I noticed something screwy happening with my pfSense late at night and after some mucking around I found this in my DHCP leases:
IP address MAC address Hostname Start End Online Lease Type
192.168.2.6 00:ab:00:00:00:00 2012/04/03 03:07:33 1969/12/31 17:00:00 offline active
I tried looking this up in System Logs but the GUI only lets me see maximum 2000 entries, and it seems that the DHCP portion was wiped after I rebooted the system. I have accounted for all the DHCP leases, except for this one, and as you can see it is quite unusual.
Can this mean that someone cracked my WPA2 encryption and is using my WIFI with this spoofed MAC address?