<?php
session_start();
$username = filter_var(trim($_POST['username']), FILTER_SANITIZE_STRING);
$password = filter_var(trim($_POST['password']), FILTER_SANITIZE_STRING);
$mysql = new mysqli('localhost', 'root', '', 'user');
$result = $mysql->query("SELECT * FROM users WHERE username='$username' AND password='$password'");
$user = $result->fetch_assoc();
if(count($user) == 0){
echo "no";
}else{
echo "yes";
}
session_destroy();
?>