About this question
Some context: I was assigned on a pentest and found an application that let me place my own links in a tag's href attribute. As expected, all strange values like [removed] were correctly filtered by an XSS filter, however I discovered that you could bypass this filter by injecting a TAB character in the middle of the protocol specification like such:
Now what I would like to know is, why do browsers accept this as a valid javascript URL which will happily execute code whereas other characters like SPACE character are not allowed? Is there a historic reason for them allowing this strange format?
Note: Tested on Chrome, for those that like to test it, it also works with [removed] like so: