Coding flaw leaves Zeus admin panels easily exploited

A flaw in the Zeus Trojan's admin panel leaves the C&C (command and control) server vulnerable to remote compromise. The flaw, which is located in an array function used by the malware's core code, fails to prevent malicious files from being uploaded.
Ironic isn't it?
It isn't shocking to see criminals making the same mistakes as commercial developers. That such a thing happens only confirms the fact that humans will always be the weakest link in the security chain. Websense has published a brief report on vulnerable admin panel. The problem, which is an upload function that uses a limited blacklist in an array, has been known publicly since 2011, shortly after the Zeus source code was stolen and leaked to the Web.