A self-hosted control plane for fleet-deployed VStarcam CB75 4G cameras — built bottom-up by reverse-engineering the Eye4 stack so every frame and motion alert lands on infrastructure you own. No Aliyun. No vendor cloud. Court-admissible by construction.
| id | timestamp (UTC) | src ip | method | path | kind | size |
|---|---|---|---|---|---|---|
| loading… | ||||||
With the camera reachable over its existing P2P session, send one CGI to redirect every future motion alert at this endpoint. Reversible — Eye4 will reset it on next connect, or you can revert manually.
# via Frida-hijacked Eye4 (today's path) from _camera_re.cgi_bridge import CGIBridge with CGIBridge(real_uid="<UID>") as br: br.send("set_factory_param.cgi", params={"alarm_server": "cam.all-track.co.uk/cb75-001"}) # verify info = br.send("get_factory_param.cgi") assert info["factory_alarmserver"] == "cam.all-track.co.uk/cb75-001"
The receiver accepts any HTTP method, any path, any body. JPEG, PNG, JSON, plaintext — all detected by content-sniff and persisted with timestamps. Use distinct subpaths per camera to tag the source.
# 1. Heartbeat (camera liveness ping every ~60s) POST https://cam.all-track.co.uk/<tag> Content-Type: application/json {"vuid":"<id>"} # Reply (required, "200" is a STRING): {"code":"200","message":"Success"} # 2. Multipart alarm push (fields: vuid, type, picture, video?) POST https://cam.all-track.co.uk/<tag> Content-Type: multipart/form-data form: vuid=ADG... type=41 picture=@snap.jpg video=@clip.mp4 # 3. Raw JPEG body (firmwares that don't multipart-encode) curl -X POST -H "Content-Type: image/jpeg" \ --data-binary @./snapshot.jpg \ https://cam.all-track.co.uk/<tag> # JSON API (mode=alarms|heartbeats|probes|all) GET https://cam.all-track.co.uk/api/health GET https://cam.all-track.co.uk/api/alarms?mode=alarms&limit=N GET https://cam.all-track.co.uk/api/inbox/<file> GET https://cam.all-track.co.uk/api/types # 8 known alarm-type codes