A few months ago our local LAN guy came into the office wondering if we had a way to shut down traffic to a particular computer in one of our other offices, based on IP address (since we handle routing and network support for commercial customers). We had to tease the info out of him.
Somebody in the other office was downloading porn to his workstation and randomly printing it out to the printers around the entire building. The IT staff had no way to shut him down or locate him because he'd blocked out the monitoring/control software on the workstation (probably by just unsharing the hard drive, the IT staff isn't extremely sophisticated).
Problem is that the entire building is behind a firewall, which we had no control over, and we couldn't just block traffic to the one computer.
After everybody spent 10 minutes trying to figure out how to locate him and block his IP, I had the insight to do a DNS query on his IP. Thanks to our wonderful internal network, the results specified which exact computer it was coming from (each computer name is unique and is assigned to the IP used by that computer when the DHCP server assigns it).
We never found out what happened to him.
Oh, and one of my roommates filled up a hard drive with porn and then backed it up to CD's after he realized he was reaching the limits of a 32bit file system. He had something on the order of 32000 pictures. Windows Explorer wouldn't even display the entire file list at one point, and when it did it would crash often. He used up a large number of CD's backing them up, but I can't remember how many. At least 5, maybe up to 20.