$user=mysql_real_escape_string($user);$sql = "SELECT * FROM users WHERE user = '$user'";#o tambien asi $sql=sprintf("SELECT * FROM users WHERE user = '%s'",mysql_real_escape_string($user));