1. Open access.log and filter by status. One IP generates many 401s against /login (brute force), then a single 200. Why: a burst of failures followed by a success is a classic account-takeover signature.
2. Right after, the same IP hits /admin?cmd=... with a 200. The cmd parameter value is base64 that decodes to the flag (page decoder provided).
Lesson: triage by source IP + status-code patterns; pivot on the anomaly.