<input type="password" name="password">

meglio mettere post qua
if ($_REQUEST['user'] == $us && $_REQUEST['password']==$pass) {
quindi $_POST['user'] == $us && $_POST['password']==$pass