1. The user is admin. There is no lockout, so try each password in wordlist.txt against POST /login. Why: without rate-limiting or lockout, an attacker can try unlimited guesses; a weak password falls quickly.
2. The correct password is letmein. Run solve.py to automate, then log in.
3. The dashboard shows the flag after a successful login.
Lesson: enforce lockouts/rate-limits, MFA, and strong password policies.