Problema com executeQuery

Bom dia pessoal. Estou iniciando com java web e estou tendo dificuldades com resultset.
Quando tento ler o resultset não faz nada e sai do código, depois do stm.executequery(qry) não erro nenhum e vai direto para o out.close;

/*
 * To change this template, choose Tools | Templates
 * and open the template in the editor.
 */
package Conhecimento;

import java.io.IOException;
import java.io.PrintWriter;
import java.util.logging.Level;
import java.util.logging.Logger;
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import Conhecimento.Conexao;
import java.sql.*;
/**
 *
 * @author picelli
 */
@WebServlet(name = "Login", urlPatterns = {"/Login"})
public class Login extends HttpServlet {

    /** 
     * Processes requests for both HTTP <code>GET</code> and <code>POST</code> methods.
     * @param request servlet request
     * @param response servlet response
     * @throws ServletException if a servlet-specific error occurs
     * @throws IOException if an I/O error occurs
     */
    protected void processRequest(HttpServletRequest request, HttpServletResponse response)
            throws ServletException, IOException, ClassNotFoundException, SQLException {
        response.setContentType("text/html;charset=UTF-8");
        PrintWriter out = response.getWriter();
        try {
            Connection con = Conexao.Conecta();
            String qry = "";
            Statement stm = null;
            ResultSet rs = null;
            out.println("<html>");
            out.println("<head>");
            out.println("<title>Valida Login</title>");  
            out.println("</head>");
            out.println("<body>");
            if (con != null) {                
                qry="Select Usuario, Senha from CTRL_USUARIO Where Usuario = \""+request.getParameter("user")+"\""+
                " and Senha = \""+request.getParameter("senha")+"\"";
                stm = con.createStatement();
                rs = stm.executeQuery(qry);
                while(rs.next()) {
                    if(!rs.getString("senha").equals(request.getParameter("senha"))) {
                        rs.close();
                        stm.close();
                        con.close();
                        out.println("<script>alert(\"Senha Inv&aacute;lida !!!\");</script>");
                    }
                    else {
                        rs.close();
                        stm.close();
                        con.close();                        
                        response.sendRedirect("Modulo");
                    }
                }
                rs.close();
                stm.close();
                con.close();
                out.println("<script>alert(\"Usu&aacuterio n&atilde; Encontrado !!!\");</script>");
            }
            else {
                con.close();
                out.println("<script>alert(\"Erro de Conex&atilde;o !!!\");</script>");
            }
            out.println("</body>");
            out.println("</html>");
        } finally {            
            out.close();
        }
    }    // <editor-fold defaultstate="collapsed" desc="HttpServlet methods. Click on the + sign on the left to edit the code.">
    /** 
     * Handles the HTTP <code>GET</code> method.
     * @param request servlet request
     * @param response servlet response
     * @throws ServletException if a servlet-specific error occurs
     * @throws IOException if an I/O error occurs
     */
    @Override
    protected void doGet(HttpServletRequest request, HttpServletResponse response)
            throws ServletException, IOException {
        try {
            try {
                processRequest(request, response);
            } catch (SQLException ex) {
                Logger.getLogger(Login.class.getName()).log(Level.SEVERE, null, ex);
            }
        } catch (ClassNotFoundException ex) {
            Logger.getLogger(Login.class.getName()).log(Level.SEVERE, null, ex);
        }
    }

    /** 
     * Handles the HTTP <code>POST</code> method.
     * @param request servlet request
     * @param response servlet response
     * @throws ServletException if a servlet-specific error occurs
     * @throws IOException if an I/O error occurs
     */
    @Override
    protected void doPost(HttpServletRequest request, HttpServletResponse response)
            throws ServletException, IOException {
        try {
            try {
                processRequest(request, response);
            } catch (SQLException ex) {
                Logger.getLogger(Login.class.getName()).log(Level.SEVERE, null, ex);
            }
        } catch (ClassNotFoundException ex) {
            Logger.getLogger(Login.class.getName()).log(Level.SEVERE, null, ex);
        }
    }

    /** 
     * Returns a short description of the servlet.
     * @return a String containing servlet description
     */
    @Override
    public String getServletInfo() {
        return "Short description";
    }// </editor-fold>
}

Cara, procure por PreparedStatement, vai facilitar mto o seu sql, na atribuição de parâmetros, além de, se tornar mais seguro qto a sql injection.

Obrigado Fabio. Funcionou.