The why is usually ease. Its running ASP which immediately suggests the server is running Windows/IIS and they may have either an unpatched or open exploit on the box.
I'm sure if he could have hacked CNN he would have, but he went for something that was likely easy to exploit after interrogating the box and getting a port scan and version of the applications on it.