When a router is defaulted, it normally has a set default config which includes firewall rules. When you first connect, you have the option to retain the config or start clean. I’d have to think you chose to start clean.
If you are running pre-6.40.8 or pre-6.42.1, someone may have already hijacked your router and added it to a botnet. See http://forum.mikrotik.com/t/winbox-vulnerability-please-upgrade/122004/1
I’m not sure why you can’t connect on 443 or 4443. I’d suggest using Winbox on port 8291 anyway. I find it to be a more responsive and useful method for administration.
Then see https://wiki.mikrotik.com/wiki/Manual:Securing_Your_Router for advice on securing your router.