Thats dumb. Sometimes hackers pretend they are trying to find security flaws but they find these deliberately through malicious activities. In this case it was so quick and harmless that he should not be held responsible.
Last year my brother's company bought a piece of software which a major website also happened to own. For the hell of it he logged into their site with the default password and it worked. He alerted them immediately and received a t-shirt!
Stuff like this wouldn't happen if people actually understood the technology.
Yup. I have no sympathy for hackers who claim they were just trying to find out security flaws - after already downloading 500 visa numbers or defacing a website. Thats just a horses*it argument and those people should burn. This guy, however, did exactly what I think any one of us would have done. A very minor and simple test & then he quickly alerted the people who own the site.