Firstly, it’s good practice to purposely input trash values into the form. In this case we will be trying ' for username We can see that the users are kept in a SQLite3 database, and all our input are passed into the query without validation.

Thus we try the good old payload ' OR 1=1--, which will bypass the password check and we will get our flag