).
285 | Thus the term 'SHIT!' can also be used to denote a situation where a high Pucker Factor is being encountered.
286 | - Running out of pedal, fore or aft cyclic, or collective are all bad ideas.
287 | Any combination of these can be deadly.
288 | All the Laws of War for Helicopters were sent by Jim Kirk with courtesy of CWO4 Larry Gilbert (Ret). his brother-in-law that sent them to him
289 | - Helicopters have been described as nothing more than 50,000 parts flying in close formation. It is the mechanics responsibility to keep that formation as tight as possible.
290 | - It is mathematically impossible for either hummingbirds, or helicopters to fly. Fortunately, neither are aware of this.
291 | The last two laws were sent by Darrell A. Pierce
292 | - LZ's are always hot.
293 | Sent by loony39478@yahoo.com
294 | - There are 'old' pilots and 'bold' pilots, but there are no 'old, bold' pilots.
295 | - Any helicopter pilot story that starts "There I was,...." will be either true or false.
296 | Any of these stories that end with "No shit." was neither true nor false.
297 | - The mark of a truly superior pilot is the use of his superior judgment to avoid situations requiring the use of his superior skill
298 | The last three laws were sent by Brad Lucas,
299 | CPT, AV USA Ret, and a 1st Gulf War Vet.
300 | - Ch-53's are living proof, that if you strap enough engines to something it will fly.
301 | Sent by Jason Koeck
302 |
303 | Laws of War for Tanks
304 |
305 | - The same gun tube that would probably stay in alignment after lifting a car, will get you beaten after calibration if used to assist in climbing on the tank.
306 | - Tanks draw fire. A lot of it. It does not behoove the infantryman to hide behind one.
307 | - If you're close enough to actually hear an M1 series tank running, while in combat, and not part of the crew, you're too close.
308 | Laws of war for tanks were sent by Darrell A. Pierce
309 |
310 | Laws of the Marine Corp
311 |
312 | - It never rains in the Marine Corp, it rains on the Marine Corp.
313 | Sent by Jesse Cason
314 |
315 | Law of Fighting Airplanes
316 |
317 | - The enemy is always has the advantage.
318 | - Heat-seeking missiles don't know the difference between friend and foe.
319 | - 'Armor' is a fantasy invented by your C.O. to make you feel better.
320 | - Afterburners aren't.
321 | - Air Brakes don't.
322 | - Your cannon will jam in combat, and then when you get back to base there will be nothing wrong with it.
323 | - You may have the better plane, but the enemy is the better pilot. (or vise versa)
324 | - When getting spare parts for your aircraft, you can get them CHEAP - FAST - IN GOOD CONDITION,
325 | pick two. (This applies to everything)
326 | - Your radar will not pick up the enemy behind you or the one in the sun.
327 | - If you have got into the sun and are about to ambush the enemy, it will either be a trap or you'll run out of fuel.
328 | Law of Fighting Airplanes were sent by Luke
329 |
330 | Saddam's First (and last) Law of War:
331 |
332 | - Don't pick a fight with the baddest guys on the block!
333 | Sent by Jim Kirk
334 |
335 | Laws of Desert Combat:
336 |
337 | - Any attempt to find cover will result in failure.
338 | - Supply Shipments at night stick out like a sore thumb.
339 | - Tanks should never leave the established roads
340 | - Established roads are always mined
341 | - Operations in daytime will cause the lesser equipped army to win
342 | - The effectiveness of a soldier in desert combat is inversely porportional to how heavy his equipment is
343 | - Have plenty of water on hand
344 | The last 7 laws were sent by Fenix
345 |
346 | Laws of War in Iraq:
347 |
348 | - If it makes sense, it is not the "Army Way"
349 | - Saddam's First (and last) Law of War:
350 | Don't pick a fight with the baddest guys on the block.
351 | If you do, don't even try to run or hide. The pain will be worse.
352 | - The Iraqis always know the area better than you, no matter how many dismounts or convoys you have been on.
353 | - Iraqis always have the advantage of blending in with the crowd. You do not.
354 | - Iraqis are used to the heat and will rarely, if ever, be out during the hottest part of the day.
355 | - Drink more water than you think that you will need.
356 | - Drink more water than you think that you will need.
357 | - Always keep your radio fill up to date.
358 | - Don't piss off the IP's that run the check points, they sometimes allow insurgents to place IED's near their location just to fuck with you.
359 | - Be nice to the Iraqi children, they will soon be either IP's, IA's, or insurgents!
360 | - Always remember: Shoot first and then swear up and down that you saw them pull out a grenade. This always works!!!
361 | - IED's will be placed frequently in the same spots over and over again.
362 | - Always shoot the guy walking down the MSR in the middle of the night carrying a gas can and a shovel. If they can't place the IED's, they can't blow you up!
363 | Last 13 laws were sent by Thomas Anderson, M SPC MIL USA USAREUR
364 | - Military restatement of Uffelman's Razor:
365 | Never attribute to an Officer that which is adequately explained by a Private.
366 | From SFC Raines
367 | - Anderson's first Law:
368 | If at first you don't succeed, blame it on the new private!
369 | If at first you don't succeed, redefine success.
370 | From SPC Coffee
371 | - Law of Murphic Relief:
372 | If, throughout your entire life you have been ruled by Murphy's Law, then at least one thing, usually no more than that, will go so right as to make up for a lifetime of failures.
373 | From My Wife Rita!! Happily married now for 5 years!!
374 | - Murphy's Law is proof that God is in Heaven laughing his butt off!!
375 | From SGT Overson
376 |
--------------------------------------------------------------------------------