1. Request a reset for your own account and inspect your token β it's md5(username + counter) and the counter is a small, visible sequence. Why: tokens built from predictable inputs can be recomputed by an attacker.
2. Compute the admin's token with the same formula (the page reveals the current counter). Run solve.py to derive it.
3. Submit it to /reset?user=admin&token=... to set a new admin password, then log in β the flag is shown.
Lesson: reset tokens must be long, random (CSPRNG), single-use, and expiring.