$sql = "SELECT * FROM usuario WHERE usuario = ".$_POST['user']." AND pass =".md5($_POST['pass'])." ";