Bypass Mode: Taking Down SSL Pinning in Web Apps

By Red Siege | November 6, 2025

What is SSL Certificate Pinning

SSL certificate pinning (HTTPS pinning/TLS pinning) is a security technique that is more often seen applied to mobile applications. However, over the years, I have noticed that some web applications have implemented it as an additional protection as well.

It is a technique that attempts to prevent forms of machine-in-the-middle (MITM) attacks even if the attacker has a valid SSL certificate from a trusted certificate authority (CA). If certificate pinning is enabled, the web server will look at the cert coming from the client, and if it doesn’t match their server’s specific criteria, it will refuse the connection, even if the client browser trusts the certificate they are sending.

This is a problem for testers, because with proxy intercepts like Burp Suite, we use a self-signed generated cert that we have added as a trusted CA. (To see how that process is done click here.) This will work for the majority of web applications, but as mentioned prior, if pinning is enabled it will create issues with the testing process.

Detecting Pinning

Usually, for me, one of the telltale signs of pinning is when I attempt to login to the application with Burp in proxy mode. The application will sometimes allow me to log in successfully in and then immediately kick me back out, or send me to a connection error screen such as the one shown below.

One of the first troubleshooting tests I perform is to turn off my intercept proxy and see if I can log into the application. If I can, it’s most likely a certificate pinning issue.

Working Around the Issue

What to do in this situation is highly determined by how strict the server is about the certificate pinning restrictions. If the server is set to allow the client to choose, then we are in luck. I have found that most organizations would rather people be able to visit their application and typically include a legacy option. While I test with multiple browsers, Firefox is my first quick go to test for a bypass. With a simple configuration change, we may be able to get past the issue.

First, we can access the more advanced configuration settings for the browser by inputting within the Address Bar.

about:config

Next we can type in the keyword pinning, to locate the setting we need. This will give us the option to configure our browser to not enforce it. We will set that value to 0 as shown below.

Now I usually restart the browser, turn my proxy on, and try again. Hopefully, this time, access to the application should be granted! If this doesn’t work, the server is set to a more restrictive level and requiring the use on pinning on the client side in order to access the application.

Conclusion

SSL certificate pinning can be a great form of protection against man-in-the-middle types of attacks. However, if the web server doesn’t explicitly require the pinning, a person can configure their browser to ignore the requirement. By doing this, the protection becomes null and void, and the web application can be proxy intercepted. Intercepting the web application traffic is a vital need for security testing, so having this ability is a definite must!


About Stuart Rorer, Security Consultant

Stuart has worked in the IT Industry for more than twenty years and has worked within Cyber Security for the past twelve. In the past he has held jobs in the education, government, and private sector, and for the last few years has specialized in web application penetration testing. Stuart has performed testing on clients in all sectors, many of which have been in the Fortune 500. He enjoys spending time in research and exploring new penetration testing tactics, and techniques.

Certifications:

CPT, ECPPT, ECSA, CEH, SEC+