RECEIVER ONLINE
Chain-of-custody surveillance for stock-in-transit

Cameras that talk only to your server.

A self-hosted control plane for fleet-deployed VStarcam CB75 4G cameras — built bottom-up by reverse-engineering the Eye4 stack so every frame and motion alert lands on infrastructure you own. No Aliyun. No vendor cloud. Court-admissible by construction.

Real alarms received
—
Last alarm
—
Heartbeats received
—
Edge location
eu-west-1 / Ireland

01System status

Alarms (total)
—
since receiver online
Alarms (24h)
—
last 24 hours
Images stored
—
JPEG bodies received
Receiver uptime
—
https://cam.all-track.co.uk

02Camera under test

Device identity live snapshot, last known
vuid (public)
VSTH409044ZBDCE
real_uid (p2p)
ADG0582942YKMV
model
VStarcam CB75 (BMG1)
alias
4G Camera01
firmware
10.187.121.17 / scm 107.56
SoC
Ingenic T23Z (MIPS32, Linux 3.10.14)
sensor
gc2083 (1920×1080)
SIM IMEI
863547077479232
Capabilities from get_status.cgi
main stream
1920×1080 H264 @ 15fps, 1280 kbps
sub streams
640×360 / 1280×720
battery
100%
PIR sensor
enabled
people detection
supported
night vision
IR-cut + low-light
audio
G.711 mic + speaker (talk-back)
SD card
none installed

03Data path

CB75 Camera
PIR-trigger ➜ HTTP POST
───▶
cam.all-track.co.uk
EC2 t4g.nano · eu-west-1 · TLS · Let's Encrypt
▸ ALARM PATH (active): camera POSTs motion-trigger payloads (header + JPEG cover) over plain HTTP/4G to your receiver. Receiver decodes JPEG magic, persists to disk + SQLite. No Aliyun, no Eye4 cloud.
▸ CONTROL PATH (in transit): CGIs (snapshot, set_*, get_*) currently issued via Frida-hijack of the Eye4 app's encrypted P2P session. Python port of CS2/PPPP underway to eliminate Eye4 entirely.
▸ FAILED PATH (blocked): Eye4 cloud at api.eye4.cn (Aliyun China) and historical OSS at d013-4.oss-eu-central-1.aliyuncs.com (Aliyun Frankfurt). Camera no longer needs to reach either.

04Live alarm feed

idtimestamp (UTC)src ipmethodpathkindsize
loading…

05Recent footage

06How to point a camera here

With the camera reachable over its existing P2P session, send one CGI to redirect every future motion alert at this endpoint. Reversible — Eye4 will reset it on next connect, or you can revert manually.

# via Frida-hijacked Eye4 (today's path)
from _camera_re.cgi_bridge import CGIBridge
with CGIBridge(real_uid="<UID>") as br:
    br.send("set_factory_param.cgi",
            params={"alarm_server": "cam.all-track.co.uk/cb75-001"})

# verify
    info = br.send("get_factory_param.cgi")
    assert info["factory_alarmserver"] == "cam.all-track.co.uk/cb75-001"

The receiver accepts any HTTP method, any path, any body. JPEG, PNG, JSON, plaintext — all detected by content-sniff and persisted with timestamps. Use distinct subpaths per camera to tag the source.

# 1. Heartbeat (camera liveness ping every ~60s)
POST https://cam.all-track.co.uk/<tag>
Content-Type: application/json
{"vuid":"<id>"}
# Reply (required, "200" is a STRING):
{"code":"200","message":"Success"}

# 2. Multipart alarm push (fields: vuid, type, picture, video?)
POST https://cam.all-track.co.uk/<tag>
Content-Type: multipart/form-data
form: vuid=ADG... type=41 picture=@snap.jpg video=@clip.mp4

# 3. Raw JPEG body (firmwares that don't multipart-encode)
curl -X POST -H "Content-Type: image/jpeg" \
     --data-binary @./snapshot.jpg \
     https://cam.all-track.co.uk/<tag>

# JSON API (mode=alarms|heartbeats|probes|all)
GET https://cam.all-track.co.uk/api/health
GET https://cam.all-track.co.uk/api/alarms?mode=alarms&limit=N
GET https://cam.all-track.co.uk/api/inbox/<file>
GET https://cam.all-track.co.uk/api/types     # 8 known alarm-type codes