$sql = "SELECT * FROM tabla_usuarios WHERE user='".$_POST['user']." AND password='".$_POST['password']."'";