Upon opening up robots.txt, we are greeted with this:

User-agent *
Disallow: /cgi-bin/
Think you have seen your flag or want to keep looking.

ZmxhZzEudHh0;anMvbXlmaW
anMvbXlmaWxlLnR4dA==
svssshjweuiwl;oiho.bsvdaslejg
Disallow: /wp-admin/

Access either /cgi-bin or /wp-admin will result in 404, so clearly it isn’t the way.

Instead, the 6th line anMvbXlmaWxlLnR4dA== has two trailing equal signs, hinting at base64 encoding.

echo "SGVsbG8gV29ybGQ=" | base64 -d

Upon decoding that line, we will get js/myfile.txt which is where our flag is. Quite fun problem.