Also, keep in mind this is for you to setup however you want. You might make the "flag" data in a DB that you have to use SQL-injection to acquire, or it may be an encrypted file that you need to get the key for. You might want to make people jump through a few hoops first. Maybe you need to crack an account before you can gain access to the DB. Be creative.
P.S. Sorry, me again
