La Presse's news, McDonald's job offers' website has been hacked: www.lapresse.ca/techno/actualites/201703/31/01-5084192-le-site-dembauche-de-mcdonalds-canada-pirate.php
From Windows XP to lastest Windows 10 affected by the DoubleAgent vulnerability allowing to inject custom DLL into applications even antiviruses: see the full article on The Hacker News and also a link to the Youtube demo:
A pretty big flaw has been release under CVE-2016-5195 that allows a privilege escalation attack in the Linux Kernel that has been there since 2007. The conditions are almost impossible to reach in normal operations but some programs have been released to force those conditions by using two threads.
To reproduce it:
1. Download the dirtyc0w.c file from https://github.com/dirtycow/dirtycow.github.io
2. Compile it using gcc for example:
gcc -pthread dirtyc0w.c -o dirtyc0w
3. Use it as follow:
./dirtyc0w <file_to_modify> <new_file_content>
4. Obviously, thanks to Dirty Cow, the <file_to_modify> can be a file on which the user does not have permission to modify, including root files !
The flaw works by writing to memory the new content so you cannot write content longer than the original size. If you attempt to write "123456" to a file containing "456", it will write "123".