<?
$sql = mysql_query("SELECT login, password FROM users WHERE login = '".mysql_escape_string($login)."'"
;
$user = mysql_fetch_assoc($sql);
if ($_POST['login'] !== $user['login'] && $_POST['password'] !== $user['password']) echo ' Логин и пароль не совпадают!';
?>