frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

The Single Byte That Kills Your Exploit: Understanding Endianness

https://pwnforfunandprofit.substack.com/p/the-single-byte-that-kills-your-exploit
17•andwati•3d ago

Comments

MrBuddyCasino•40m ago
What first confused me about endianness is that it is about byte order, not bit order. The latter would have seemed more logical, or is this just me?
andwati•19m ago
Learning this initially was confusing for me too, aren't we arranging bits?
scottlamb•36m ago
This is a weird take. I've never put together this kind of exploit, but still I know enough to not buy this. Do people ever really craft exploits that are perfectly valid except for using the wrong endianness?

> If you’ve ever crafted a perfect shellcode and ROP chain only to have your exploit immediately crash with a SIGSEGV(a signal sent by the operating system to a program when it attempts to access a protected or invalid memory location) or EIP(a 32-bit CPU register in the x86 architecture that holds the memory address of the next machine instruction to be executed) pointing to garbage, you’ve likely met the silent killer of beginners: Endianness.

Aren't there a million other ways to get addresses wrong?

> Using x86/x86_64 gadgets and packers on a MIPS/PowerPC target (different endianness and instruction set) will not work.

"and instruction set" is carrying a lot of weight here.

This isn't like a coin flip thing: even considering architectures with configurable endianness, in 2025 it's overwhelmingly likely both host and target are little-endian. And on old, big-endian platforms, that's just one of many things you have to get right.

The last-ever penny will be minted today in Philadelphia

https://www.cnn.com/2025/11/12/business/last-penny-minted
317•andrewl•4h ago•449 comments

Steam Machine

https://store.steampowered.com/sale/steammachine
669•davikr•2h ago•331 comments

Project Euler

https://projecteuler.net
97•swatson741•3h ago•29 comments

Steam Frame

https://store.steampowered.com/sale/steamframe
494•Philpax•2h ago•154 comments

Yt-dlp: External JavaScript runtime now required for full YouTube support

https://github.com/yt-dlp/yt-dlp/issues/15012
726•bertman•10h ago•452 comments

Learn Prolog Now

https://lpn.swi-prolog.org/lpnpage.php?pageid=top
200•rramadass•5h ago•115 comments

Launch HN: JSX Tool (YC F25) – A Browser Dev-Panel IDE for React

36•jsunderland323•2h ago•32 comments

Archive or Delete?

https://email-is-good.com/2025/11/05/archive-or-delete/
21•speckx•1w ago•16 comments

Blasting Yeast with UV Light

https://chillphysicsenjoyer.substack.com/p/results-from-blasting-yeast-with
13•Gormisdomai•1h ago•0 comments

Async and Finaliser Deadlocks

https://tratt.net/laurie/blog/2025/async_and_finaliser_deadlocks.html
33•emailed•2h ago•8 comments

GLP-1 drugs linked to lower death rates in colon cancer patients

https://today.ucsd.edu/story/glp-1-drugs-linked-to-dramatically-lower-death-rates-in-colon-cancer...
25•gmays•41m ago•11 comments

Ioannis Yannas invented artificial skin for treatment of burns–dies at 90

https://news.mit.edu/2025/professor-ioannis-yannas-dies-1027
95•bookofjoe•1w ago•4 comments

Valve Announces New Steam Machine, Steam Controller and Steam Frame

https://www.phoronix.com/news/Steam-Machines-Frame-2026
107•doener•2h ago•3 comments

A brief look at FreeBSD

https://yorickpeterse.com/articles/a-brief-look-at-freebsd/
46•todsacerdoti•8h ago•12 comments

How Tube Amplifiers Work

https://robrobinette.com/How_Amps_Work.htm
19•gokhan•1h ago•5 comments

.NET 10

https://devblogs.microsoft.com/dotnet/announcing-dotnet-10/
428•runesoerensen•1d ago•359 comments

Fighting the New York Times' invasion of user privacy

https://openai.com/index/fighting-nyt-user-privacy-invasion
190•meetpateltech•6h ago•200 comments

Maestro Technology Sells Used SSD Drives as New

https://kozubik.com/items/MaestroTechnology/
114•walterbell•2h ago•40 comments

Waymo robotaxis are now giving rides on freeways in LA, SF and Phoenix

https://techcrunch.com/2025/11/12/waymo-robotaxis-are-now-giving-rides-on-freeways-in-these-3-cit...
231•nharada•4h ago•269 comments

Is your electric bill going up? AI is partly to blame

https://www.npr.org/2025/11/06/nx-s1-5597971/electricity-bills-utilities-ai
33•ilamont•1h ago•29 comments

What happened to Transmeta, the last big dotcom IPO

https://dfarq.homeip.net/what-happened-to-transmeta-the-last-big-dotcom-ipo/
180•onename•11h ago•100 comments

Yann LeCun to depart Meta and launch AI startup focused on 'world models'

https://www.nasdaq.com/articles/metas-chief-ai-scientist-yann-lecun-depart-and-launch-ai-start-fo...
757•MindBreaker2605•13h ago•572 comments

Micro.blog launches new 'Studio' tier with video hosting

https://heydingus.net/blog/2025/11/micro-blog-offers-an-indie-alternative-to-youtube-with-its-stu...
89•justin-reeves•6h ago•27 comments

LLM Output Drift in Financial Workflows: Validation and Mitigation (arXiv)

https://arxiv.org/abs/2511.07585
4•raffisk•39m ago•2 comments

The Single Byte That Kills Your Exploit: Understanding Endianness

https://pwnforfunandprofit.substack.com/p/the-single-byte-that-kills-your-exploit
17•andwati•3d ago•3 comments

NetHack4 Philosophy

http://nethack4.org/philosophy.html
52•suioir•1w ago•23 comments

Show HN: Cancer diagnosis makes for an interesting RL environment for LLMs

23•dchu17•3h ago•4 comments

The Geometry Behind Normal Maps

https://www.shlom.dev/articles/geometry-behind-normal-maps/
88•betamark•6h ago•5 comments

UK pauses intelligence-sharing with US on suspected drug vessels in Caribbean

https://www.theguardian.com/uk-news/2025/nov/11/uk-suspends-intelligence-sharing-with-us-amid-air...
74•beardyw•2h ago•15 comments

GPT-5.1: A smarter, more conversational ChatGPT

https://openai.com/index/gpt-5-1/
126•tedsanders•1h ago•164 comments