>smart enough to not let one of those networks gobble up > 1 address //
If you spoof your MAC then how would they know to only give one address?
From the OP:
>"Depending on the server's method of releasing IP addresses associated with a given MAC address this attack will either be more, or less effective. For example, if a server quickly releases allocations that it doesn't receive responses from, the attack will be less effective."
Why not respond to the responses on all those MACs then, surely in promiscuous mode you could send responses (and even fake a little traffic) for each MAC used. My home router is preconfigured to allow only 253 connections (lease time 1 day) - seems you could easily mess with SOHO routers with this?