So the hint is very obvious :)
.bak uesd to be the postfix of backup file.
Download this backup file and the flag is hidden in source code.