Yeah, I have been doing this with a naive firewall rule blocking its IP from egress, but how long until they'll wise up to it and start truly nefarious shit like using hidden MACs to acquire multiple addresses in the background? Then you could probably VLAN it off, but most people don't have managed gear on their networks.