Endianness in x86/x86_64 Memory
Endianness describes the order in which the bytes of a multi-byte value are stored in memory.
Little-endian (x86/x86_64)
The least-significant byte is stored at the lowest memory address.
Example with the 32-bit value 0x000000c8 (decimal 200):
| Memory address | Byte |
|---|---|
0x100 |
c8 |
0x101 |
00 |
0x102 |
00 |
0x103 |
00 |
A debugger prints memory from low address to high address left-to-right:
c8 00 00 00
To reconstruct the value, read the bytes in reverse order: 0x000000c8.
Big-endian
The most-significant byte is stored at the lowest memory address.
Same value 0x000000c8 would appear in memory as:
00 00 00 c8
This already matches the written hex value left-to-right.
Pointers are also integers
A pointer is just an address stored as an integer, so it follows the same endianness rules.
For example, if a 64-bit pointer appears in memory as:
78 56 34 12 7f 00 00 00
Its actual value is:
0x00007fff12345678
Key takeaway
When reading a hex dump on x86/x86_64, the leftmost byte is the little end of the number. Reverse the byte order to get the value you would write in source code or see in a register.