I'm having some problems with my router. Some bot or dude is opening TCP connections over pptp/ppp and I dont know how. PPTP service is disabled, winbox access is unlocked only to one IP address, web html access is disabled too.
That ramdom IP address are connecting all the time, some failed logins attempt too.
Anyway to block this?
My CCR1036 is up to date but previously was atacked and the hacker uploaded a script file to it. I have erased all configs that he made with that scrip file, but that tcp connections still ocurring.
That router is operational in a remote location, I can't erase all configs