$userid = 0; $user = mysql_real_escape_string($user); $check = mysql_query("SELECT userid,password,salt FROM user WHERE username='$user'"); if(mysql_num_rows($check) > 0) { $rec = mysql_fetch_array($check); if($rec['password'] == md5(md5($password).$rec['salt'])) { $userid = $rec['userid']; } } // if $userid > 0 then login was ok.