First thing you should check are any leaked scripts you have downloaded. This is a very common place for people to put in back doors before they leak a script.
We don't condone using leaked scripts, so if you are, you should probably remove them, but all the same those would be the first place I'd look for back doors.
Second, make sure your rcon password is strong. I recently helped someone who had an rcon password of '1764'. He changed it after I explained to him how that was troublesome.. but if someone knows your rcon password, they could be using that to exploit your server. Also, make sure your rcon password is in your command line, NOT your server.cfg file.