First two parts of the flag can be found on the HTML and CSS source file. The third part can be found on robots.txt. No problems with this.

In robots.txt it mentions that the server the web is running on is Apache, which can be verified by sending a simple HTTP request. This strongly hints at accessing .htaccess file, which is the common Apache config file. It reveals how the backend of a website is structured, internal IP addresses, and convieniently our fourth part of the flag.

Containing .htaccess also reveals that the developer used a Mac during development. This leads us to try accessing .DS_STORE, which is a Mac artifact that is automatically created when you open a folder and keeps track of how you like to view that specific folder (icon size, background color). If left public, we can parse the file and map out the directory, file structure, hidden files, and of course the final part of our flag. Learnt quite a bit from this problem.