SqlConnection con;
SqlCommand cmd;
SqlDataReader dr;
con = new SqlConnection();
con.ConnectionString = "строка подключения к БД";
cmd = new SqlCommand();
cmd.Connection = con;
con.Open();
cmd.CommandText = "SELECT * FROM users WHERE username='"+username+"' AND password='"+password+"'";
dr = cmd.ExecuteReader();
dr.Read();
if ((string)dr["username"] != "")
// юзер найден
else
// юзер не найден
con.Close();