Some one can give direction to start this new adventure
ty i already do some pt in different phone and tablet just i ask to understand better this area to learn more and compare if some procedure ll be different from course i studySS7 has nothing to do with mobile, it's basically a general telephony protocol. Yeah, its leveraged by mobile operators as well that's true, but you have even more chances to exploit it by hacking into a VoIP (SIP) - SS7 gateway device. Can be even a linux with Asterix and the right hardware/interfaces. First you must understand the protocol or just fuzzy some fields and see what happens. Just saying "scan for vulnerability" shows you don't have a plan...
In my experience is more likely to find an implementation mistake leading to a vuln with some vendor than finding a general flaw in the protocol stack. If that is what you want, I'd rather suggest a protocol emulator over messing with a real gateway without knowing what you are doing.