Kolejność bajtów i endianness
Poznają Państwo sposób rozmieszczenia wartości wielobajtowych w pamięci i plikach, dowiedzą się, dlaczego endianness sprawia trudności początkującym oraz jak prawidłowo odczytywać surowe bajty.
Kolejność bajtów i endianness to bezpłatna lekcja Reverse Engineering & Binary Analysis Basics na CoddyKit. To lekcja 4 z 4. Możesz przeczytać całą lekcję poniżej za darmo — a potem ćwiczyć ją interaktywnie w przeglądarce z wbudowanym edytorem kodu i tutorem AI dostępnym 24/7. To część ścieżki edukacyjnej Reverse Engineering & Binary Analysis Basics, a Twój postęp synchronizuje się między webem a aplikacją CoddyKit. Kurs Reverse Engineering & Binary Analysis Basics zawiera 4 lekcji w sumie.
Części tej lekcji nie zostały jeszcze przetłumaczone i są wyświetlane po angielsku.
Bytes Have an Order
You learned how data is represented in binaries. But a number like 0x12345678 occupies four bytes, and the CPU must decide which byte comes first in memory.
That decision is called endianness.
Little-Endian
In little-endian, the least significant byte is stored first (lowest address).
The value 0x12345678 is stored as the bytes 78 56 34 12. x86, x64, and most ARM systems use little-endian.
Value: 0x12345678
Memory: 78 56 34 12 (low -> high address)Big-Endian
In big-endian, the most significant byte is stored first.
The same value 0x12345678 is stored as 12 34 56 78. Network protocols and some older RISC chips use big-endian, so it is also called network byte order.
Value: 0x12345678
Memory: 12 34 56 78 (low -> high address)Why It Matters in RE
When you see raw bytes in a hex editor, you must apply the correct endianness to recover the real value. Misreading endianness turns a valid pointer into garbage.
- Reading addresses
- Parsing file headers
- Interpreting struct fields
Reading a 4-Byte Integer
Suppose a hex dump shows the bytes 2A 00 00 00. On a little-endian machine that is the integer 42, not 0x2A000000.
Always know the platform before interpreting.
Bytes: 2A 00 00 00
LE int: 0x0000002A = 42
BE int: 0x2A000000 = 704643072Seeing It in Code
This C snippet inspects the running machine's endianness by aliasing an int through a byte pointer.
#include <stdio.h>
int main(void) {
unsigned int x = 0x12345678;
unsigned char *p = (unsigned char *)&x;
printf('First byte: %02X\n', p[0]);
return 0;
}Network Byte Order
Protocols standardize on big-endian so machines of different architectures agree. C provides conversion helpers like htons and ntohl.
When reversing network code, watch for these calls; they reveal which fields are multi-byte.
uint16_t port = htons(8080); // host -> network orderByte Swapping
Converting between endian formats means reversing the byte order. Tools and disassemblers often offer a one-click swap, but understanding the mechanism is essential.
uint32_t swap32(uint32_t v) {
return ((v & 0xFF) << 24) |
((v & 0xFF00) << 8) |
((v >> 8) & 0xFF00) |
((v >> 24) & 0xFF);
}Endianness in File Formats
Many file formats declare their endianness in a magic field. ELF stores EI_DATA in its header; TIFF starts with II (Intel/little) or MM (Motorola/big).
Reading this field first tells you how to parse the rest.
Common Pitfalls
Beginners often:
- Read bytes left-to-right and forget to reverse for little-endian
- Assume the target matches their own machine
- Mix endianness mid-struct
When a pointer looks absurd, suspect endianness first.
Tools That Show Endianness
Most analysis tools let you toggle interpretation. In a hex editor you can flip between little- and big-endian data inspectors; disassemblers display the architecture's native order automatically.
When carving raw structures, always confirm the tool's current setting matches the target.
xxd -l 4 sample.bin
# 00000000: 2a00 0000 -> LE int = 42Quick Check
How is the value 0x12345678 stored on a little-endian machine?
Recap
Endianness decides byte order for multi-byte values:
- Little-endian: least significant byte first (x86/x64)
- Big-endian: most significant first (network order)
- Check the format's endianness field before parsing
Mastering this stops the most common 'garbage value' confusion in binary analysis.
Często zadawane pytania
Czy lekcja „Kolejność bajtów i endianness” jest bezpłatna?
Tak — pełny tekst „Kolejność bajtów i endianness” jest dostępny za darmo tutaj w sieci. Aby ćwiczyć ją interaktywnie (wbudowany edytor kodu i tutor AI dostępny 24/7) i odblokować resztę kursu Reverse Engineering & Binary Analysis Basics, przejdź na CoddyKit PRO. Kurs Reverse Engineering & Binary Analysis Basics zawiera 4 lekcji w sumie.
Co nauczysz się w „Kolejność bajtów i endianness”?
Poznają Państwo sposób rozmieszczenia wartości wielobajtowych w pamięci i plikach, dowiedzą się, dlaczego endianness sprawia trudności początkującym oraz jak prawidłowo odczytywać surowe bajty. Ćwiczysz Reverse Engineering & Binary Analysis Basics z praktycznym kodem, który uruchamiasz bezpośrednio w przeglądarce, a tutor AI dostępny 24/7 odpowiada na Twoje pytania podczas pracy nad lekcją.
Czy potrzebuję doświadczenia, aby zacząć Reverse Engineering & Binary Analysis Basics?
Nie wymagamy żadnego doświadczenia. Reverse Engineering & Binary Analysis Basics w CoddyKit jest strukturyzowany dla początkujących i zaawansowanych użytkowników, więc możesz zacząć tutaj lub od początku i uczyć się w swoim tempie. To lekcja 4 z 4.
Ile czasu zajmuje lekcja „Kolejność bajtów i endianness”?
Większość lekcji CoddyKit trwa około 5–10 minut. Każda lekcja to mały, interaktywny krok, dzięki czemu robisz systematyczne postępy i zawsze wracasz dokładnie do tego samego miejsca — na webie i w aplikacji.
Czy mogę pisać i uruchamiać kod w tej lekcji Reverse Engineering & Binary Analysis Basics?
Tak. Każda lekcja Reverse Engineering & Binary Analysis Basics zawiera wbudowany edytor kodu, więc piszesz i uruchamiasz prawdziwy kod bezpośrednio w przeglądarce i od razu otrzymujesz sprzężenie zwrotne od AI — bez konfiguracji na komputerze.
Wszystkie lekcje w tym kursie
- Przegląd architektur procesorów
- Reprezentacja danych w plikach binarnych
- Popularne formaty plików binarnych
- Kolejność bajtów i endianness